Hosting generously provided by
www.mv.com





Pick Your Language


02/25/2007 Cross-site Request Forgery and Blackhat SEO
I research whitehat and blackhat SEO in my spare time (however not on this domain :), and was thinking about some additional uses for Cross-site Request forgery from the blackhat SEO perspective.

* Publishing/Spamming links: People spamming forums with links is nothing new. By utilizing CSRF on the otherhand you could force a website user base (either by embedding it into your site html directly, or by utilizing an XSS vulnerability) to submit forms with your url without their knowledge using the img javascript trick (as described about in the Cross-site Request Forgery FAQ.

* Redirectors: Search engines and sites displaying a sites rank (blogs, top sites community, top referers/incoming site links, etc...) count the number of times a specific url is clicked or visited. As described above if you can get the user to visit the site via CSRF, then you can potentially influence these counters using unique hostnames/sessions (if logged in already). I suspect this will start becoming a real issue within the next year. One of the issues with CSRF is that the referer is typically sent to the target site. These can be easily hidden by utilizing an open relay issue on a totally non related site. This will make that site show up in the referers instead of the site containing the CSRF payload.

CSRF is where Cross site scripting was 5 years ago and new and more interesting uses are going to keep being discovered. This vuln is in it for the long haul.

Link to this Story: 02/25/2007 Cross-site Request Forgery and Blackhat SEO
Link: Have a Site Suggestion, Material Request, or News? Submit it!
News RSS Feed: Web Security news RSS Feed

     



External Links:
Copyright 2000-2007 Cgisecurity.com.
Providing Web Security news since 2000.
Information contained on this website may not be copied without explicit permission.
Best Viewed with Netscape.
Website Security Web Application Security solid state drives ssd ebay ebay topdeals nslookup online buy macbook air not work safe software security


Popular Links By Subject

Sponsored Link (Advertise)


Subscribe to CGISecurity.com


The Web Security Mailing List
  • Re: [WEB SECURITY] Scripting Question
  • Re: [WEB SECURITY] Scripting Question
  • Re: [WEB SECURITY] Scripting Question
  • Re: [WEB SECURITY] Scripting Question
  • Re: [WEB SECURITY] Scripting Question
  • [WEB SECURITY] WASC Web Application Security Statistics Project
  • Re: [WEB SECURITY] Scripting Question
  • [WEB SECURITY] Peach 2.1 BETA2 Released
  • RE: [WEB SECURITY] Scripting Question
  • [WEB SECURITY] widespread sql injection + javascript malware

  • Contact us
    Post News, get linkage!

    Name

    Email or Homepage:

    Subject

    Finish the word below: deadb33f

    Body