« .ORG Leading by Example on DNSSEC | Main | Fresh Air On "the Numerati" »
September 30, 2008
Cross-Site Request Forgeries Targeting Some Major Sites
“Underscoring the severity of of an exotic form of website bug, security researchers from Princeton University have cataloged four cross-site request forgeries in some of the world’s most popular sites.
“The most serious vulnerability by far was in the website of global financial services company ING Direct. The flaw could have allowed an attacker to transfer funds out of a user’s account, or to create additional accounts of behalf of a victim, according to this post from Freedom to Tinker blogger Bill Zeller.
“The vulnerabilities were confirmed for users of Firefox and Internet Explorer browsers, and ING’s use of the secure sockets layer protocol did nothing to prevent the attack. ING plugged the hole after Zeller and colleague Ed Felton reported it privately.”
The New York Times has yet to fix its problem, but MeFi MetaFilter has.
(Link)
Posted by mhall at 7:29 PM | Add Comment


Leave a comment