Hacker News new | ask | show | jobs
by cottenio 2760 days ago
Correct. It's more valuable, especially when trying to exfiltrate data or when trying to inject XSS opportunities.

Plus, realistically, SLEEP allows you to scan for thousands of different test cases in a quick period and measure the hang time to figure out which vector worked.