Re: [WEB SECURITY] Persistent CSRF and The Hotlink Hell

2007-04-17 Thread Ryan Barnett
I believe that the SecurityFocus "defacement" by FluffiBunni a few years back would be an example of the defacement attack that Michael listed in his article. The concept was that SF had a trust relationship with the company that was rotating their banners and FB replaced the expected image with

Re: [Full-disclosure] [WEB SECURITY] Persistent CSRF and The Hotlink Hell

2007-04-17 Thread Blue Boar
He compromised the server(s) at the ad network we were using at the time, and simply served up his ad instead of the usual ones. BB Ryan Barnett wrote: > I believe that the SecurityFocus "defacement" by FluffiBunni a few > years back would be an example of