Web Hack List

Later archive addition

Weaponizing the Web / MonkeyFist

Introduces MonkeyFist for constructing dynamic cross-site requests using leaked referrer state or separately retrievable values. Configurable redirect, form and session-fixation handlers illustrate how unique-looking tokens can fail when they are not bound to the victim’s session, with user-generated-content and service-integration examples.

Record

Researcher
Nathan Hamiel and Shawn Moyer
Published by
Black Hat USA
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Nathan Hamiel and Shawn Moyer, first published at the original source. Preserved copies are kept so the citation survives its host.