
One of the most interesting (in other words, “dangerous”) vulnerabilities that almost every existing web application falls victim to is cross-site request forgery (CSRF – “sea-surf”). CSRF is a type of malicious attack vector whereby unauthorized commands are transmitted from a user that the website trusts. It is an example of the confused deputy problem. This is different than the widely-known cross-site scripting (XSS) in that CSRF exploits the trust that a site has in the user’s browser, and XSS exploits the trust a user has for a particular web site.
Categories
Archives
Recent Posts
- Q1 2010 Printed Barking Seal Newsletter Hot off the Presses
- Enlightening the Confused Deputy
- Why do we do Social Engineering exercises, anyway? They seem so far-fetched sometimes.
- PCI-DSS Compensating Controls
- Pursuit of Happiness
- PCI DSS-driven assessment
- HITECH business associate deadlines looming
- Five things network and system administrators can learn from Agile
- Exploring your NIC for fun and profit
- New Year’s Resolutions for IT (and free T-Shirt offer!)
Recent Comments
- ben on Changing Active Directory Passwords with Perl
- Roger on Changing Active Directory Passwords with Perl
- The Barking Seal » Blog Archive » PCI DSS-driven assessment on Compliance Series: PCI Data Security Standard
- VPNTTG on Monitoring site-to-site VPNs on a Cisco ASA
- Jason Held on Wake up AT&T: Prayer is not an effective capacity planning and service assurance method
- Jason Held on Five things network and system administrators can learn from Agile
- The Barking Seal » Blog Archive » New Year’s Resolutions for IT (and free T-Shirt offer!) on Fend off disaster with preventative maintenance
- The Barking Seal » Blog Archive » New Year’s Resolutions for IT (and free T-Shirt offer!) on End-of-year IT checklist
- BigMcLargehuge on Monitoring site-to-site VPNs on a Cisco ASA
- Mike Adams on Applied Trust’s Deck-tacular Summer!





I’m excited to say that 