WebApp Sec mailing list archives

CSRF attack in Firefox


From: Vishal Garg <vishal () firstbase co uk>
Date: Tue, 18 Mar 2008 14:46:50 +0000

Hi List,

I have tested the following attack in Firefox and it has worked successfully, while I would not have expected this to work because of the same origin policy in Firefox. The Firefox version I am using is 2.0.0.12.

http://www.victim.com/webapp/wcs/servlet/ImagePopup?storeId=111&imageName=image1.jpg&imageText=%3Cimg%20src=http://www.attacker.com/images/image2.jpg%3E

Can someone please explain why this attack works in Firefox.

Thanks in advance...

cheers
Vishal



-------------------------------------------------------------------------
Sponsored by: Watchfire Methodologies & Tools for Web Application Security Assessment With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? Download this Whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=70170000000940F
-------------------------------------------------------------------------


Current thread: