Hacking CSRF Tokens using CSS History Hack
securethoughts.com
securethoughts.com
I personally don't like whitelists to solve general browsing problems but noscript does allow you to only trust certain sites with possibly attaining your history information by limiting their ability to run JS. I like seeing new sites with JS magic though. In general, I am leaning towards using a separate browser entirely just for things I log in to and fully trust -- this is just another log on that fire.
All in all, it seems like most developers who know enough security to try to stop CSRF with tokens in the first place would create an implementation where the hack is useless. Still an interesting idea though.
(I see this is mentioned in the comments there.)
So, you set a cookie in the .example.com domain, and then, on the server side, you create a one-way hash of that cookie and a key phrase (a crumb), and put it on the url of the iframe.
The key phrase doesn't have to be particularly secret, it's mostly for convenience so that you can use the same cookie and hash function in multiple different applications without getting the same crumb everywhere for a given user. So, if a crumb is leaked, it's only going to expose one thing, not everything. Also, if you make it time-dependent, then it further limits the exposure.
The iframe validates that the crumb in the query string matches the one-way hash that it gets by performing the same one-way hash against the cookies and the key phrase.
Yahoo uses this technique all over the place. It's very effective as long as the crumb function is sufficiently clever. However, if your crumb is brute-forcible, then it can be exploited easily.