News:

Facebook killed the radio star. And by radio star, I mean the premise of distributed forums around the internet. And that got got by Instagram/SnapChat. And that got got by TikTok. Where the fuck is the internet we once knew?

Main Menu

Death by 1000 cuts

Started by iago, November 21, 2008, 10:31:03 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

iago

This is a cool story about how a bunch of minor issues in a Web application can be combined to gain access:

http://ha.ckers.org/deathby1000cuts/

rabbit

Good read.  Though it wasn't exactly 1000...

iago

"1000 cuts" is a figure of speech. :P

Hitmen

Quote
(22:15:39) Newby: it hurts to swallow

Camel

I can't believe people actually consider CSRF to be minor! The name alone instills fear in to the hearts of developers around here.

<Camel> i said what what
<Blaze> in the butt
<Camel> you want to do it in my butt?
<Blaze> in my butt
<Camel> let's do it in the butt
<Blaze> Okay!

iago

Quote from: Camel on November 21, 2008, 03:27:24 PM
I can't believe people actually consider CSRF to be minor! The name alone instills fear in to the hearts of developers around here.
It strongly depends on the situation.

But I agree, it's often non-minor, just not well understood.

Camel

Incidentally, if you use GWT, your apps will be inherently safe vs CSRF and XSS, so long as you do not go out of your way to work around the security that's built in (publishing login tokens, writing vulnerable pure-javascript, etc)

<Camel> i said what what
<Blaze> in the butt
<Camel> you want to do it in my butt?
<Blaze> in my butt
<Camel> let's do it in the butt
<Blaze> Okay!