Web Hack List

Collected research

Backchannel Leaks on Strict Content-Security Policy

Under a strict default-src 'self' policy the browser still allows outbound requests to unapproved hosts. Chrome does not enforce CSP on link rel=prerender, and Chrome, Firefox and Safari all follow a meta http-equiv=refresh redirect, so either tag gives an out-of-band channel for exfiltration and for triggering blind XSS callbacks without JavaScript.

Record

Researcher
Mazin Ahmed and @mazen160
Published by
Mazin Ahmed
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mazin Ahmed and @mazen160, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .