Web Hack List

Other nomination

The Case of the Unconventional CSRF Attack in Firefox

Firefox 21 and earlier ignored the XHR rule that a HEAD request must have its body set to null, so send(data) after open("HEAD") still transmitted the body cross-origin with cookies attached. Against an application that accepts verb tampering this yields a CSRF that POST-shaped defences never see. Fixed in Firefox 22 as CVE-2013-1692.

Record

Researcher
Kuskos
Published by
WhiteHat Security

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Kuskos, first published at the original source. Preserved copies are kept so the citation survives its host.