Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: blocking CSRF attacks |
|---|---|
| Date: | Sat, 15 Dec 2007 18:48:48 +0100 |
[Sorry for not replying to the original post, but I lost it.]
I wrote this six years ago:
http://shh.thathost.com/text/client-side-trojans.txt
* May 2000: Jim Fulton writes about it on zope.org http://www.zope.org/Members/jim/ZopeSecurity/ClientSideTrojan Name: Client-side Trojan
* May 2000: Referenced on Linux Weekly News
http://lwn.net/2000/features/Redirect.php3 * May 2000: Referenced on kuro5hin.org, including demo of having
people post messages to slashdot.
http://www.kuro5hin.org/story/2000/5/9/183550/1910* June 2001: Peter W describes it on BugTraq http://www.securityfocus.com/archive/1/191390 Name: Cross-Site Request Forgeries
* December 2004: Thomas Schreiber writes about it on webappsec http://www.securityfocus.com/archive/107/384630 Name: Session Riding
Sverre.
https://www.watchfire.com/securearea/whitepapers.aspx?id=70170000000940F -------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Snort Network Suppression, Boogie B. |
|---|---|
| Next by Date: | Re: Snort Network Suppression, Ngot |
| Previous by Thread: | Re: blocking CSRF attacks, Jan Heisterkamp |
| Next by Thread: | Snort Network Suppression, Jonathan Askew JBASKEW |
| Indexes: | [Date] [Thread] [Top] [All Lists] |