Can I take Your Subdomain?

Exploring Same-Site Attacks in the Modern Web

Marco Squarcina1, Mauro Tempesta1, Lorenzo Veronese1, Stefano Calzavara2, Matteo Maffei1
1 TU Wien, 2 Università Ca’ Foscari Venezia & OWASP
30th USENIX Security Symposium (USENIX Security ‘21), August 11–13, 2021 (to appear)

Service # Domains PSL
afraid (FreeDNS) 52443   0/52443
duckdns 1   1/1
dyndns 293   287/293
noip 91   85/91
securepoint 10   10/10