Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
Trust the World's Fastest VPN with Your Internet Security & Freedom - A Lifetime Subscription of PureVPN at 88% off. Also, Slashdot's Facebook page has a chat bot now. Message it for stories and more. ×
Security

Submission + - GMail POST Mortem: Can You Handle CSRF? (hackademix.net)

Giorgio Maone writes: "This week couldn't be worse for Google and GMail: four distinct vulnerabilities disclosed in the past few days, plus a Google Docs weakness by Rios/McFeters allowing for easy Flash-based XSS, and now another GMail hijacking technique half-disclosed (!) by Petko H. Petkov (AKA pdp).

GMail POST Mortem analyzes the details published by Petko under his ambiguous "semi-disclosure" policy, and it shows how this is in facts a 0 day full disclosure, since building a working exploit from it is pretty trivial. Finally, countermeasures against the CSRF (the class of vulnerabilities which this one belongs to) are provided, both for developers and for users.

BTW, the GMail hole is still unpatched (tested 1 minute ago)."

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

GMail POST Mortem: Can You Handle CSRF?

Comments Filter:

You can do more with a kind word and a gun than with just a kind word. - Al Capone

Working...