Earlier quoted context omitted.
I've got a lot of practice breaking things. CSRF can be identified really fast by checking for unique tokens. Some unguessable token should be submitted with each state changing request. If not, attackers can steal authenticated accounts by making a request to the "change PW" or "change email" URLs. It's a little confusing at first. XSS I just set JavaScript as something that shows up in a field on a different page.…
Hey, I appreciate the response. BTW, I tried to follow you on Twitter via your website link but it said user doesn't exist anymore. :-/
It's actually twitter.com/steakejjs. I just changed it last night actually independent of reading this.
Cheers