Just in case it might be a problem for anyone: The article uses the CSRF vulnerability to log you out of all Google services (and says so in a PS at the bottom). Don't open the article if you don't want to have to log in to Google again afterwards (might be a problem if you're using two-factor auth and you don't have your phone handy for instance).
hm yep. should I hide that thing? hm.. Sorry guys in advance.
#1 CSRF Is A Vulnerability In All Browsers
11–20 of 256 posts
Re: #1 CSRF Is A Vulnerability In All Browsers
#12I'm having a little trouble parsing this post. Is he saying he's discovered a variant of CSRF that cannot be stopped by using the Synchronizer Token Pattern? Or has he found something that a lot of site's protection patterns don't follow?
Re: #1 CSRF Is A Vulnerability In All Browsers
#13Just in case it might be a problem for anyone: The article uses the CSRF vulnerability to log you out of all Google services (and says so in a PS at the bottom). Don't open the article if you don't want to have to log in to Google again afterwards (might be a problem if you're using two-factor auth and you don't have your phone handy for instance).
hm yep. should I hide that thing? hm.. Sorry guys in advance.
Re: #1 CSRF Is A Vulnerability In All Browsers
#14Re: #1 CSRF Is A Vulnerability In All Browsers
#15In order for requestpolicy to block this it needs to be in a fairly locked down state too...
Re: #1 CSRF Is A Vulnerability In All Browsers
#16I'm having a little trouble parsing this post. Is he saying he's discovered a variant of CSRF that cannot be stopped by using the Synchronizer Token Pattern? Or has he found something that a lot of site's protection patterns don't follow?
Re: #1 CSRF Is A Vulnerability In All Browsers
#17Just in case it might be a problem for anyone: The article uses the CSRF vulnerability to log you out of all Google services (and says so in a PS at the bottom). Don't open the article if you don't want to have to log in to Google again afterwards (might be a problem if you're using two-factor auth and you don't have your phone handy for instance).
hm yep. should I hide that thing? hm.. Sorry guys in advance.
Re: #1 CSRF Is A Vulnerability In All Browsers
#18I'm having a little trouble parsing this post. Is he saying he's discovered a variant of CSRF that cannot be stopped by using the Synchronizer Token Pattern? Or has he found something that a lot of site's protection patterns don't follow?
nope. Token Pattern is ugly workaround browsers' vulnerability - that's the point.
Re: #1 CSRF Is A Vulnerability In All Browsers
#19Just in case it might be a problem for anyone: The article uses the CSRF vulnerability to log you out of all Google services (and says so in a PS at the bottom). Don't open the article if you don't want to have to log in to Google again afterwards (might be a problem if you're using two-factor auth and you don't have your phone handy for instance).
> To stir up your interest - check any google service e.g. gmail, you are logged out.
Great hook btw. Even more impressively, I have all js on his blog blocked through NoScript and it still worked.