Smashing the state machine: the true potential of web race conditions
portswigger.net | research | #web-security | #research | #race-conditions | #single-packet-attack | #state-machine
Summary
New race condition classes beyond limit-overrun exploits compromise major sites and the Devise Rails framework, powered by a single-packet attack squeezing 30 requests into a sub-1ms window.
- Published
- Collected
Skip to content