HashWick V8 Vulnerability
About one year ago, I've discovered a way to do a Denial-of-Service (DoS) attack on a local Node.js instance. The process involved sending huge amounts of data to the HTTP server running on the same machine as the attacker, and measuring the timing differences between various payloads. Given that the scope of attack was limited to the same machine, it was decided by V8 team and myself that the issue wasn't worth looking in yet. Nevertheless, a blog post was published. This year, I had a chance to revisit the Hash Seed guessing game with restored enthusiasm and new ideas. The results of this experiment are murky, and no fix is available yet in V8. Thus all V8 release lines are vulnerable to the HashWick attack. (Disclaimer: the issue was disclosed responsibly. This blog post is published after more than 90 days since the initial report) The Hash Seed is a random number that is used as an initial value for the (non-cryptographic) hash functions inside of V8 instances. Such numbers are us
HashWick V8 Vulnerability Skip to main content HashWick V8 Vulnerability 22 August 2018 security About one year ago, I've discovered a way to do a Denial-of-Service (DoS) attack on a local Node.js instance. The process involved sending huge amounts of data to the HTTP server running on the same machine as the attacker, and measuring the timing differences between various payloads. Given that the scope of attack was limited to the same machine, it was decided by V8 team and myself that the issue wasn't worth looking in yet. Nevertheless, a blog post was published. This year, I had a chance to r
Explore this link on the map →related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Hash function - Wikipediaen.wikipedia.org
- abseil / Performance Hintsabseil.io
- Verifiable Delay Functions. A brief and gentle introduction | by Ramses Fernandez | RootstockLabs: Research & Technology | Mediummedium.com
- ZK-Friendly Hash Functions | Zellic — Researchzellic.io
- Exploiting the Profanity Flaw. On 20 Sep 2022, a tweet indicated that… | by Amber Group | Amber Group | Mediummedium.com
- Cryptographic Hashes | Computer Securitytextbook.cs161.org
- An intensive introduction to cryptography: Hash Functions, Random Oracles, and Bitcoinintensecrypto.org
- Length extension attack - Wikipediaen.wikipedia.org
- Introduction to Locality-Sensitive Hashingtylerneylon.com
- All learning materials - detailed | Web Security Academyportswigger.net
- The Hitchhiker's Guide to Ethereum - Delphi Digitalmembers.delphidigital.io