Other nomination
Generic cross-browser cross-domain theft
Browsers sent cookies on cross-domain CSS loads and let the CSS parser skip any leading junk, so an attacker who controls two injection points in a victim page can wrap its response in a CSS string and exfiltrate it through a background-image URL. Demonstrated against Yahoo! Mail to steal subjects and anti-XSRF mid tokens; works with JavaScript disabled.
Record
- Researcher
- Chris Evans
In the archive
- Nominated for the 2009 Top 10 Web Hacking Techniques
- Nominated for the 2010 Top 10 Web Hacking Techniques
Tags
This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host.