Web Hack List

Collected research

Zoom Session Takeover - Cookie Tossing Payloads, OAuth Dirty Dancing, Browser Permissions Hijacking, and WAF abuse

An XSS in a nonce cookie reflects into every CSP nonce on the domain; an XSS on a neglected subdomain tosses that cookie across the domain, giving persistent XSS nearly everywhere. The chain steals a Google authorization code by OAuth dirty dancing, reuses granted camera and microphone permissions, and tosses a script-tagged cookie so the WAF locks the victim out.

Record

Researcher
Sudi, BrunoZero and H4R3L
Published by
Harel Security Research
Date
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sudi, BrunoZero and H4R3L, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .