csrf-token-extraction

2 articles
sort: new top best
clear filter
0 9/10

A critical XSS vulnerability on Facebook's CDN was achieved by encoding malicious JavaScript into PNG IDAT chunks, uploading the image as an advertisement, then serving it with an .html extension to trigger HTML interpretation via MIME sniffing. The attacker leveraged document.domain to access the fb_dtsg CSRF token from www.facebook.com and bypass LinkShim protections.

Facebook Akamai akamaihd.net fbcdn.net photo.facebook.com fnt.pe phwd
whitton.io · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

A reflected XSS vulnerability in an OAuth2 redirect_uri parameter was escalated from simple alert injection to account takeover by extracting CSRF tokens from meta tags and automating admin user creation without authentication. The writeup demonstrates a practical methodology for showing XSS impact through functional exploitation rather than simple proof-of-concept.

HackerOne XMLHttpRequest FormData
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details