3 ms·
This should serve as a reminder to developers, GET requests should only be returning information, not writing information. With an IMG tag it's trivial to get
by nmjohn 12y ago
This should serve as a reminder to developers, GET requests should only be returning information, not writing information.
With an IMG tag it's trivial to get any user to execute any GET request the attacker wants, and that was critical in this exploit for binding a specified token to a users account.
- bkrausz 12y agoIn the desktop case this didn't actually matter... The attacker could have just as easily made a POST form with hidden fields that it then submitted to FB. Requiring POSTs for write-based end points is a good start, but there's a ton more necessary to keep API endpoints safe.