[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] Google Buzz and blind CSRF attacks



On Fri, Feb 12, 2010 at 7:08 AM, Cody Robertson <cody@xxxxxxxxxxxx> wrote:
> Doesn't work for me

It has been verified against multiple GMail users.  You can try the
direct link as well, but the issue is more effective within the "Buzz"
interface.  It doesn't look like you tested from a gmail account
either (hawkhost.com?)...

http://kristian-hermansen.blogspot.com/2010/02/google-buzz-csrf-test.html
-- 
Kristian Erik Hermansen

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/