funsec mailing list archives

erm.. referrers and web mail


From: Gadi Evron <ge () linuxbox org>
Date: Tue, 17 Jan 2006 03:17:21 +0200

I've been watching referrers to some web sites recently.. well, I encountered an old-new issue (old because it's old, new because people are still silly and we can call everything new in this industry).

When following URL's from web-mail, with enough lack of security I can access user accounts.

Gmail seems to not allow this.. others demand I login. When I checked some Yahoo! referrers though...
"Your login session has expired."

I wonder if I should spend some extra time and follow the next Yahoo mail referrer in real time? :)

        Gadi.
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: