Web Hack List

Collected research

Generic cross-browser cross-domain theft

Browsers sent cookies on cross-domain CSS loads and let the CSS parser skip any leading junk, so an attacker who controls two injection points in a victim page can wrap its response in a CSS string and exfiltrate it through a background-image URL. Demonstrated against Yahoo! Mail to steal subjects and anti-XSRF mid tokens; works with JavaScript disabled.

Record

Researcher
Chris Evans
Published by
scarybeastsecurity.blogspot.com
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .