|
You are here |
introvertmac.wordpress.com | ||
| | | | |
mazinahmed.net
|
|
| | | | | Facebook Messenger Multiple CSRF Vulnerabilities | |
| | | | |
www.sjoerdlangkemper.nl
|
|
| | | | | IceHRM is an open source human resource management system. Its functionality to change the user's password is vulnerable to CSRF. | |
| | | | |
mathieu.fenniak.net
|
|
| | | | | Cross-site request forgery (CSRF) is a type of security exploit where a user's web browser is tricked by a third-party site into performing actions on websites that the user is logged into. It is often a difficult attack to pull off, as it requires a number of factors to line up at once. Protecting against it requires good discipline and good design practices, especially when it comes to protecting Web APIs. Here's a brief example of a fictitious CSRF attack against a bank: | |
| | | | |
zfnd.org
|
|
| | | In one of ourprevious posts, we wrote an overview of the structure of the asynchronous network stack we designed forZebra, the Zcash Foundations forthcoming node implementation. This post will zoom in to take a close look at one small but interesting component: how we use Tokioscodecfunctionality to implement the Bitcoin wire protocol used by Zcash. [] | ||