Later archive addition
Weaponizing the Web / MonkeyFist
Introduces MonkeyFist for constructing dynamic cross-site requests using leaked referrer state or separately retrievable values. Configurable redirect, form and session-fixation handlers illustrate how unique-looking tokens can fail when they are not bound to the victim’s session, with user-generated-content and service-integration examples.
Record
- Researcher
- Nathan Hamiel and Shawn Moyer
- Published by
- Black Hat USA
- Format
- Whitepaper
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Nathan Hamiel and Shawn Moyer, first published at the original source. Preserved copies are kept so the citation survives its host.