Later archive addition
Stealing CSRF tokens with CSS injection (without iFrames)
The project demonstrates exfiltrating CSRF tokens with CSS injection and attribute selectors, without relying on iframes. Repeated selector rules test token prefixes and trigger outbound requests for matches, allowing a secret value embedded in the page to be reconstructed one character at a time.
Record
- Researcher
- dxa4481
- Published by
- GitHub
- Format
- Repository
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of dxa4481, first published at the original source. Preserved copies are kept so the citation survives its host.