Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

Re: Google Buzz and blind CSRF attacks
From: Kristian Erik Hermansen <kristian.hermansen () gmail com>
Date: Fri, 12 Feb 2010 09:48:44 -0800

On Fri, Feb 12, 2010 at 7:08 AM, Cody Robertson <cody () hawkhost com> wrote:
Doesn't work for me

It has been verified against multiple GMail users.  You can try the
direct link as well, but the issue is more effective within the "Buzz"
interface.  It doesn't look like you tested from a gmail account
either (hawkhost.com?)...

http://kristian-hermansen.blogspot.com/2010/02/google-buzz-csrf-test.html
-- 
Kristian Erik Hermansen

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault