Top 10 winner
CSRF: Flash + 307 redirect = Game Over
A Flash file served with a permissive crossdomain.xml can set arbitrary headers and POST body, then follow a 307 redirect to the victim host; Flash keeps the attacker's policy instead of re-checking the target's, so the POST arrives with custom headers and cookies. That defeats CSRF defences that trust a custom header alone, as Rails did. Tested across Chrome, Safari and Firefox.
Record
- Researcher
- Phillip Purviance
- Published by
- Web Application Security Consortium
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Phillip Purviance, first published at the original source. Preserved copies are kept so the citation survives its host.