Live data from Hacker News

Viewing profile — tomvangoethem

tomvangoethem

HN member
Joined
Wed, Jan 23, 2013, 8:29 PM UTC
HN karma
600
Public activity
45 items

About tomvangoethem

No profile information was provided.

Recent public activity

  1. story
  2. story
  3. story
  4. comment
    Comment #17778565

    It would be very useful if you could point us to such examples! (I'm an author of the paper)

  5. comment
    Comment #17778547

    The main reason why the issue isn't present in Firefox is because their PDF reader (PDF.js) does not have an API to trigger requests (it does execute JS included within the PDF tho…

  6. comment
    Comment #17778528

    The bug still seems to be present. You can use the testing on our website: navigate a Chrome browser with an ad-blocking extension to e.g. https://wholeftopenthecookiejar.eu/data/e…

  7. comment
    Comment #12697319

    Attaching cookies to third-party requests is the source of many issues. In a similar demonstration [0], I showed that browser-based timing attacks (which can probably be considered…

  8. story
  9. story
  10. story
  11. comment
    Comment #11594353

    The attack on Facebook (or any other website for that matter) works regardless of any Access-Control-Allow-Origin headers. The Fetch API has a mode "no-cors", which does not requir…

  12. comment
    Comment #10335729

    The email address is used to send you the link where the results for your domain are shown. If you keep track of this URL yourself, feel free to enter a bogus email. (domain verifi…

  13. story
  14. story
  15. comment
    Comment #10238324

    For anyone interested in similar issues: here you can find a report for a vulnerability in Phabricator with exactly the same cause (truncation by MySQL), and pretty much the same r…

  16. story
  17. comment
    Comment #9892625

    Colleague of the author here. I guess that 4450 requests/s to one IP, or even spread across multiple IPs, could trigger some alarms if the victim is alert. Unfortunately, I'm not t…

  18. story
  19. story
  20. comment
    Comment #8875228

    If you're curious on how he "finds out", check out his other video (Quickjack - Hacking Facebook likes with Clickjacking): https://www.youtube.com/watch?v=bCkSVGhIEb4#t=217

  21. comment
    Comment #8755331

    Cool, comes in quite handy! You may want to up your security-game though. Check the ~/FIXME file on your sever for more info :-)

  22. story
  23. story
  24. comment
    Comment #7686739

    When you are redirected from Facebook - either after clicking "Accept" or in an implicit flow - to the page with the next parameter, and that page redirects to attacker.com , then …

  25. comment
    Comment #7585636

    Yes, I was. I extracted access-log entries from 23 unique IPs in a few hours, though most came from a single IP