Collected research
UI Redressing Mayhem: Firefox 0-Day And The LeakedIn Affair
UI Redressing Mayhem: Firefox 0day and the LeakedIn affair
Mozilla had killed cross-domain drag and drop, so this post revives it by framing both the victim page and the attacker's dropper page as two iframes of one malicious page, a case Firefox 17.0.1 never checked. Applied to LinkedIn it drags out the csrfToken, adds an attacker email to the profile and confirms it over IMAP, yielding a full password reset.
Record
- Document
- UI Redressing Mayhem: Firefox 0day and the LeakedIn affair
- Researcher
- Luca De Fulgentis
- Published by
- blog.nibblesec.org
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Luca De Fulgentis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .