Hacker News new | past | comments | ask | show | jobs | submit login
Ed Felten & Team Disclose 4 New CSRF Vulnerabilities, Can Transfer Funds From ING (freedom-to-tinker.com)
7 points by tptacek on Sept 29, 2008 | hide | past | favorite | 1 comment



CSRF is "Cross-Site Request Forgery"; it's a simple problem: for many HTML forms, you can craft an IMG tag that will "submit" (via GET) to it. For others, XMLHttpRequest Javascript code can do the same thing for POST. In both cases, the exploit is the same: a "drive-by" form submission from malicious HTML rendered off any web page.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: