• Home
  • About
  • Contact
  • Applied Trust
 

Categories

  • Green IT
  • Infrastructure
  • IT Management
  • Ramblings
  • Recruiting
  • Security

Archives

  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008

Recent Posts

  • Slow network performance for Windows Server 2008 guest on vmware ESXi 4.1
  • Now available: Unix and Linux System Administration Handbook, 4th edition
  • The Barking Seal Q3 2010 is Here and Filled with Goodies!
  • A Gentle Infrastructure Monitoring Reminder
  • AppliedTrust Goes Drupal!
  • Information Security and Running, Long Lost Brothers?
  • An IT lesson from the BP disaster
  • AppliedTrust sponsors “Laps for Learning”
  • AppliedTrust featured on One Day, One Job!
  • issues.apache.org compromised by XSS vulnerability

Recent Comments

  • Big D on Slow network performance for Windows Server 2008 guest on vmware ESXi 4.1
  • trent on Slow network performance for Windows Server 2008 guest on vmware ESXi 4.1
  • Big D on Slow network performance for Windows Server 2008 guest on vmware ESXi 4.1
  • The Barking Seal » Blog Archive » A Gentle Infrastructure Monitoring Reminder on Interpreting Packet Traces with Wireshark (Part 1 of n)
  • Drew on An IT lesson from the BP disaster
  • GKhamait on Monitoring site-to-site VPNs on a Cisco ASA
  • Onthebus on MS SQL Mirroring for High Availability
  • casandpoint on Encrypted Storage in the Cloud
  • Ben Edelen on issues.apache.org compromised by XSS vulnerability
  • dan on Social Engineering, Part Two

The Barking Seal

Applied Trust off-leash: IT infrastructure, security, and performance
Applied Trust is hiring!
  • Enlightening the Confused Deputy

    09Mar
    Author: zack Categories: Infrastructure, Security Comments: 0

    Confused Deputy
    One of the most interesting (in other words, “dangerous”) vulnerabilities that almost every existing web application falls victim to is cross-site request forgery (CSRF – “sea-surf”). CSRF is a type of malicious attack vector whereby unauthorized commands are transmitted from a user that the website trusts. It is an example of the confused deputy problem. This is different than the widely-known cross-site scripting (XSS) in that CSRF exploits the trust that a site has in the user’s browser, and XSS exploits the trust a user has for a particular web site.

    Read more »

    Tags: cross-site request forgery, cross-site scripting, csrf, Security, XSS

Subscribe:

  • RSS
  • Comments RSS

Popular Posts

  • 04-27-2010 / AppliedTrust featured on One Day, One Job!
  • 02-15-2010 / PCI DSS-driven assessment
  • 01-15-2010 / Five things network and system administrators can learn from Agile
  • 01-01-2010 / New Year’s Resolutions for IT (and free T-Shirt offer!)
  • 10-05-2009 / The Barking Seal Blog celebrates a birthday!
© 2010 Applied Trust Engineering. All Rights Reserved. Legal Entries RSS Comments RSS