
Episode 28: Surfin' with CSRFs
Critical Thinking - Bug Bounty Podcast
00:00
C Surf: How to Get an Account on an Obvious Domain
A C surf is a way to trick users into visiting an old legacy website. It can be triggered by one click, but it also uses other tricks such as the meta tag. The bug was discovered at a live hacking event in 2022 and has since received five figures worth of bounties from that specific domain.
Play episode from 01:06:04
Transcript


