Collected research
CSRF token disclosure via iFRAME and CAPTCHA trickery
Attackers can abuse Yahoo developer feature to steal user emails, other data
A news report on Sergiu Dragos Bogdan's DefCamp talk: the Yahoo Developer Network YQL console can be framed, showing the victim a session-bound "crumb" token. Same-origin rules stop the attacker reading the frame, so he dressed the crumb up as a CAPTCHA challenge; typing it back authorised YQL queries against the victim's own mail and contacts.
Record
- Document
- Attackers can abuse Yahoo developer feature to steal user emails, other data
- Researcher
- Lucian Constantin
- Published by
- Computerworld
- Date
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Lucian Constantin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .