Web Hack List

Collected research

I used to know what you watched, on YouTube (CSRF + Crossdomain.xml)

I <i>used to</i> know what you watched, on YouTube

YouTube's crossdomain.xml trusted *.google.com, so a SWF hosted anywhere on google.com could act as the victim on YouTube. Grossman mailed a SWF to a Gmail account he controlled, then used the Stanford login-CSRF/identity-misbinding trick to force the victim into that Gmail session so the attachment URL would load, giving read/write access to their account.

Record

Document
I <i>used to</i> know what you watched, on YouTube
Researcher
Jeremiah Grossman
Published by
blog.jeremiahgrossman.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .