Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tomvangoethem
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Web Almanac 2020: the annual state of the web report
(almanac.httparchive.org)
4 points
by
tomvangoethem
6y ago
|
0 comments
2.
▲
Dragonblood – several design flaws discovered in WPA3
(wpa3.mathyvanhoef.com)
9 points
by
tomvangoethem
7y ago
|
0 comments
3.
▲
Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation
(tranco-list.eu)
1 points
by
tomvangoethem
8y ago
|
0 comments
4.
▲
by
tomvangoethem
8y ago
It would be very useful if you could point us to such examples! (I'm an author of the paper)
5.
▲
by
tomvangoethem
8y ago
The main reason why the issue isn't present in Firefox is because their PDF reader (PDF.js) does not have an API to trigger requests (it does execute JS included within the PDF though)
6.
▲
by
tomvangoethem
8y ago
The bug still seems to be present. You can use the testing on our website: navigate a Chrome browser with an ad-blocking extension to e.g. https://wholeftopenthecookiejar.eu/data/extensions/AdBlock/c... and c
7.
▲
by
tomvangoethem
10y ago
Attaching cookies to third-party requests is the source of many issues. In a similar demonstration [0], I showed that browser-based timing attacks (which can probably be considered as wont-fix as well) can be used to extract more specific i
8.
▲
Revealing Private Information Through Browser-Based Timing Attacks
(labs.tom.vg)
3 points
by
tomvangoethem
10y ago
|
0 comments
9.
▲
Request and Conquer
(tom.vg)
1 points
by
tomvangoethem
10y ago
|
0 comments
10.
▲
Timing Attacks in the Modern Web
(tom.vg)
7 points
by
tomvangoethem
10y ago
|
1 comments
11.
▲
by
tomvangoethem
10y ago
The attack on Facebook (or any other website for that matter) works regardless of any Access-Control-Allow-Origin headers. The Fetch API has a mode "no-cors", which does not require CORS. Also: the cache being used is a programmab
12.
▲
by
tomvangoethem
11y ago
The email address is used to send you the link where the results for your domain are shown. If you keep track of this URL yourself, feel free to enter a bogus email. (domain verification is not related to the email address)
13.
▲
CloudPiercer: Is your cloud-protected website's origin exposed?
(cloudpiercer.org)
14 points
by
tomvangoethem
11y ago
|
2 comments
14.
▲
CloudPiercer: Is your cloud-protected website's origin exposed?
(cloudpiercer.org)
2 points
by
tomvangoethem
11y ago
|
0 comments
15.
▲
by
tomvangoethem
11y ago
For anyone interested in similar issues: here you can find a report for a vulnerability in Phabricator with exactly the same cause (truncation by MySQL), and pretty much the same result: https://hackerone.com/reports/22
16.
▲
Android 5.x Lockscreen Bypass
(sites.utexas.edu)
1 points
by
tomvangoethem
11y ago
|
0 comments
17.
▲
by
tomvangoethem
11y ago
Colleague of the author here. I guess that 4450 requests/s to one IP, or even spread across multiple IPs, could trigger some alarms if the victim is alert. Unfortunately, I'm not that familiar with IDS/IPS's to answer th
18.
▲
Practical attack against TLS/SSL and RC4
(rc4nomore.com)
111 points
by
tomvangoethem
11y ago
|
42 comments
19.
▲
Combining the power of R and D3.js
(blog.ae.be)
82 points
by
tomvangoethem
12y ago
|
15 comments
20.
▲
by
tomvangoethem
12y ago
If you're curious on how he "finds out", check out his other video (Quickjack - Hacking Facebook likes with Clickjacking): https://www.youtube.com/watch?v=bCkSVGhIEb4#t=217
21.
▲
by
tomvangoethem
12y ago
Cool, comes in quite handy! You may want to up your security-game though. Check the ~/FIXME file on your sever for more info :-)
22.
▲
Clubbing (Third-party Security) Seals
(vagosec.org)
6 points
by
tomvangoethem
12y ago
|
2 comments
23.
▲
Attacking the Internet using Broadcast Digital Television
(iss.oy.ne.ro)
3 points
by
tomvangoethem
12y ago
|
0 comments
24.
▲
by
tomvangoethem
12y ago
When you are redirected from Facebook - either after clicking "Accept" or in an implicit flow - to the page with the next parameter, and that page redirects to attacker.com , then attacker.com will have access to the referer
25.
▲
by
tomvangoethem
12y ago
Yes, I was. I extracted access-log entries from 23 unique IPs in a few hours, though most came from a single IP
26.
▲
by
tomvangoethem
12y ago
Note that by visiting, your IP and referer become accessible by anyone running an heartbleed exploit: 93.142.x.x - - [11/Apr/2014:10:44:36 -0400] "GET /heartbleed HTTP/1.1" 200 1148 "https://
27.
▲
IamA Hacker who was Raided by the FBI and Secret Service AMAA
(reddit.com)
2 points
by
tomvangoethem
12y ago
|
0 comments
28.
▲
Wilcard DNS, Content Poisoning, XSS and Certificate Pinning
(w00tsec.blogspot.be)
3 points
by
tomvangoethem
12y ago
|
0 comments
29.
▲
Virtual Reality with HTML5: demo (try on mobile)
(people.opera.com)
2 points
by
tomvangoethem
12y ago
|
0 comments
30.
▲
PBKDF2+HMAC hash collisions explained
(mathiasbynens.be)
4 points
by
tomvangoethem
12y ago
|
1 comments
More ›