[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] Google Buzz and blind CSRF attacks
- To: Cody Robertson <cody@xxxxxxxxxxxx>
- Subject: Re: [Full-disclosure] Google Buzz and blind CSRF attacks
- From: Kristian Erik Hermansen <kristian.hermansen@xxxxxxxxx>
- Date: Fri, 12 Feb 2010 09:48:44 -0800
On Fri, Feb 12, 2010 at 7:08 AM, Cody Robertson <cody@xxxxxxxxxxxx> wrote:
> Doesn't work for me
It has been verified against multiple GMail users. You can try the
direct link as well, but the issue is more effective within the "Buzz"
interface. It doesn't look like you tested from a gmail account
either (hawkhost.com?)...
http://kristian-hermansen.blogspot.com/2010/02/google-buzz-csrf-test.html
--
Kristian Erik Hermansen
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/