ipositivesecurity-The-Atlantic

Thursday, July 23, 2009

Hacking CSRF Tokens using CSS History Hack

Detailed write up on new CSRF Token hack using CSS History:

http://securethoughts.com/2009/07/hacking-csrf-tokens-using-css-history-hack/

Proof of Concept here:

http://www.securethoughts.com/security/csrfcsshistory/csrfscan.html

Best Regards.

Posted by Unknown at 11:52 PM
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: CSRF Token hack, CSS History, Inferno, Proof of Concept, Web Application Assessment, Web Application Security

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

About Me

Unknown
View my complete profile

Blog Archive

  • ►  2013 (4)
    • ►  August (2)
    • ►  June (1)
    • ►  February (1)
  • ►  2012 (9)
    • ►  December (3)
    • ►  August (2)
    • ►  January (4)
  • ►  2011 (17)
    • ►  December (3)
    • ►  November (1)
    • ►  August (4)
    • ►  July (4)
    • ►  June (1)
    • ►  April (3)
    • ►  March (1)
  • ►  2010 (19)
    • ►  December (2)
    • ►  September (2)
    • ►  July (2)
    • ►  June (5)
    • ►  April (1)
    • ►  March (3)
    • ►  February (2)
    • ►  January (2)
  • ▼  2009 (33)
    • ►  December (8)
    • ►  November (1)
    • ►  October (1)
    • ►  August (2)
    • ▼  July (6)
      • Presentation: Botnets
      • RainbowCrack 1.4
      • Hacking CSRF Tokens using CSS History Hack
      • Anatomy of a Twitter Attack.
      • Quick update: Botnet lab test
      • Back...
    • ►  June (5)
    • ►  May (6)
    • ►  April (4)
Awesome Inc. theme. Powered by Blogger.