<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	<title>MetaFilter posts tagged with CSRF</title>
	<link>http://www.metafilter.com/tags/CSRF</link>
	<description>Posts tagged with 'CSRF' at MetaFilter.</description>
	<pubDate>Sun, 22 Oct 2006 02:09:31 -0800</pubDate> <lastBuildDate>Sun, 22 Oct 2006 02:09:31 -0800</lastBuildDate>

	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>
	<item>
		<title>Self Linking Considered Harmful</title>
		<link>http://www.metafilter.com/55720/Self%2DLinking%2DConsidered%2DHarmful</link>
		<description>&lt;a href="http://jeremiahgrossman.blogspot.com/2006/09/csrf-sleeping-giant.html"&gt;CSRF (Cross Site Request Forgery)&lt;/a&gt; is starting to become a real issue for many web forums.  While the vulnerability has been &lt;a href=&quot;http://www.namb.la/popular/&quot;&gt;around&lt;/a&gt; for a &lt;a href=&quot;http://shiflett.org/articles/security-corner-dec2004&quot;&gt;while&lt;/a&gt;, &lt;a href=&quot;http://www.hardened-php.net/library/poking_new_holes_with_flash_crossdomain_policy_files.html&quot;&gt;recently&lt;/a&gt;    &lt;a href=&quot;http://shiflett.org/archive/271&quot;&gt; it&lt;/a&gt; &lt;a href=&quot;http://isc.sans.org/diary.php?storyid=1750&quot;&gt;has&lt;/a&gt; &lt;a href=&quot;http://blog.thinkphp.de/archives/150-Buy-one-XSS,-get-a-CSRF-for-free.html&quot;&gt; become more&lt;/a&gt; &lt;a href=&quot;http://www.gnucitizen.org/blog/attackapi-08-is-out&quot;&gt;interesting&lt;/a&gt;.  Luckily the policy against against self linking and some &lt;a href=&quot;http://metatalk.metafilter.com/mefi/12891#351219&quot;&gt;recent&lt;/a&gt; fixes should protect readers here.  </description>
		<guid isPermaLink="false">tag:metafilter.com,2006:site.55720</guid>
		<pubDate>Sun, 22 Oct 2006 02:09:31 -0800</pubDate>
		<category>crossdomain.xml</category>
		<category>CSRF</category>
		<category>omgtheinternetismelting</category>
		<category>security</category>
		<category>XSS</category>
		<dc:creator>mock</dc:creator>
	</item>
      
	</channel>
</rss>


