Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
gdeglin.blogspot.com
Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
1–10 of 13 posts
Re: Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
#2Re: Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
#3This is my first blog post about web security, and hopefully the first of many. I'd love to hear feedback and I'm happy to answer questions. One of the concerns I had with this post was that it is highly technical, but I feel the issue is extremely important since so many sites are vulnerable to these kinds of issues.
Re: Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
#4Re: Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
#5Re: Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
#6Re: Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
#7This is my first blog post about web security, and hopefully the first of many. I'd love to hear feedback and I'm happy to answer questions. One of the concerns I had with this post was that it is highly technical, but I feel the issue is extremely important since so many sites are vulnerable to these kinds of issues.
* what document.domain is
* what hijacking user's session actually impliesRe: Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
#8This is my first blog post about web security, and hopefully the first of many. I'd love to hear feedback and I'm happy to answer questions. One of the concerns I had with this post was that it is highly technical, but I feel the issue is extremely important since so many sites are vulnerable to these kinds of issues.
Re: Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
#9This is my first blog post about web security, and hopefully the first of many. I'd love to hear feedback and I'm happy to answer questions. One of the concerns I had with this post was that it is highly technical, but I feel the issue is extremely important since so many sites are vulnerable to these kinds of issues.
It would be helpful to elaborate on: * what document.domain is * what hijacking user's session actually implies
Re: Careful when hosting 3rd party apps on subdomains, or how I hacked Facebook
#10This is my first blog post about web security, and hopefully the first of many. I'd love to hear feedback and I'm happy to answer questions. One of the concerns I had with this post was that it is highly technical, but I feel the issue is extremely important since so many sites are vulnerable to these kinds of issues.
It would be helpful to elaborate on: * what document.domain is * what hijacking user's session actually implies