Other nomination
I used to know what you watched, on YouTube (CSRF + Crossdomain.xml)
YouTube's crossdomain.xml trusted *.google.com, so a SWF hosted anywhere on google.com could act as the victim on YouTube. Grossman mailed a SWF to a Gmail account he controlled, then used the Stanford login-CSRF/identity-misbinding trick to force the victim into that Gmail session so the attachment URL would load, giving read/write access to their account.
Record
- Researcher
- Jeremiah Grossman
- Published by
- blog.jeremiahgrossman.com
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman, first published at the original source. Preserved copies are kept so the citation survives its host.