{"id":5398,"date":"2025-01-10T07:08:57","date_gmt":"2025-01-10T06:08:57","guid":{"rendered":"https:\/\/rock-the-prototype.com\/uncategorized\/xs-leak\/"},"modified":"2025-01-10T15:47:09","modified_gmt":"2025-01-10T14:47:09","slug":"xs-leak","status":"publish","type":"encyclopedia","link":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/","title":{"rendered":"XS-Leak"},"content":{"rendered":"<p><\/p><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\"><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1144px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Inhaltsverzeichnis<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #ffffff;color:#ffffff\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #ffffff;color:#ffffff\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#What_is_an_XS_leak_or_cross-site_leak\" >What is an XS leak or cross-site leak?<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#Basic_principle_of_XS-Leaks\" >Basic principle of XS-Leaks<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#How_do_XS_leaks_work\" >How do XS leaks work?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#What_are_the_risks_of_cross-site_attacks\" >What are the risks of cross-site attacks?<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#Undermining_the_effectiveness_of_the_same-origin_policy\" >Undermining the effectiveness of the same-origin policy<\/a><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#Indirect_access_to_resources_worthy_of_protection\" >Indirect access to resources worthy of protection<\/a><\/li><\/ul><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#XS_leak_examples\" >XS leak examples<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#HTTP_Status_Codes_Secrets\" >HTTP Status Codes &amp; Secrets<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#Reasons_and_causes_of_XS_leaks\" >Reasons and causes of XS leaks<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#Defense_strategies_against_XS_leaks\" >Defense strategies against XS leaks<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#Examples_of_XS_leaks_in_detail\" >Examples of XS leaks in detail<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#Why_are_XS_leaks_difficult_to_prevent\" >Why are XS leaks difficult to prevent?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"What_is_an_XS_leak_or_cross-site_leak\"><\/span>What is an XS leak or cross-site leak?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>An <strong>XS leak<\/strong> or <strong>cross-site leak<\/strong> defines a class of vulnerabilities resulting from side channels implemented in web platforms.<\/p>\n\n<h3><span class=\"ez-toc-section\" id=\"Basic_principle_of_XS-Leaks\"><\/span>Basic principle of XS-Leaks<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The principle of XS leaks is to use such side channels available on the web to reveal sensitive information about users, such as their data in other web applications, details about their local environment or internal networks they are connected to.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_do_XS_leaks_work\"><\/span>How do XS leaks work?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>XS leaks<\/strong> exploit the core principle of the web, known as composability, which enables websites to interact with each other. In doing so, <strong>cross-site leaks<\/strong> abuse legitimate mechanisms to derive information about a user. One way to look at XS leaks is to illustrate their similarity to the technique of <strong>Cross-Site Request Forgery<\/strong> <strong>(CSRF 3) <\/strong>. The main difference here is that XS leaks do not allow other websites to perform actions on behalf of a user, but can be used to infer information about a user. It is therefore about spying on sensitive user information. Knowledge of XS leak vulnerabilities therefore increases <a href=\"https:\/\/rock-the-prototype.com\/programmieren-im-team\/software-architektur\/it-sicherheit\/\">IT security<\/a> overall.<\/p>\n<\/div><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.IT-Security in Software Development - Rock the Prototype Podcast - Softwareentwicklung &amp; Prototyping\" href=\"#\"><iframe class=\"lazyload\" style=\"border-radius: 12px;\" src=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%27100%27%20height%3D%27352%27%20viewBox%3D%270%200%20100%20352%27%3E%3Crect%20width%3D%27100%27%20height%3D%27352%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-orig-src=\"https:\/\/open.spotify.com\/embed\/episode\/3Uis0uViBdKlYxYS2nm1XU?utm_source=generator\" width=\"100%\" height=\"352\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/a>\n<div class=\"fusion-text fusion-text-2\"><h2><span class=\"ez-toc-section\" id=\"What_are_the_risks_of_cross-site_attacks\"><\/span>What are the risks of cross-site attacks?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Web browsers offer a variety of functions to support interactions. All relevant data flows between different web applications, i.e. between users and an application, via such browser functions. This data, which is provided with the help of these functions, enables a website to load sub-resources, navigate or send messages to another application, for example.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Undermining_the_effectiveness_of_the_same-origin_policy\"><\/span><strong>Undermining the effectiveness of the same-origin policy<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>While such behavior is usually restricted by security mechanisms built into the web platform (e.g. the <strong>same-origin policy<\/strong>), <a href=\"https:\/\/xsleaks.dev\/\">XS leaks<\/a> exploit small pieces of information that are disclosed during interactions between websites. This also includes metadata that is exchanged during this communication.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"Indirect_access_to_resources_worthy_of_protection\"><\/span>Indirect access to resources worthy of protection<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>Even though websites are not allowed to directly access data from other websites, they can load resources from them and observe the side effects. For example, evil.com is prohibited from explicitly reading a response from bank.com, but evil.com can attempt to load a script from bank.com and determine whether or not it has loaded successfully.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"XS_leak_examples\"><\/span>XS leak examples<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The information used for an XS leak usually has a binary form (i.e. o and 1 or TRUE and FALSE) and is referred to as an &ldquo;oracle&rdquo;. A potential attacker obtains information that is definitely worth protecting or at least information that can be used directly for an attack, for example:<\/p>\n<ul>\n<li>Does the word &ldquo;secret&rdquo; appear in the user&rsquo;s data flow to another web application?<\/li>\n<\/ul>\n<p>This question could be synonymous with the question:<\/p>\n<ul>\n<li>Does the query ?query=secret return an HTTP 200 status code?<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"HTTP_Status_Codes_Secrets\"><\/span>HTTP Status Codes &amp; Secrets<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Since it is possible to determine the HTTP 200 status code with error events, this has the same effect as the question:<\/p>\n<ul>\n<li>Does loading a resource of ?query=secret in the application trigger the onload event?<\/li>\n<\/ul>\n<p>The above query could be repeated by an attacker for many different keywords, so the responses could be used to infer sensitive information about the user&rsquo;s data. Browsers offer a variety of different APIs that, while well-intentioned, can still reveal small amounts of cross-origin information.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Reasons_and_causes_of_XS_leaks\"><\/span>Reasons and causes of XS leaks<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The cause of most XS leaks lies in the design of the web, so it is essential that you have a solid knowledge of these technologies. Often applications are prone to cross-page information leaks without having done anything wrong. It is difficult to fix the cause of XS leaks at the browser level, as in many cases this would break existing websites. For this reason, browsers are now implementing various defenses to overcome these difficulties. Many of these defenses require websites and apps that access resources worthy of protection via URLS to opt for a more restrictive security model. This is usually done by using specific HTTP headers (e.g. cross-origin-opener-policy: same-origin), which often need to be combined to achieve the desired result. We can distinguish different sources of XS leaks, such as:<\/p>\n<ul>\n<li><strong>Browser APIs<\/strong> (e.g. frame counting and timing attacks)<\/li>\n<li><strong>Details and errors in the browser implementation<\/strong> (e.g. connection pooling and typeMustMatch)<\/li>\n<li><strong>Hardware errors<\/strong> (e.g. speculative execution attacks)<\/li>\n<\/ul>\n<\/div><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.Apple Podcast - IT Security in Software Development - Podcast Interview with Vladyslav Cherednychenko\" href=\"#\"><iframe style=\"width: 100%; max-width: 660px; overflow: hidden; border-radius: 10px;\" src=\"https:\/\/embed.podcasts.apple.com\/us\/podcast\/folge-8-it-security-in-software-development-podcast\/id1684107786?i=1000626870744\" height=\"175\" frameborder=\"0\" sandbox=\"allow-forms allow-popups allow-same-origin allow-scripts allow-storage-access-by-user-activation allow-top-navigation-by-user-activation\"><\/iframe><\/a>\n<div class=\"fusion-text fusion-text-3\"><h2><span class=\"ez-toc-section\" id=\"Defense_strategies_against_XS_leaks\"><\/span>Defense strategies against XS leaks<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ol>\n<li><strong>Isolation through browser settings<\/strong>: Security headers such as <code>Cross-Origin-Opener-Policy<\/code> (COOP) and <code>Cross-Origin-Embedder-Policy<\/code> (COEP) make it possible to control and minimize the exchange of information between different origins.<\/li>\n<li><strong>Content Security Policy (CSP)<\/strong>: A targeted configuration of CSP can help to block unwanted content and thus prevent XS leaks.<\/li>\n<li><strong>Resource restrictions<\/strong>: Minimize the availability of certain resources (e.g. through server-side <a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/authentication\/\" target=\"_blank\" title=\"Authentication is a multi-step process in identity management. Authentication in an IT system implements IT security functions that are realized by various security services and components.\" class=\"encyclopedia\">authentication<\/a>) to better protect sensitive data.<\/li>\n<\/ol>\n<h3><span class=\"ez-toc-section\" id=\"Examples_of_XS_leaks_in_detail\"><\/span>Examples of XS leaks in detail<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ol>\n<li><strong>Frame counting<\/strong>: Attackers use differences in the number of loaded frames to draw conclusions about user activity.<\/li>\n<li><strong>Timing attacks<\/strong>: By measuring loading times, attackers can determine whether a specific resource exists on another domain.<\/li>\n<li><strong>CSS-based leaks<\/strong>: Style checks with CSS properties such as <code>:visited<\/code> can indirectly provide information about visited pages.<\/li>\n<\/ol>\n<\/div><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.Spotify - Episode 9 - The invisible force behind modern web applications: Why JavaScript engines are so powerful\" href=\"#\"><iframe class=\"lazyload\" style=\"border-radius: 12px;\" src=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%27100%27%20height%3D%27352%27%20viewBox%3D%270%200%20100%20352%27%3E%3Crect%20width%3D%27100%27%20height%3D%27352%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-orig-src=\"https:\/\/open.spotify.com\/embed\/episode\/0kCkWqDG4YpeqKnXKc1qmy?utm_source=generator\" width=\"100%\" height=\"352\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/a>\n<div class=\"fusion-text fusion-text-4\"><h3><span class=\"ez-toc-section\" id=\"Why_are_XS_leaks_difficult_to_prevent\"><\/span>Why are XS leaks difficult to prevent?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>XS leaks often occur due to basic web standards that are necessary for the interoperability of services. Changes to these standards would jeopardize numerous existing web applications. Therefore, security measures rely on the browser and specific protection configurations that must be activated by developers.<\/p>\n<\/div><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.itunes - Episode 9 - The invisible force behind modern web applications: Why JavaScript engines are so powerful\" href=\"#\"><iframe style=\"width: 100%; max-width: 660px; overflow: hidden; border-radius: 10px;\" src=\"https:\/\/embed.podcasts.apple.com\/us\/podcast\/episode-9-the-invisible-force-behind-modern-web\/id1684835330?i=1000630428175\" height=\"175\" frameborder=\"0\" sandbox=\"allow-forms allow-popups allow-same-origin allow-scripts allow-storage-access-by-user-activation allow-top-navigation-by-user-activation\"><\/iframe><\/a>\n<div class=\"fusion-text fusion-text-5\"><h3>Rock the Prototype Podcast<\/h3>\n<p>The <strong>Rock the Prototype Podcast<\/strong> and the <strong>Rock the Prototype YouTube channel<\/strong> are the perfect place to go if you want to delve deeper into the world of web development, <a href=\"https:\/\/rock-the-prototype.com\/en\/prototyping-en\/prototyping\/\" target=\"_blank\" title=\"What is prototyping? Prototyping is both a process and a strategy for realizing ideas as quickly as possible.\" class=\"encyclopedia\">prototyping<\/a> and technology.<\/p>\n<p class=\"p1\"><strong>&#127911; Listen on Spotify: &#128073; Spotify Podcast: <a href=\"https:\/\/bit.ly\/41pm8rL\">https:\/\/bit.ly\/41pm8rL<\/a><\/strong><\/p>\n<p class=\"p1\"><strong><span class=\"s1\">&#127822;<\/span> Enjoy on Apple Podcasts: <span class=\"s1\">&#128073;<\/span>&nbsp;<a href=\"https:\/\/bit.ly\/4aiQf8t\">https:\/\/bit.ly\/4aiQf8t<\/a><\/strong><\/p>\n<p>In the podcast, you can expect exciting discussions and valuable insights into current trends, tools and best practices &ndash; ideal for staying on the ball and gaining fresh perspectives for your own projects. On the YouTube channel, you&rsquo;ll find practical tutorials and step-by-step instructions that clearly explain technical concepts and help you get straight into implementation.<\/p>\n<p><strong>Rock the Prototype YouTube Channel<\/strong><\/p>\n<p>&#128640; Rock the Prototype is &#128073; Your format for exciting topics such as software development, prototyping, software architecture, <a href=\"https:\/\/rock-the-prototype.com\/en\/cloud-computing-cloud-technology\/cloud\/\" target=\"_blank\" title=\"What is cloud? Cloud or cloud computing moves data and programs from desktop PCs or servers in a company to remote cloud servers. Cloud storage therefore consists of a standard server network in a cloud data center or distributed across several cloud server locations.\" class=\"encyclopedia\">cloud<\/a>, DevOps &amp; much more.<\/p>\n<p>&#128250; &#128075;&nbsp;<strong><a href=\"https:\/\/www.youtube.com\/@Rock-the-Prototype\" target=\"_blank\" rel=\"noopener\">Rock the Prototype YouTube Channel<\/a>&nbsp;&#128072;&nbsp; &#128064;&nbsp;<\/strong><\/p>\n<p style=\"padding-left: 40px;\">&#9989; Software development &amp; prototyping<\/p>\n<p style=\"padding-left: 40px;\">&#9989; Learning to program<\/p>\n<p style=\"padding-left: 40px;\">&#9989; Understanding software architecture<\/p>\n<p style=\"padding-left: 40px;\">&#9989; Agile teamwork<\/p>\n<p style=\"padding-left: 40px;\">&#9989; Test prototypes together<\/p>\n<p><strong>THINK PROTOTYPING &ndash; PROTOTYPE DESIGN &ndash; PROGRAM &amp; GET STARTED &ndash; JOIN IN NOW!<\/strong><\/p>\n<h4>Why is it worth checking back regularly?<\/h4>\n<p>Both formats complement each other perfectly: in the podcast, you can learn new things in a relaxed way and get inspiring food for thought, while on YouTube you can see what you have learned directly in action and receive valuable tips for practical application.<\/p>\n<p>Whether you&rsquo;re just starting out in software development or are passionate about prototyping, UX design or IT security. We offer you new technology trends that are really relevant &ndash; and with the Rock the Prototype format, you&rsquo;ll always find relevant content to expand your knowledge and take your skills to the next level!<\/p>\n<\/div>\n<\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\"><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1144px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.Rock the Prototype - Software development &amp; Prototyping Podcast iTunes\" href=\"#\"><iframe id=\"embedPlayer\" style=\"width: 100%; max-width: 660px; overflow: hidden; border-radius: 10px; transform: translateZ(0px); animation: 2s ease 0s 6 normal none running loading-indicator; background-color: #e4e4e4;\" src=\"https:\/\/embed.podcasts.apple.com\/us\/podcast\/rock-the-prototype-software-development-prototyping\/id1684835330?itsct=podcast_box_player&amp;itscg=30200&amp;ls=1&amp;theme=auto\" height=\"450px\" frameborder=\"0\" sandbox=\"allow-forms allow-popups allow-same-origin allow-scripts allow-top-navigation-by-user-activation\"><\/iframe><\/a><\/div><\/div><\/div><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>What is an XS leak or cross-site leak? An XS leak or cross-site leak defines a class of vulnerabilities resulting from side channels implemented in web platforms. <\/p>\n","protected":false},"author":1,"featured_media":3504,"template":"","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0},"categories":[1232],"tags":[1171,1172,3684,2104,3681,3679,3682,3683,1144,1176,3686,3687,3685,1169,1142,3688,3612,3689,1147,1146,1173,1290,1262,1384,1287,1288,3680],"class_list":["post-5398","encyclopedia","type-encyclopedia","status-publish","has-post-thumbnail","hentry","category-it-security","tag-app-en","tag-apps-en","tag-browser-en","tag-conditional-expression","tag-cross-site-leak-en","tag-cross-site-leaks-en","tag-cross-site-request-forgery-en","tag-csrf-3-en","tag-design-pattern-en","tag-frameworks-en","tag-http-status-code","tag-http-status-codes","tag-interactions","tag-javascript-en","tag-programming","tag-secret-en","tag-secret-value-en","tag-secrets-en","tag-software-architecture","tag-software-design-en","tag-web-app-en","tag-web-applications","tag-web-apps-en","tag-webbrowser-en","tag-website-en","tag-websites-en","tag-xs-leaks-en"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>XS-Leak - IT security: Cross-site leaks &amp; XS leaks explained<\/title>\n<meta name=\"description\" content=\"What is an XS leak or cross-site leak? \u2705 Basic principle of XS leaks \u2705 XS leak examples \u2705 HTTP status codes &amp; secrets \u2705\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"XS-Leak - IT security: Cross-site leaks &amp; XS leaks explained\" \/>\n<meta property=\"og:description\" content=\"What is an XS leak or cross-site leak? \u2705 Basic principle of XS leaks \u2705 XS leak examples \u2705 HTTP status codes &amp; secrets \u2705\" \/>\n<meta property=\"og:url\" content=\"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/\" \/>\n<meta property=\"og:site_name\" content=\"Rock the Prototype - Softwareentwicklung &amp; Prototyping\" \/>\n<meta property=\"article:modified_time\" content=\"2025-01-10T14:47:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2022\/02\/XS-Leaks.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"912\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/xs-leak\\\/\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/xs-leak\\\/\",\"name\":\"XS-Leak - IT security: Cross-site leaks & XS leaks explained\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/xs-leak\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/xs-leak\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/XS-Leaks.jpg\",\"datePublished\":\"2025-01-10T06:08:57+00:00\",\"dateModified\":\"2025-01-10T14:47:09+00:00\",\"description\":\"What is an XS leak or cross-site leak? \u2705 Basic principle of XS leaks \u2705 XS leak examples \u2705 HTTP status codes & secrets \u2705\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/xs-leak\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/xs-leak\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/xs-leak\\\/#primaryimage\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/XS-Leaks.jpg\",\"contentUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/XS-Leaks.jpg\",\"width\":1280,\"height\":912,\"caption\":\"XS-Leaks - Was ist ein XS-Leak oder Cross-Site-Leak?\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/xs-leak\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/rock-the-prototype\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Prototyping Wiki\",\"item\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/wiki\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"XS-Leak\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/\",\"name\":\"Rock the Prototype - Softwareentwicklung &amp; Prototyping\",\"description\":\"Prototyping: Software Prototypen, Software entwickeln &amp; Programmieren im Team\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"XS-Leak - IT security: Cross-site leaks & XS leaks explained","description":"What is an XS leak or cross-site leak? \u2705 Basic principle of XS leaks \u2705 XS leak examples \u2705 HTTP status codes & secrets \u2705","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/","og_locale":"en_US","og_type":"article","og_title":"XS-Leak - IT security: Cross-site leaks & XS leaks explained","og_description":"What is an XS leak or cross-site leak? \u2705 Basic principle of XS leaks \u2705 XS leak examples \u2705 HTTP status codes & secrets \u2705","og_url":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/","og_site_name":"Rock the Prototype - Softwareentwicklung &amp; Prototyping","article_modified_time":"2025-01-10T14:47:09+00:00","og_image":[{"width":1280,"height":912,"url":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2022\/02\/XS-Leaks.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/","url":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/","name":"XS-Leak - IT security: Cross-site leaks & XS leaks explained","isPartOf":{"@id":"https:\/\/rock-the-prototype.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#primaryimage"},"image":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#primaryimage"},"thumbnailUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2022\/02\/XS-Leaks.jpg","datePublished":"2025-01-10T06:08:57+00:00","dateModified":"2025-01-10T14:47:09+00:00","description":"What is an XS leak or cross-site leak? \u2705 Basic principle of XS leaks \u2705 XS leak examples \u2705 HTTP status codes & secrets \u2705","breadcrumb":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#primaryimage","url":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2022\/02\/XS-Leaks.jpg","contentUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2022\/02\/XS-Leaks.jpg","width":1280,"height":912,"caption":"XS-Leaks - Was ist ein XS-Leak oder Cross-Site-Leak?"},{"@type":"BreadcrumbList","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/xs-leak\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/rock-the-prototype.com\/en\/rock-the-prototype\/"},{"@type":"ListItem","position":2,"name":"Prototyping Wiki","item":"https:\/\/rock-the-prototype.com\/en\/wiki\/"},{"@type":"ListItem","position":3,"name":"XS-Leak"}]},{"@type":"WebSite","@id":"https:\/\/rock-the-prototype.com\/en\/#website","url":"https:\/\/rock-the-prototype.com\/en\/","name":"Rock the Prototype - Softwareentwicklung &amp; Prototyping","description":"Prototyping: Software Prototypen, Software entwickeln &amp; Programmieren im Team","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/rock-the-prototype.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/encyclopedia\/5398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/encyclopedia"}],"about":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/types\/encyclopedia"}],"author":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/users\/1"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/media\/3504"}],"wp:attachment":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/media?parent=5398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/categories?post=5398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/tags?post=5398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}