[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <fe37588d1002120948j29f1bcb2w77df574e41366d64@mail.gmail.com>
Date: Fri, 12 Feb 2010 09:48:44 -0800
From: Kristian Erik Hermansen <kristian.hermansen@...il.com>
To: Cody Robertson <cody@...khost.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: Google Buzz and blind CSRF attacks
On Fri, Feb 12, 2010 at 7:08 AM, Cody Robertson <cody@...khost.com> wrote:
> Doesn't work for me
It has been verified against multiple GMail users. You can try the
direct link as well, but the issue is more effective within the "Buzz"
interface. It doesn't look like you tested from a gmail account
either (hawkhost.com?)...
http://kristian-hermansen.blogspot.com/2010/02/google-buzz-csrf-test.html
--
Kristian Erik Hermansen
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists