4 ms·
Years and years ago I went out searching for UMD devices vulnerable to CSRF. They universally were, but the only vendor that responded to my email was CheckPoi
by danielweber 10y ago
Years and years ago I went out searching for UMD devices vulnerable to CSRF.
They universally were, but the only vendor that responded to my email was CheckPoint, who admitted it and said they were working on a fix. (They had the fix released soon, too.) Everyone else was 100% silent treatment.
- rudolf0 10y agoWhat % of the devices you tested were security appliances? It's good Checkpoint did that, but you would expect most security companies to care a lot more about patching their devices relative to all of the other various network device manufacturers out there.
- danielweber 10y agoI should have said "UTM" devices, not "UMD" devices. So all of them were security devices. One company accused me of gaining access to a private development build. That was fun.