Web Hack List

Collected research

Weaponizing the Web / MonkeyFist

Weaponizing the Web: More Attacks on User Generated Content

Introduces MonkeyFist for constructing dynamic cross-site requests using leaked referrer state or separately retrievable values. Configurable redirect, form and session-fixation handlers illustrate how unique-looking tokens can fail when they are not bound to the victim’s session, with user-generated-content and service-integration examples.

Record

Document
Weaponizing the Web: More Attacks on User Generated Content
Researcher
Nathan Hamiel and Shawn Moyer
Published by
Black Hat USA
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Nathan Hamiel and Shawn Moyer, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .