Feed Sign in with OpenID OpenID

Simon Willison’s Weblog

1 item tagged “alfeaton”

Logout/Login CSRF. Alf Eaton built an example page (this link goes to his description, not the page itself) that uses a login CSRF attack to log you in to Google using an account he has created. Scary. 3 24th September 2008, 10:18 pm

A django site