3 ms·
I'm curious about the technical details of the CSRF bypass vulnerability. Anyone know what the "combinations of browser plugins and HTTP redirects" that lead to
by jfirebaugh 16y ago
I'm curious about the technical details of the CSRF bypass vulnerability. Anyone know what the "combinations of browser plugins and HTTP redirects" that lead to it are?
http://groups.google.com/group/rubyonrails-security/browse_thread/thread/2d95a3cc23e03665 http://groups.google.com/group/rubyonrails-security/browse_t...
- nbpoole 16y agoSame here. Based on the changes made in the patch, it seems like the attack involves being able to make cross-domain requests but not being able to read back the response. I didn't think that was the way Java and Flash behaved.