Simon Willison’s Weblog

Entries tagged csrf in 2005

Filters: Type: entry × Year: 2005 × csrf ×


Fighting RFCs with RFCs

Google’s recently released Web Accelerator apparently has some scary side-effects. It’s been spotted pre-loading links in password-protected applications, which can amount to clicking on every “delete this” link — bypassing even the JavaScript prompt you carefully added to give people the chance to think twice.

[... 353 words]

Types

Years

Months

Tags