|
You are here |
www.sjoerdlangkemper.nl | ||
| | | | |
tom.vg
|
|
| | | | | [AI summary] This article explains cross-site and browser-based timing attacks that allow attackers to infer sensitive information from response sizes using side-channel leaks in web browsers. | |
| | | | |
blog.plataformatec.com.br
|
|
| | | | | A security bug (CVE-2015-8314) has been reported in Devise's remember me system. Devise implements the "Remember me" functionality by using cookies. While this functionality works across multiple devices, Devise ended-up generating the same cookie for all devices. Consequently, if a malicious user was able to steal a remember me cookie, the cookie could be used | |
| | | | |
timtech.blog
|
|
| | | | | Fun with Cross-Site Request Forgery (CSRF) in a creative Web Timing Attack scenario, highlighting the risks inherent to SameSite=None session cookies. | |
| | | | |
plasma-umass.org
|
|
| | | Demo of the Doppio Runtime System. Contribute to plasma-umass/doppio-demo development by creating an account on GitHub. | ||