A page to show up #1 on Google when searching for "Jeremiah" (Currently #4).
Only the prophet and TV show left!
I have the edge, TV show is cancelled and the prophet isn't generating any new content.
The prophet, TV show, and that pesky Owyang guy going down!
A page to show up #1 on Google when searching for "Jeremiah Grossman", and it FINALLY has!
Tuesday, July 25, 2006
Forging HTTP request headers with Flash
Amit Klein, a top webappsec expert, published "Forging HTTP request headers with Flash". Essentially Amit found a way using Flash to force a users browser to send HTTP requests to any location and alter the Referer header in the process. This discovery has wide-ranging implications for web application security, not the least of which impact the ability to do anti-CSRF using Referers. In an odd conicidence, I was working on a solution to do easy anti-CSRF using ModSecurity (Amit had prior knowledge of) based on using Referers. Was set to be released through WASC. I know what your thinking, "don't ever ever ever trust the client". But I felt there could be an exception in this case and had the proof to back it up. But Amit being the nice guy that he is let me know what he was working on ahead of time. So, the article I had planned is being moth balled. Every week is something new.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment