4 ms·
That's correct: control over the first few bytes (the size of the encryption block) is needed. In addition, in practice you will also need a Same-Origin Policy
by ivanr 13y ago
That's correct: control over the first few bytes (the size of the encryption block) is needed. In addition, in practice you will also need a Same-Origin Policy bypass in order to submit requests to the target web site.
Surprisingly, the Java SOP bypass used for BEAST originally is still without a fix. In addition, IIRC, Java continues to treat sites behind the same IP address as belonging to the same origin. I think that, with some trickery, the latter could be used for arbitrary SOP bypass too.
In my research I discovered that XmlHttpRequest allows you to use arbitrary methods, which is handy, because those are the bytes that are submitted first. So that feature, along with keep-alives and a SOP bypass could also make BEAST possible in a vulnerable browser. (Disclaimer: I tested this approach a bit, but I haven't attempted to exploit it all the way.)
- marshray 13y agoOh my.