Google Adsense CSRF hole

It doesn’t seem like you’re a web security researcher these days unless you find a security hole in Google. So I had 5 minutes spare whilst drinking my brew to find a hole in Google Adsense. I’ve reported the problem to Google and I won’t release the specific details but if you’re creative you might be able to find the poc.

Google Adsense has no CSRF protection in certain areas, it is possible for a remote attacker to do all sorts of nasty stuff like change the address details of your adsense account. I’ve tested it on my own account and I successfully appended “Test” on my address.

The poc will automatically log you onto your account and browse the Adsense site “as you” before finally posting an update to your address.

Prevention

In order to protect against this sort of stuff I have posted a couple of demos and articles to help with the process, check them out here:-

CSRF Protection part 1
CSRF Protection part 2

Share and Enjoy:
  • Digg
  • del.icio.us
  • Slashdot
  • StumbleUpon

Comments 5

  1. Ronald wrote:

    How is that one different from mine Gareth?
    I did exactly the same 6 months ago, only I used GET.

    I don’t think it has something to do with releasing Google holes to be a researcher.
    All of Google is vulnerable, unlike PDP I found more, but I don’t feel like spending a single second on their site anymore. Okay it gets a ton of media attention, but it isn’t hard to find one. For me, I don’t want all this media hyping around me anymore, cause first off it doesn’t do a thing for you only that you’ll become a sort of side-show, some kind of carnivale, you knwo like: see the bearded lady! IMHO thats how I look at it.

    lol :D

    Posted 27 Sep 2007 at 4:30 pm
  2. pdp wrote:

    rock on!

    Posted 27 Sep 2007 at 4:42 pm
  3. Gareth Heyes wrote:

    Hi Ronald

    I’m sorry I didn’t realise you had released the same exploit, I just wanted to point out how easy it was to find a hole.

    My comment about a security researcher was in jest :) of course I don’t think I need to find one in Google, I just thought it would be funny.

    Posted 27 Sep 2007 at 4:59 pm
  4. 0kn0ck wrote:

    Good Stroke Gareth

    Posted 28 Sep 2007 at 7:08 am
  5. s c tan wrote:

    great blog!

    Posted 18 Dec 2007 at 12:12 pm

Post a Comment

Your email is never published nor shared. Required fields are marked *

Comment spam protected by SpamBam