Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
FanFiction.Net -- Javascript trojan
RE: FanFiction.Net -- Javascript trojan
#16
Maybe?  I didn't look at it, was it something like an iframe embedded in the page, that used some JS?  If it really was a CSRF bug, I'm not too surprised they missed it, though I have the same level of dismay.  I just had a discussion at work about how this is one of the hardest security issues to understand.  To wit, a couple months back I had to convince Apple that no, there was not a CSRF vector in our application, despite what their security team was saying.
"Kitto daijoubu da yo." - Sakura Kinomoto
Reply


Messages In This Thread
RE: FanFiction.Net -- Javascript trojan - by Labster - 10-31-2018, 02:41 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)