Practical Web Timing Attacks: New Techniques and Tools for Real-World Exploitation
James Kettle, Director of Research at PortSwigger, published a comprehensive paper titled 'Listen to the whispers: web timing attacks that actually work.' The research challenges the notion that web timing attacks are merely theoretical, demonstrating novel techniques that are accurate and efficient in real-world scenarios. Validated against a test bed of 30,000 live websites, the study reveals methods to detect sub-millisecond differentials without prior configuration. Key findings include strategies for uncovering hidden attack surfaces, exploiting server-side injection vulnerabilities like blind SQLi and JSON injection, and identifying misconfigured reverse proxies. The paper accompanies presentations at Black Hat USA and DEF CON, offering open-source tools integrated into Param Miner for automated exploitation. By refining methodologies through extensive testing, Kettle provides actionable insights for security professionals to identify masked misconfigurations and bypass firewalls. This work significantly advances the practical application of side-channel attacks, transforming them from lab concepts into reliable tools for discovering critical security flaws across diverse web targets.
Wire timeline
Practical Web Timing Attacks: New Techniques and Tools for Real-World Exploitation
James Kettle, Director of Research at PortSwigger, published a comprehensive paper titled 'Listen to the whispers: web timing attacks that actually work.' The research challenges the notion that web timing attacks are merely theoretical, demonstrating novel techniques that are accurate and efficient in real-world scenarios. Validated against a test bed of 30,000 live websites, the study reveals methods to detect sub-millisecond differentials without prior configuration. Key findings include strategies for uncovering hidden attack surfaces, exploiting server-side injection vulnerabilities like blind SQLi and JSON injection, and identifying misconfigured reverse proxies. The paper accompanies presentations at Black Hat USA and DEF CON, offering open-source tools integrated into Param Miner for automated exploitation. By refining methodologies through extensive testing, Kettle provides actionable insights for security professionals to identify masked misconfigurations and bypass firewalls. This work significantly advances the practical application of side-channel attacks, transforming them from lab concepts into reliable tools for discovering critical security flaws across diverse web targets.
PortSwigger Research