Web Hack List

Collected research

CSRF with MS Word

David Kierznowski turns Microsoft Word into a CSRF client by inserting a frame pointing at an attacker-controlled HTML page full of image tags. Word fetches it through Internet Explorer with no warning in Word 2000, so the requests fire every time the document is opened, and the attacker can retarget them later via 302 redirects or by editing the hosted page.

Record

Researcher
David Kierznowski
Published by
michaeldaw.org
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of David Kierznowski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .