USENIX Security2016Top-tier venue
Request and Conquer: Exposing Cross-Origin Resource Size
Tom van Goethem, Mathy Vanhoef, Frank Piessens, Wouter Joosen
Abstract
Numerous initiatives are encouraging website owners to enable and enforce TLS encryption for the communication between the server and their users. Although this encryption, when configured properly, completely prevents adversaries from disclosing the content of the traffic, certain features are not concealed, most notably the size of messages. As modern-day web applications tend to provide users with a view that is tailored to the information they entrust these web services with, it is clear that knowing the size of specific resources, an adversary can easily uncover personal and sensitive information. In this paper, we explore various techniques that can be employed to reveal the size of resources. As a result of this in-depth analysis, we discover several design flaws in the storage mechanisms of browsers, which allows an adversary to expose the exact size of any resource in mere seconds. Furthermore, we report on a novel size-exposing technique against Wi-Fi networks. We evaluate the severity of our attacks, and show their worrying consequences in multiple real-world attack scenarios. Furthermore, we propose an improved design for browser storage, and explore other viable solutions that can thwart size-exposing attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 671f20eb-9036-4efc-84eb-09ab84e3e6ebCited by top-tier papers11
- Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser SecurityPeter Snyder, Cynthia Bagier Taylor, Chris KanichCCS 2017 · 75 citations
- Pride and Prejudice in Progressive Web Apps: Abusing Native App-like Features in Web ApplicationsJiyeon Lee, Hayeon Kim, Junghwan Park, Insik Shin et al.CCS 2018 · 40 citations
- Deterministic BrowserYinzhi Cao, Zhanhao Chen, Song Li, Shujiang WuCCS 2017 · 32 citations
- Rendered Private: Making GLSL Execution Uniform to Prevent WebGL-based Browser FingerprintingShujiang Wu, Song Li, Yinzhi Cao, Ningfei WangUSENIX Security 2019 · 27 citations
- Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer DefensesF. Nisa Bostanci, Oguzhan Canpolat, Ataberk Olgun, Ismail Emir Yüksel et al.MICRO 2025 · 8 citations
Related papers
- Off-Path TCP Hijacking in Wi-Fi Networks: A Packet-Size Side Channel AttackZiqiang Wang, Xuewei Feng, Qi Li, Kun Sun et al.NDSS 2025
- Near-Optimal Constrained Padding for Object Retrievals with DependenciesPranay Jain, Andrew C. Reed, Michael K. ReiterUSENIX Security 2024 · 1 citation
- DBREACH: Stealing from Databases Using Compression Side ChannelsMathew Hogan, Yan Michalevsky, Saba EskandarianS&P 2023
- Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and FragmentationMathy VanhoefUSENIX Security 2021 · 48 citations
- Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy LeakageSoroush Karami, Panagiotis Ilia, Jason PolakisNDSS 2021
