XSinator - XS Leak Browser Test

Discussion in 'other anti-malware software' started by Sampei Nihira, Dec 7, 2021.

  1. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    A group of German researchers from the Ruhr University (Bochum) and the Hochschule Niederrhein have discovered 14 types of XS-Leaks attacks that affect all major browsers.
    Cross-site attacks are not new, but the academic researchers showed how many types of XS-Leaks are still unclassified and unresolved.

    I would like to implore W. members who decide to post their test not to cheat.;)
    So please do it only once, with the browser in daily browsing conditions.:thumb:
    TH.


    https://xsinator.com/

    With Edge (OS W.10) I have 3 vulnerabilities:

    • History Length Leak
    • Frame Count Leak
    • COOP Leak
    Immagine.jpg

    With Firefox (OS Linux) I have 2 vulnerabilities:

    • Frame Count Leak
    • COOP Leak
     
    Last edited: Dec 7, 2021
  2. faircot

    faircot Registered Member

    Joined:
    May 17, 2012
    Posts:
    228
    Location:
    UK
     
  3. faircot

    faircot Registered Member

    Joined:
    May 17, 2012
    Posts:
    228
    Location:
    UK
    OnWin10 with Opera and Adguard I registered a bucketful of 'leaks', around 20, but I've no idea whether this is normal browser behaviour or not?
     
  4. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    On page 9 paragraph 6 are the results for various browsers:

    https://xsinator.com/paper.pdf
     
  5. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,791
    Firefox ESR 91.3 portable

    10 exploitable + a few timed out from 37
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    But I wonder how serious the risk is from cross site scripting (XSS) attacks. In 25 years of surfing the web, I don't think I have ever been affected by this type of stuff. So these type of tests are barely interesting to me, but perhaps I'm underestimating the risk?
     
  7. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Many, many leaks. Firefox and Edge.Dev. I didn't bother to count but it seemed the red findings were approaching the green ones in number. I did not panic nor try to analyze the results into something I needed to act on immediately--like install yet another software trinket for "security's" sake.

    Status quo. This is highly esoteric but worth watching to see if anything further develops.
     
  8. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,568
    To be fair. Just because one isn’t affected by something doesn’t mean it isn’t a problem.

    I have never been infected by ransomware. That doesn’t mean it isn’t a issue that affects thousands. If it wasn’t, then Microsoft would not have bother to protect users against it.
     
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    No I agree, but I'm trying to figure out how big the threat is. I have never been infected with malware in the last 20 years or so, but I know that the threat is out there and it's real. But I'm not so sure about XSS.
     
  10. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,100
    Location:
    Canada

    Same as yours using latest Firefox on Windows 11.

    Edit

    same results on Firefox running on Linux MX-21. Eight of the tests timed out, just as on Windows platform.
     
    Last edited: Dec 9, 2021
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice