HN user

telechair

4 karma
Posts0
Comments1
View on HN
No posts found.

It's odd the author thinks they're introducing the world to some new class of vulnerability. There's been a least a few presentations about it as far back as 2009, and is generally a known thing in web security.

[1]. G. Heyes, D. Lindsay, and E.V. Nava, “The Sexy Assassin: Tactical Exploitation Using CSS” (2009), http://slideplayer.com/slide/3493669/

[2] [CSSconf.eu 2013] Mike West - XSS. (No, the _other_ "S"), https://youtu.be/eb3suf4REyI?t=582

[3] https://twitter.com/blubbfiction/status/657632031845826560

[4] Demo PoC http://eaea.sirdarckcat.net/cssar/v2/