Freedom to Tinker: Popular Websites Vulnerable to Cross-Site Request Forgery Attacks
“We found four major vulnerabilities on four different sites. These vulnerabilities include what we believe is the first [Cross-Site Request Forgery] vulnerability that allows the transfer of funds from a financial institution. We contacted all the sites involved and gave them ample time to correct these issues. Three of these sites have fixed the vulnerabilities listed below, one has not.”
(via fergdawg)


