Web Hack List

Other nomination

I used to know what you watched, on YouTube (CSRF + Crossdomain.xml)

YouTube's crossdomain.xml trusted *.google.com, so a SWF hosted anywhere on google.com could act as the victim on YouTube. Grossman mailed a SWF to a Gmail account he controlled, then used the Stanford login-CSRF/identity-misbinding trick to force the victim into that Gmail session so the attachment URL would load, giving read/write access to their account.

Record

Researcher
Jeremiah Grossman
Published by
blog.jeremiahgrossman.com

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman, first published at the original source. Preserved copies are kept so the citation survives its host.