Hacker News new | past | comments | ask | show | jobs | submit login

As far as I can tell that particular vulnerability isn't a CSRF at all, it's an insecure JSONP endpoint[1]. The original author is mistaken.

[1] http://homakov.blogspot.com/2013/02/are-you-sure-you-use-jso...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: