Re: Linksys WRT54 GL - Session riding (CSRF)

看板Bugtraq作者時間18年前 (2008/01/16 04:12), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串7/8 (看更多)
> The catch is that this exploit don't work unnoticed, because the admin > get notification in the browser that there has occured an error with the > cerificate ["Unable to verify the identity of Linksys as a trusted > site"] and he has explicity allow it. In other words first he has to > allow to be attacked... It's generally (although not always!) a requirement of CSRF that the user has already logged in. So there won't be any new notification window popping up. It will make it harder for the attacker to stealthily attack multiple targets without someone noticing, though. Like Basic Authentication (which is ugly for the end-user, but browsers can defend slightly better against attacks over it), this is one of the cases where a little bit of user friction helps reduce attacks. It's an open question as to whether end users pay attention to security pop-ups at all. :)
文章代碼(AID): #17ZHEJ00 (Bugtraq)
討論串 (同標題文章)
文章代碼(AID): #17ZHEJ00 (Bugtraq)