Top 10 winner
CSRF: Flash + 307 redirect = Game Over
[WEB SECURITY] CSRF: Flash + 307 redirect = Game Over
A Flash file served with a permissive crossdomain.xml can set arbitrary headers and POST body, then follow a 307 redirect to the victim host; Flash keeps the attacker's policy instead of re-checking the target's, so the POST arrives with custom headers and cookies. That defeats CSRF defences that trust a custom header alone, as Rails did. Tested across Chrome, Safari and Firefox.
Record
- Document
- [WEB SECURITY] CSRF: Flash + 307 redirect = Game Over
- Researcher
- Phillip Purviance
- Published by
- Web Application Security Consortium
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Phillip Purviance, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .