The Clock Doesn't Lie: Timing Attacks in Authentication Flows
A timing side-channel in JSONAuth allows unauthenticated attackers to enumerate valid usernames based on response time differences.
TAG ARCHIVE
7 posts across research, tutorials, and notes.
A timing side-channel in JSONAuth allows unauthenticated attackers to enumerate valid usernames based on response time differences.
Analysis of a password change flow that accepts a valid session token without requiring current-password reauthentication.
An analysis of an incomplete remediation in FileBrowser Quantum where tokenized download URLs remained exposed, resulting in an authentication bypass despite a prior security fix.
Quick note documenting a cache poisoning condition caused by query normalization mismatch between CDN and origin cache layers.
Investigation into an authentication bypass caused by trusting a forwarded identity header at the edge gateway.
Step-by-step methodology for validating reset flow token handling, expiry controls, and host header trust boundaries.
A practical review sequence for extension filtering, MIME validation, content sniffing, and asynchronous malware scanning.