Collected research
Exploiting CSRF Protected XSS
CSRF tokens do not make an XSS unexploitable, because nothing forces the victim to use their own session. Make the browser send the attacker's cookie, matching token and payload at once, via Flash addRequestHeader after emptying the cookie jar, a path-scoped cookie set from a sibling subdomain, or a URL session id once RequestRodeo strips cookies.
Record
- Researcher
- kuza55
- Published by
- kuza55.blogspot.com
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of kuza55, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .