funsec mailing list archives

Re: Is this a hoax?


From: Valdis.Kletnieks () vt edu
Date: Thu, 28 Jun 2007 16:39:25 -0400

On Thu, 28 Jun 2007 15:57:21 EDT, Blanchard_Michael () emc com said:
Sure seems like a hoax or other baddie to me.

Looks more like a wake-up call to me.  Another DarkReading link:

http://www.darkreading.com/document.asp?doc_id=126560

"The most famous CSRF attack was the Samy worm that crippled MySpace last year.
The attacker used a toxic combination of XSS and CSRF exploits to wreak havoc
on the social networking site."

I cant comment on whether this *current* one is for real, but the concept that
'they got bored with XSS and went looking for CSRF" certainly strikes me as
a *plausible* event.  

Attachment: _bin
Description:

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

Current thread: