Web Hack List

Top 10 winner

Abusing Flash-Proxies for client-side cross-domain HTTP requests

Biting the hand that serves you: A closer look at client-side Flash proxies for cross-domain requests

A cross-domain Flash applet keeps the origin of its SWF, not of the embedding page, so any page embedding someone else's Flash HTTP proxy can issue requests under that proxy's origin. A survey of five published proxies found three exploitable through allowDomain("*"). Proposed fixes: nonce-gated SWF delivery, a config-file domain list, and a fragment-redirect check of the caller's URL.

Record

Document
Biting the hand that serves you: A closer look at client-side Flash proxies for cross-domain requests
Researcher
Martin Johns and Sebastian Lekies
Published by
polyboy.net
Format
Whitepaper
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Martin Johns and Sebastian Lekies, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .