Collected research
Backchannel Leaks on Strict Content-Security Policy
Under a strict default-src 'self' policy the browser still allows outbound requests to unapproved hosts. Chrome does not enforce CSP on link rel=prerender, and Chrome, Firefox and Safari all follow a meta http-equiv=refresh redirect, so either tag gives an out-of-band channel for exfiltration and for triggering blind XSS callbacks without JavaScript.
Record
- Researcher
- Mazin Ahmed and @mazen160
- Published by
- Mazin Ahmed
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mazin Ahmed and @mazen160, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .