Web Hack List

Top 10 winner

Exploiting Unexploitable XSS

Google's ServiceLogin auth URLs let an attacker silently log a victim into an account the attacker controls, and Google CSRF tokens were bound to the account rather than the session. Combining the two turned self-only and CSRF-protected XSS in Google Sites, Blogger and YouTube into fully exploitable ones. Twitter fell to the same idea via login CSRF plus its persistent Remember-me cookie.

Record

Published by
stephensclafani.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of stephensclafani.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .