Forgot your password?
typodupeerror

Comment I can edit your blog. (Score 1) 241

To help prove how serious this security hole is, I have set up the following demonstration. You must be using IE, and have checked "remember me" when you logged on to Blogger, or have logged on (and not off) to Blogger in your current browser session.
  1. Go create a new account at http://www.blogger.com (unless you want me to mess with your real account), check "rememeber me" when you log on.
  2. Create a new blog, enter you FTP password if you want me to be able to actually publish changes I make.
  3. Add a blog entry that says you want me (Eric Costello) to add an entry to prove I was there.
  4. Go to http://www.glish.com/cookies.html.
I will get your cookie info and will soon have access to your blog. I have confirmed this works by hacking into pixelpony's blog.

Slashdot Top Deals

You are in the hall of the mountain king.

Working...