barrett778's csrf clipmarks

Newest Clips
see Newest Clips
  • See all clipmarks by barrett778
  • See all public csrf clipmarks
  •    
     
     
     
       
     
    top scroll end
    0
    POPS
    Cross-Site Request Forgery (CSRF or XSRF)
    barrett778
    by barrett778  11-27-2007   
     Related to the Firefox / SeaMonkey vulnerability noted in the previous clip. Please see source for excellent examples on how this is done. The Digg example is not well written, but explains well how this is accomplished.
    0
    POPS
    Firefox / Seamonkey HTTP Referer Vulnerability
    barrett778
    by barrett778  11-27-2007   
     This issue relates to Cross-site Request Forgeries. One countermeasure is for the authenticating web site to check the HTTP Referer header to ensure the request is coming from an authorized site. This vulnerability permitted an attacker to delay the loading of the attack script until the intended (permitted) referring page was loaded, which would circumvent HTTP Referer checks to prevent CSRF. Solution: Update to Firefox 2.0.0.10 and latest version of SeaMonkey. See next post for explanation of CSRS (aka XSRF)
    — end of the list —

    barrett778 csrf

    loading clips...
    Filter
    rss tools
    Clipmarks
    About   Clippers   Privacy   EULA   Copyright   Site Map

    OK