Web Hack List

Later archive addition

Stealing CSRF tokens with CSS injection (without iFrames)

The project demonstrates exfiltrating CSRF tokens with CSS injection and attribute selectors, without relying on iframes. Repeated selector rules test token prefixes and trigger outbound requests for matches, allowing a secret value embedded in the page to be reconstructed one character at a time.

Record

Researcher
dxa4481
Published by
GitHub
Format
Repository

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of dxa4481, first published at the original source. Preserved copies are kept so the citation survives its host.