Files

12 lines
820 B
Plaintext

client: replay.sh
----------------------------------------------------------------------------------------
C0 control: genuine form, same-origin, token present -> wiener.new@ -> HTTP 200
A1 §3.1 GET /change-email?email=attacker, token dropped, cross-site -> HTTP 405
A2 §3.2B GET …&_method=POST (method override), cross-site -> HTTP 405
A3 §3.2A POST, token absent, cross-site form -> HTTP 403
A4 POST from evil.example.com (same-site sibling), token absent -> HTTP 403
A5 POST with allowed Origin, token absent (layer 3 alone must hold) -> HTTP 403
A6 POST with allowed Origin, token from another session -> HTTP 403
----------------------------------------------------------------------------------------
final state: current email: [email protected]