Web Hack List

Other nomination

Why CSP Should be carefully crafted: Twitter XSS CSP Bypass

Twitter checked an app's Terms of Service URL with a regex that lacked a leading anchor, so data:text/html,<payload>#https:// passed and gave HTML injection. The CSP allowed unsafe-inline and trusted syndication.twitter.com, which serves JSONP: fetching a timeline widget with callback=alert runs attacker-chosen code, and Chrome executes it despite a Content-Disposition attachment header. The callback can also name a page method for same-origin method execution.

Record

Published by
Paulos Yibelo - Hacking Research

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Paulos Yibelo - Hacking Research, first published at the original source. Preserved copies are kept so the citation survives its host.