Collected research
Hacking CSRF Tokens using CSS History Hack
CSRF tokens carried in URLs can be brute-forced entirely on the client using the CSS visited-link history hack, generating no server traffic for an IDS or WAF to see. A five-character base16 token space was exhausted in under two minutes. Defences given: longer tokens, hidden form fields, per-submission tokens, SafeHistory or private browsing.
Record
- Published by
- securethoughts.com
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of securethoughts.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .