NCC Group Blog

Go Back

CSRF worm released on Twitter

“Cross-site request forgery is a method of gaining access to a web application by exploiting the user’s logged-in session. This worm appears to be mischievous rather than malicious - such as the worm last week that exploited a mouseover flaw – but it exposes a serious issue in the Twitter security model which needs to be fixed to avoid users suffering weekly or daily incidents of this kind.”
  • Facebook
  • Twitter
  • DZone It!
  • Digg It!
  • StumbleUpon
  • Technorati
  • Del.icio.us
  • NewsVine
  • Reddit
  • Blinklist
  • Add diigo bookmark
Post a comment!
  1. Formatting options