4 ms·
Hacking Google Calendar
- jrockway 16y agoVery odd that they included XSRF tokens but did not validate them.
- nbpoole 16y agoYeah, that was what I thought too. It was a very weird situation. And it was the only one of its kind that I found: I found other vulnerabilities, but none where CSRF tokens were presented but not validated. Edit: I should clarify that this is my blog post ;)
- mcs 16y agoI wonder how many other sites put in CSRF tokens but don't validate.
- mike-cardwell 16y agoFor every one of these websites, there are probably 10,000 that don't do any CSRF checking at all.
- xtacy 16y agoAnother interesting point is the generation of unique IDs that weren't cryptographic. The uid in src=<uid> shouldn't be guessable, right? It looks like it just went a simple transformation that was easily reversible. On the other hand, if the CSRF tokens were validated, the uid field needn't be guessable.