Pinned Repositories
BranchDifferent
Implementation for the DIMVA'22 paper "Branch Different - Spectre Attacks on Apple Silicon"
browser-cpu-fingerprinting
This repository contains the code for our paper "Browser-based CPU Fingerprinting".
CacheWarp
Proof-of-concept implementation for the paper "CacheWarp: Software-based Fault Injection using Selective State Reset" (USENIX Security 2024)
GhostWrite
Proof-of-concept for the GhostWrite CPU bug.
loop-DoS
Repository for application-layer loop DoS
Microarchitectural-Hash-Function-Recovery
Proof-of-concept implementation for the paper "Efficient and Generic Microarchitectural Hash-Function Recovery" (IEEE S&P 2024)
mwait
Proof-of-concept implementation for the paper "(M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side Channels" (USENIX Security'23)
osiris
Proof-of-concept implementation for the paper "Osiris: Automated Discovery of Microarchitectural Side Channels" (USENIX Security'21)
persistent-clientside-xss
Exploit generator and Taint Engine to find persistent (and reflected) client-side XSS
Security-RISC
Proof-of-concept implementation for the paper "A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUs" (IEEE S&P 2023)
cispa's Repositories
cispa/GhostWrite
Proof-of-concept for the GhostWrite CPU bug.
cispa/CacheWarp
Proof-of-concept implementation for the paper "CacheWarp: Software-based Fault Injection using Selective State Reset" (USENIX Security 2024)
cispa/Security-RISC
Proof-of-concept implementation for the paper "A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUs" (IEEE S&P 2023)
cispa/browser-cpu-fingerprinting
This repository contains the code for our paper "Browser-based CPU Fingerprinting".
cispa/loop-DoS
Repository for application-layer loop DoS
cispa/Microarchitectural-Hash-Function-Recovery
Proof-of-concept implementation for the paper "Efficient and Generic Microarchitectural Hash-Function Recovery" (IEEE S&P 2024)
cispa/mwait
Proof-of-concept implementation for the paper "(M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side Channels" (USENIX Security'23)
cispa/indirect-meltdown
Proof-of-concept implementation for the paper "Indirect Meltdown: Building Novel Side-Channel Attacks from Transient Execution Attacks" (ESORICS 2023)
cispa/xs-observations
Code for our 2023 IEEE S&P Paper "The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web"
cispa/hammulator
Proof-of-concept implementation for the paper "Hammulator: Simulate Now - Exploit Later" (DRAMSec 2023)
cispa/regcheck
Proof-of-concept implementation for the paper "Reviving Meltdown 3a" (ESORICS 2023)
cispa/http-conformance
Code for our 2024 ACM AsiaCCS Paper "Who's Breaking the Rules? Studying Conformance to the HTTP Specifications and its Security Impact"
cispa/Switchpoline
Proof-of-concept implementation for the paper "Switchpoline: A Software Mitigation for Spectre-BTB and Spectre-BHB on ARMv8" (AsiaCCS 2024)
cispa/gdpr-consent
Code for our paper: "Share First, Ask Later (or Never?) - Studying Violations of GDPR's Explicit Consent in Android Apps"
cispa/login-security-landscape
Code for our 2024 IEEE S&P Paper "To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security Landscape"
cispa/IRQGuard
cispa/cascading-spy-sheets
This repository contains the artifact for our paper "Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting" published at NDSS 2025.
cispa/micsec-training
The material for the hands-on session "Turning Timing Differences into Data Leakage" at Mic-Sec 2022
cispa/12-angry-developers-web-applications
This repository contains our code for each version (programming language) for the Coding Task. It is a product of our work published at the 28th ACM Conference on Computer and Communications Security (CCS) in 2021.
cispa/consent-notices
cispa/DNS-Applayer-DDoS-Protection
Code and datasets for protecting DNS infrastructures against application-layer DDoS attacks (EuroS&P '23 paper)
cispa/analogdevices-hdl-lib
HDL libraries and projects
cispa/cva6
The CORE-V CVA6 is an Application class 6-stage RISC-V CPU capable of booting Linux
cispa/cva6-sdk
CVA6 SDK containing RISC-V tools and Buildroot
cispa/CVA6-Vivado-Project-with-Xilinx-AXI-Ethernet
Vivado 2023.2 project built around the CVA6 RISC-V CPU and a software stack including u-boot and embedded linux.
cispa/Ethical-Server-Side-Scanning
Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy Research - Supplementary Material
cispa/html-violations-analyzer
cispa/internet-archive-study
This repository contains the crawling scripts used for the paper "You Call This Archaeology? Evaluating Web Archives for Reproducible Web Security Measurements"
cispa/trust-me-if-you-can
cispa/Verification-Disjunctive-Time-Networks