danielmiessler.com | posterous

grep understanding

« Back to posts
  • Viewed
    times

Filed under

  • CSRF
  • Web Application Security
December 1, 2010

Neal Poole » Google Vulnerability Reward Program: Google Calendar CSRF

  • Edit
  • Delete
  • Tags
  • Autopost

Summary

Google Calendar was vulnerable to a series of CSRF vulnerabilities. In two separate instances, I found that existing countermeasures (CSRF tokens) were not being validated by the application.

via nealpoole.com

Interesting stuff.

Tweet
  • 0 responses
  • Like
  • Comment