Defeating CSRF Protections Through Expired cross-domain.xml Domains
netspi.com | blog | #csrf | #flash | #web-pentesting | #cross-origin | #crossdomain-xml | #domain-expiry
Summary
Shows how registering an expired domain listed in a site's crossdomain.xml grants full Flash cross-domain access and defeats CSRF protections, with a Python scanner to discover such policies.
- Published
- Collected
Skip to content