Web Hack List

Collected research

AJAX Hammer — Harnessing AJAX for Dynamic CSRF

An intranet-classified page uses permissive browser zones and user-approved cross-domain XMLHttpRequest to read authenticated responses. It can extract CSRF tokens and ViewState, adapt subsequent requests, and send custom headers or JSON bodies. Requires matching scheme and port and the victim’s confirmation.

Record

Researcher
Oren Ofer
Published by
Hacktics Advanced Security Center, Ernst & Young
Date
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Oren Ofer, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .