XS-Leak Victim Lab

Victime seule pour entrainement. Host prevu: https://xsleak.raltheo.fr. Tu ecris tes propres scripts attaquants depuis une autre origine.

Session et defense

Actif: Vulnerable. Cookie: SameSite=None Secure HttpOnly

Session vuepas de cookie session
Rolen/a
Projectsn/a
Flagsn/a

Login AliceLogin BobLogoutDebug request

Secrets par famille

Cibles a attaquer

FamilleSecretURL victimeSignal attaquant
Script status charlb-ultraskiddy-script https://xsleak.raltheo.fr/api/features/charlb-ultraskiddy-script.js script.onload vs script.onerror
Image status charlb-image-bigskiddy https://xsleak.raltheo.fr/media/badges/charlb-image-bigskiddy.png Image.onload vs Image.onerror
CSS status css-charlb-newbie https://xsleak.raltheo.fr/theme/css-charlb-newbie.css link.onload vs link.onerror
Timing search timing-skiddy-charli https://xsleak.raltheo.fr/search?q=timing-skiddy-charli fetch no-cors duration
Download size size-charlb-noobie https://xsleak.raltheo.fr/download/reports/size-charlb-noobie load duration / response size side effect
Frame count frame-charlb-pasunbon https://xsleak.raltheo.fr/app/projects/frame-charlb-pasunbon/dashboard iframe.contentWindow.length
ID attribute focus id-charlb-focus https://xsleak.raltheo.fr/account/device-pairing#id-charlb-focus top window blur after iframe fragment focus
Cache probing cache-charlb-skid https://xsleak.raltheo.fr/private/cache-primer?asset=cache-charlb-skid&key=YOUR_KEY warm private page, then time public cacheable asset
Redirect chain charlb-reward-skid https://xsleak.raltheo.fr/redirect/coupon/charlb-reward-skid redirect chain timing / navigation behavior

Profils defense

ProfilCookieHeaders / comportement
vulnerableSameSite=None Secure HttpOnlypublic cache oracle enabled
cookieLaxSameSite=Lax Secure HttpOnlypublic cache oracle enabled
cookieStrictSameSite=Strict Secure HttpOnlypublic cache oracle enabled
frameProtectedSameSite=None Secure HttpOnlyXFO=DENY, frame-ancestors 'none', public cache oracle enabled
corpProtectedSameSite=None Secure HttpOnlyCORP=same-origin, public cache oracle enabled
coopProtectedSameSite=None Secure HttpOnlyCOOP=same-origin, public cache oracle enabled
fetchMetadataSameSite=None Secure HttpOnlyFetch Metadata block, public cache oracle enabled
cacheHardenedSameSite=None Secure HttpOnlypublic cache hardened
hardenedSameSite=Strict Secure HttpOnlyXFO=DENY, frame-ancestors 'none', COOP=same-origin, COEP=require-corp, CORP=same-origin, Fetch Metadata block, uniform responses, public cache hardened