BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//sched.securitybsides.org.uk//bsides-london-2023//speaker
 //ML3FN9
BEGIN:VTIMEZONE
TZID:GMT
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:GMT
TZOFFSETFROM:+0100
TZOFFSETTO:+0000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T020000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:BST
TZOFFSETFROM:+0000
TZOFFSETTO:+0100
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsides-london-2023-KKBLFN@sched.securitybsides.org.uk
DTSTART;TZID=GMT:20231209T100000
DTEND;TZID=GMT:20231209T101500
DESCRIPTION:The web platform's openness and composability provide many bene
 fits. Yet\, the ability for websites to interact with each other has provi
 ded many opportunities for attacks that abuse the core principles of the w
 eb.\n\nWith the evolution of web frameworks and browsers\, Cross-Site Scri
 pting (XSS) and Cross-Site Request Forgery (CSRF) have become increasingly
  rare. In response\, researchers have found new ways to reveal sensitive i
 nformation about users\, giving rise to a new class of vulnerabilities kno
 wn as XS-Leaks.\n\nXS-Leaks abuse interactions between websites to leak se
 nsitive information about users. Among other things\, this includes leakin
 g the user's visit history\, leaking the content of a cross-site page\, an
 d leaking response status codes in order to de-anonymize a user on the web
 . In certain cases\, this allows a cross-origin site to perform an XS-Sear
 ch\, where characters in a search query are brute-forced to find a query w
 ith valid results.\n\nFor example\, an HTML injection without XSS can be w
 eaponized to leak response status codes of API endpoints\, and browser beh
 aviour when approaching the browser's URL length limit can be used to leak
  302 redirects.\n\nIn this talk\, we will explore various XS-Leak techniqu
 es that exist in 2023\, their mitigations\, and some bypasses.
DTSTAMP:20260714T134756Z
LOCATION:Rookie track
SUMMARY:XS-Leaks: Client-Side Attacks in a Post-XSS World - Zeyu (Zayne) Zh
 ang
URL:https://sched.securitybsides.org.uk/bsides-london-2023/talk/KKBLFN/
END:VEVENT
END:VCALENDAR
