Collected research
I used to know what you watched, on YouTube (CSRF + Crossdomain.xml)
I <i>used to</i> know what you watched, on YouTube
YouTube's crossdomain.xml trusted *.google.com, so a SWF hosted anywhere on google.com could act as the victim on YouTube. Grossman mailed a SWF to a Gmail account he controlled, then used the Stanford login-CSRF/identity-misbinding trick to force the victim into that Gmail session so the attachment URL would load, giving read/write access to their account.
Record
- Document
- I <i>used to</i> know what you watched, on YouTube
- Researcher
- Jeremiah Grossman
- Published by
- blog.jeremiahgrossman.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .