Web Hack List

Top 10 winner

CSRF: Flash + 307 redirect = Game Over

[WEB SECURITY] CSRF: Flash + 307 redirect = Game Over

A Flash file served with a permissive crossdomain.xml can set arbitrary headers and POST body, then follow a 307 redirect to the victim host; Flash keeps the attacker's policy instead of re-checking the target's, so the POST arrives with custom headers and cookies. That defeats CSRF defences that trust a custom header alone, as Rails did. Tested across Chrome, Safari and Firefox.

Record

Document
[WEB SECURITY] CSRF: Flash + 307 redirect = Game Over
Researcher
Phillip Purviance
Published by
Web Application Security Consortium
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Phillip Purviance, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .