Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 49 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow XSS combined with CSRF
EH-Net
May 18, 2013, 08:52:59 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: XSS combined with CSRF  (Read 3438 times)
0 Members and 1 Guest are viewing this topic.
mn_kthompson
Jr. Member
**
Offline Offline

Posts: 58



View Profile WWW
« on: April 02, 2007, 10:00:53 AM »

I found an interesting article over at the Dark Reading website about a technique that was recently covered at Black Hat Europe.  The hack involves combining XSS and CSRF to gain control of a browser and launch attacks against other sites using the users level of access. 

An example giving in the article would be to gain control of a corporate users browser and then attack corporate servers from inside the firewall.

http://www.darkreading.com/document.asp?doc_id=120801&WT.svl=news1_4

If you're like me, and you've never heard of CSRF before, you can read about it in more detail at wikipedia!  http://en.wikipedia.org/wiki/CSRF
Logged
Craig
EH-Net Columnist
Jr. Member
*****
Offline Offline

Posts: 69


View Profile WWW
« Reply #1 on: April 02, 2007, 10:54:26 AM »

XSS and CSRF are everywhere, and I don't think that most people are really taking them seriously enough. There are some really awesome XSS attacks that can be done, and as this article shows, when combined with CSRF you aren't safe from them even if your site has no XSS what so ever. I'd reccommend checking out sla.ckers.org, ha.ckers.org and jeremiah grossman's blog, they all have a lot of cool XSS-related information.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.