17 ms·
As mentioned in other comments in this thread, LinkedIn's tech team frequently disregards security standards. I found a CSRF attack on LinkedIn by accident whe
by th 14y ago
As mentioned in other comments in this thread, LinkedIn's tech team frequently disregards security standards.
I found a CSRF attack on LinkedIn by accident when searching in Duck Duck Go some months back. I clicked a link in my search results and was presented with a page thanking me for signing up for some LinkedIn group. I then received an email thanking me for joining the group as well.
LinkedIn was joining a group whenever an authenticated user performed a GET request to a particular URL in their browser. I followed this up by searching Google for other URLs that suffered from the same problem and found many. I wrote an exploit (very easy for that issue) and contacted LinkedIn. They have fixed the issue by now but it took more than 6 months.