lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 15 Feb 2010 09:30:59 +0100
From: Fabien VINCENT <fabvincent@...il.com>
To: Kristian Erik Hermansen <kristian.hermansen@...il.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: Google Buzz and blind CSRF attacks

It works for me, thanks Kristian Erik for this found !

I tried to inject an IMG tag with XSRF URL into Google Reader in my
Share, and all my Followers were disconnect from Google SSO each time
they visit my Shared items in GReader. As GReader shared items are also
shared in Google Buzz, the PoC worked, but only for some hours.

It seems that Google doesn't accept <img> tags anymore in GBuzz ?

I wrote a quick article on my blog, thanks to your PoC Kristian ! It's
available here :
http://blog.beufa.net/2010/02/xsrf-in-google-reader-and-google-buzz.html

Regards,

--------------------------------------------------------
*Fabien VINCENT*
--------------------------------------------------------

Le 12/02/2010 18:48, Kristian Erik Hermansen a écrit :
> On Fri, Feb 12, 2010 at 7:08 AM, Cody Robertson <cody@...khost.com> wrote:
>   
>> Doesn't work for me
>>     
> It has been verified against multiple GMail users.  You can try the
> direct link as well, but the issue is more effective within the "Buzz"
> interface.  It doesn't look like you tested from a gmail account
> either (hawkhost.com?)...
>
> http://kristian-hermansen.blogspot.com/2010/02/google-buzz-csrf-test.html
>   

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ