Full Disclosure mailing list archives

Re: Google Buzz and blind CSRF attacks


From: Fabien VINCENT <fabvincent () gmail com>
Date: Mon, 15 Feb 2010 09:30:59 +0100

It works for me, thanks Kristian Erik for this found !

I tried to inject an IMG tag with XSRF URL into Google Reader in my
Share, and all my Followers were disconnect from Google SSO each time
they visit my Shared items in GReader. As GReader shared items are also
shared in Google Buzz, the PoC worked, but only for some hours.

It seems that Google doesn't accept <img> tags anymore in GBuzz ?

I wrote a quick article on my blog, thanks to your PoC Kristian ! It's
available here :
http://blog.beufa.net/2010/02/xsrf-in-google-reader-and-google-buzz.html

Regards,

--------------------------------------------------------
*Fabien VINCENT*
--------------------------------------------------------

Le 12/02/2010 18:48, Kristian Erik Hermansen a écrit :
On Fri, Feb 12, 2010 at 7:08 AM, Cody Robertson <cody () hawkhost com> wrote:
  
Doesn't work for me
    
It has been verified against multiple GMail users.  You can try the
direct link as well, but the issue is more effective within the "Buzz"
interface.  It doesn't look like you tested from a gmail account
either (hawkhost.com?)...

http://kristian-hermansen.blogspot.com/2010/02/google-buzz-csrf-test.html
  

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: