<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: POST is not enough to prevent CRSF vulnerability, a proof with Reddit</title>
	<atom:link href="http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/feed/" rel="self" type="application/rss+xml" />
	<link>http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/</link>
	<description></description>
	<lastBuildDate>Thu, 16 Jul 2009 17:26:55 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Tagz &#124; &#34;POST is not enough to prevent CRSF vulnerability, a proof with Reddit « Inane ramblings in the programming landscape&#34; &#124; Comments</title>
		<link>http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-1295</link>
		<dc:creator>Tagz &#124; &#34;POST is not enough to prevent CRSF vulnerability, a proof with Reddit « Inane ramblings in the programming landscape&#34; &#124; Comments</dc:creator>
		<pubDate>Sat, 16 May 2009 17:07:01 +0000</pubDate>
		<guid isPermaLink="false">http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-1295</guid>
		<description>[...]               [upmod] [downmod]     POST is not enough to prevent CRSF vulnerability, a proof with Reddit « Inane ramblings in the prog...  (monkeyget.wordpress.com)    0 points posted 10 months, 1 week ago by jeethu  tags webdev security [...]</description>
		<content:encoded><![CDATA[<p>[...]               [upmod] [downmod]     POST is not enough to prevent CRSF vulnerability, a proof with Reddit « Inane ramblings in the prog&#8230;  (monkeyget.wordpress.com)    0 points posted 10 months, 1 week ago by jeethu  tags webdev security [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dblackshell</title>
		<link>http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-1284</link>
		<dc:creator>dblackshell</dc:creator>
		<pubDate>Fri, 11 Jul 2008 14:35:06 +0000</pubDate>
		<guid isPermaLink="false">http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-1284</guid>
		<description>dinamic script tags can be used... if it&#039;s not a regenerative token http://insanesecurity.wordpress.com/2008/05/29/regenerative-tokens/</description>
		<content:encoded><![CDATA[<p>dinamic script tags can be used&#8230; if it&#8217;s not a regenerative token <a href="http://insanesecurity.wordpress.com/2008/05/29/regenerative-tokens/" rel="nofollow">http://insanesecurity.wordpress.com/2008/05/29/regenerative-tokens/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Top Posts &#171; WordPress.com</title>
		<link>http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-4</link>
		<dc:creator>Top Posts &#171; WordPress.com</dc:creator>
		<pubDate>Sat, 31 Mar 2007 23:58:38 +0000</pubDate>
		<guid isPermaLink="false">http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-4</guid>
		<description>[...] POST is not enough to prevent CRSF vulnerability, a proof with Reddit Note: CSRF is an attack were a user is logged on site A. Site B contains a malicious page which forces any user loading [&#8230;] [...]</description>
		<content:encoded><![CDATA[<p>[...] POST is not enough to prevent CRSF vulnerability, a proof with Reddit Note: CSRF is an attack were a user is logged on site A. Site B contains a malicious page which forces any user loading [&#8230;] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harshad Joshi</title>
		<link>http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-3</link>
		<dc:creator>Harshad Joshi</dc:creator>
		<pubDate>Sat, 31 Mar 2007 19:10:28 +0000</pubDate>
		<guid isPermaLink="false">http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-3</guid>
		<description>Thanks.</description>
		<content:encoded><![CDATA[<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tiago Serafim</title>
		<link>http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-2</link>
		<dc:creator>Tiago Serafim</dc:creator>
		<pubDate>Sat, 31 Mar 2007 03:22:17 +0000</pubDate>
		<guid isPermaLink="false">http://monkeyget.wordpress.com/2007/03/30/post-is-not-enough-to-prevent-crsf-vulnerability-a-proof-with-reddit/#comment-2</guid>
		<description>Hi,

&gt;An ajax request could also be used.

I don&#039;t think that an ajax request could be used since the browser&#039;ll only do ajax calls for urls from the same domain the script is running.

Thanks for the article,</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>&gt;An ajax request could also be used.</p>
<p>I don&#8217;t think that an ajax request could be used since the browser&#8217;ll only do ajax calls for urls from the same domain the script is running.</p>
<p>Thanks for the article,</p>
]]></content:encoded>
	</item>
</channel>
</rss>
