Home of ABS Computer Technoloogy, Linux and Security Consultants Network Security solutions from our security experts Security solutions for Internet and Network technologies Some of our services for Linux, security, and hosting Contact us

Home > Headlines

    Home
       Site Map
       Headlines
       Glossary
       Contact Us
       Search
       Customers
       links
    Library
    Hosting
    Network
    Products
    Security
    Services
    Training
    Free Offers






Click here to register.




 

A Better Bureau Approved Company

We are proud to be a Better Business Bureau Accredited Business.

When you look to secure your business, start with an Accredited Business for your security needs.

 


Cross Site Request Forgeries found on many websites.

User: Admin
Date: 10/2/2008 7:39 am
Views: 118
Rating: 0    Rate [
|
]

An anonymous reader sends a link to DarkReading on the recent announcement by Princeton researchers of four major Web sites on which they found exploitable cross-site request forgery vulnerabilities. The sites are the NYTimes, YouTube, Metafilter, and INGDirect. All but the NYTimes site have patched the hole.

"... four major Websites susceptible to the silent-but-deadly cross-site request forgery attack — including one on INGDirect.com's site that would let an attacker transfer money out of a victim's bank account ... Bill Zeller, a PhD candidate at Princeton, says the CSRF bug that he and fellow researcher Edward Felton found on INGDirect.com represents ... 'the first example of a CSRF attack that allows money to be transferred out of a bank account that [we're] aware of.' ... CSRF is little understood in the Web development community, and it is therefore a very common vulnerability on Websites. 'It's basically wherever you look,' says [a security researcher]."

PreviousBackNext
 

Contact Us - Home - Site Map

© 2005-2008 ABS Computer Technology, Inc. - All Rights Reserved
SpamZapper® is the registered trademark of ABS Computer Technology, Inc.

Site Design - Marc Dorsett Graphic Artist