Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
滥用 Chrome 的 XSS 过滤器窃取令牌
portswigger.net
| 研究 |
#browser-security
|
#chrome
|
#side-channel
|
#token-theft
|
#xss-auditor
摘要
Gareth Heyes 将 Chrome XSS Auditor 的拦截模式用作侧信道判定器:利用 iframe 是否被清除的差异暴力枚举内联脚本中的用户 ID 等值并窃取令牌,附完整 PoC 代码。
发布时间
2019-06-14 12:02
收录时间
2026-07-27 07:19
原文 ↗
相关内容
利用 Hackability 发现 Chrome 信息泄露
(portswigger.net)
XS-Leak:利用 Portal 检测 ID
(portswigger.net)
XS-Leak:利用 focus 泄漏 ID
(portswigger.net)
滥用 jQuery 实现基于 CSS 的时序攻击
(portswigger.net)
用可靠的基于浏览器的端口扫描暴露内网
(portswigger.net)
涡轮增压前的机油检查:CVE-2026-7899 浅析 V8 优化引擎积碳缺陷
(nebusec.ai)
返回