Collected research
CSS Data Exfiltration to Steal OAuth Token
Combines an OAuth redirect with CSS injection on a page where an advertising script reflects the URL token into a DOM attribute. Imported styles test that attribute and signal matches through background requests; the writeup diagnoses cascade failures and increases selector specificity between rounds to continue extracting the token.
Record
- Researcher
- Amirmohammad Safari and Yashar Shahinzadeh
- Published by
- Voorivex
- Date
- Topic
- Identity
In the archive
Related sources
- CSS-Exfiltration Code
- CSS exfiltration test environment
- CSS specificity demonstration
- CSS specificity adjustment demonstration
- OAuth token CSS exfiltration code
- Blind CSS exfiltration original implementation
Tags
This page is the archive's own catalogue record. The research is the work of Amirmohammad Safari and Yashar Shahinzadeh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .