Главная
Study mode:
on
1
APPSEC EUROPE
2
TID TIMING ATTACKS
3
Timing Attack Concept
4
Drunkenness Timing Attack
5
The Experiment Part 2
6
Web-based Timing Attacks
7
Same-Origin Policy
8
Classic Cross-site Timing Attacks
9
Browser-based Timing Attacks
10
Video Parsing Attack
11
Cache Storing Attack
12
Age-discovery Attack
13
Moar Attacks
14
Mitigation
15
Conclusion
16
Questions?
Description:
Explore the evolving landscape of timing attacks in web security through this 42-minute conference talk from AppSecEU 2016 in Rome. Delve into various timing attack concepts, including the Drunkenness Timing Attack and its experimental results. Examine web-based timing attacks, their relationship to the Same-Origin Policy, and classic cross-site timing attacks. Investigate browser-based timing attacks, such as the Video Parsing Attack, Cache Storing Attack, and Age-discovery Attack. Learn about additional attack vectors, mitigation strategies, and engage in a Q&A session to deepen your understanding of this critical aspect of application security.

The Timing Attacks They Are A-Changin' - Web-based and Browser-based Timing Attack Techniques

OWASP Foundation
Add to list
0:00 / 0:00