Full Disclosure mailing list archives
Re: Google Buzz and blind CSRF attacks
From: Kristian Erik Hermansen <kristian.hermansen () gmail com>
Date: Fri, 12 Feb 2010 09:48:44 -0800
On Fri, Feb 12, 2010 at 7:08 AM, Cody Robertson <cody () hawkhost com> wrote:
Doesn't work for me
It has been verified against multiple GMail users. You can try the direct link as well, but the issue is more effective within the "Buzz" interface. It doesn't look like you tested from a gmail account either (hawkhost.com?)... http://kristian-hermansen.blogspot.com/2010/02/google-buzz-csrf-test.html -- Kristian Erik Hermansen _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Google Buzz and blind CSRF attacks Kristian Erik Hermansen (Feb 12)
- Re: Google Buzz and blind CSRF attacks Cody Robertson (Feb 12)
- Re: Google Buzz and blind CSRF attacks Kristian Erik Hermansen (Feb 12)
- Re: Google Buzz and blind CSRF attacks Fabien VINCENT (Feb 15)
- Re: Google Buzz and blind CSRF attacks Kristian Erik Hermansen (Feb 12)
- Re: Google Buzz and blind CSRF attacks Cody Robertson (Feb 12)
