Cross-Site ETag Length Leak
blog.arkark.dev/2025/12/26/eta…
I just posted the author writeup for impossible-leak in SECCON CTF 14 Quals. As far as I know, this is a new XS-Leak technique! The ETag header can become a side channel :)
Writeups for my challenges in #SECCON CTF 2023 Finals!
- cgi-2023: XS-Leak with CSP error reports by SRI checks.
- LemonMD: Breaking Islands Architecture of Fresh.
- DOMLeakify: New CSS injection on style **attributes**.
and 2 challs.
Writeups for my challenges in ASIS CTF Finals 2024!
- fetch-box: A sandbox challenge with fetch.
- fire-leak: XS-Leak based on client-side ReDoS without JavaScript.