5 ms·
Such attacks are interesting, but the CSP part is a red herring to some extent; we had this problem without CSP and the issue is mostly that nobody has any good
by f- 12y ago
Such attacks are interesting, but the CSP part is a red herring to some extent; we had this problem without CSP and the issue is mostly that nobody has any good ideas on how to get rid of this class of attacks without breaking the web:
http://lists.w3.org/Archives/Public/public-webappsec/2014Feb/0043.html http://lists.w3.org/Archives/Public/public-webappsec/2014Feb...
- ZoFreX 12y agoTo what extent is CSP a red herring here? Is there any part of this that would be mitigated if we didn't have it, or can you do everything here without it?
- jlogsdon 12y agoIt's all possible with HTTP statuses according to a link[1] posted above. [1] https://grepular.com/Abusing_HTTP_Status_Codes_to_Expose_Private_Information https://grepular.com/Abusing_HTTP_Status_Codes_to_Expose_Pri...
- ZoFreX 12y agoWhat legitimate use do those onerror / onload callbacks have... that seems like the kind of thing that should be restricted to same origin!
- TheLoneWolfling 12y agoI've seen it used for fallbacks when loading resources hosted on a CDN.
- f- 12y agoSimilarly to CSP, onload and onerror are not the only ways to pull it off. The effect of successfully or unsuccessfully loading images or scripts can be usually inferred without that; for example, images have dimensions that, even if you take away the ability to read them directly, can be inferred from the changes to the layout of the nearby elements.