Collected research
Generic cross-browser cross-domain theft
Browsers sent cookies on cross-domain CSS loads and let the CSS parser skip any leading junk, so an attacker who controls two injection points in a victim page can wrap its response in a CSS string and exfiltrate it through a background-image URL. Demonstrated against Yahoo! Mail to steal subjects and anti-XSRF mid tokens; works with JavaScript disabled.
Record
- Researcher
- Chris Evans
- Published by
- scarybeastsecurity.blogspot.com
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .