Web Hack List

Collected research

Exploiting CSRF Protected XSS

CSRF tokens do not make an XSS unexploitable, because nothing forces the victim to use their own session. Make the browser send the attacker's cookie, matching token and payload at once, via Flash addRequestHeader after emptying the cookie jar, a path-scoped cookie set from a sibling subdomain, or a URL session id once RequestRodeo strips cookies.

Record

Researcher
kuza55
Published by
kuza55.blogspot.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of kuza55, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .