ContentsThe library

Proving Who You Are

The Request Your Browser Sent for Somebody Else

Last timeSigning In Somewhere Else

A page on another site can cause your browser to send a request to yours, carrying your session. The attack is a few lines of markup, and the defences follow from how it works.

The attack, in markup

Here is the whole attack. A person is signed in to your site in one tab.

In another tab they open a page somewhere else entirely, perhaps from a

search result or a link in a message. That page contains this.

FIG 1The attacker page
plaintext
a form that submits itself

  <form method='post' action='https://bank.northwind.co/transfer'>
    <input type='hidden' name='to' value='attacker-account'>
    <input type='hidden' name='amount' value='4000'>
  </form>
  <script>document.forms[0].submit()</script>

the same thing, if a read method performs the action

  <img src='https://bank.northwind.co/transfer?to=attacker&amount=4000'>

what the attacker can see of the response

  nothing at all

why that does not matter

  the effect already happened on the server
No exploit, no vulnerability in the browser, no stolen credential. A form with an action pointing at your site and a line of script that submits it, or in the second case a single image tag. The person sees a blank page, or a broken image, and nothing else.

The browser sends the request to your site. Because it is going to your

site, the browser attaches your cookies, including the session cookie. Your

server receives a well-formed, correctly authenticated request to move

money, and does it.

The attacker cannot read the response. The same-origin policy sees to that,

and it is why this attack is about actions rather than about reading data.

It does not matter: the transfer has happened.

Why the browser helps

The behaviour that makes this work is simple and is not a bug.

Cookies are attached by destination. When the browser prepares a request to

your site, it looks at which cookies belong to your site and attaches them.

It does not consider which page caused the request, because for almost all

of the web that would be the wrong thing to consider: an image, a

stylesheet or a link from another site should still arrive with the session

attached, or the web would not work.

The lesson stops here

2 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Who You Are, What You May Do, and Who Remembers
  2. 02What Each Kind of Proof Actually Resistsopening only
  3. 03The Thing the Browser Carriesopening only
  4. 04The Token That Answers for Itselfopening only
  5. 05Two Tokens Beat Oneopening only
  6. 06Borrowing Somebody Elses Proofopening only
  7. 07The Request Your Browser Sent for Somebody Elseyou are here
  8. 08Making Somebody Stop Being Signed Inopening only

Read alongside