<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CSRF chat</title>
	<atom:link href="http://www.thespanner.co.uk/2008/02/11/csrf-chat/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/</link>
	<description>Javascript blog with messed up syntax inside</description>
	<lastBuildDate>Thu, 26 Jan 2012 01:38:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: aÅŸk-Ä± memnu</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1422</link>
		<dc:creator>aÅŸk-Ä± memnu</dc:creator>
		<pubDate>Tue, 20 Jan 2009 22:49:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1422</guid>
		<description>Thank you. good document. i add u favoritesites..</description>
		<content:encoded><![CDATA[<p>Thank you. good document. i add u favoritesites..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Forex</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1348</link>
		<dc:creator>Forex</dc:creator>
		<pubDate>Sun, 02 Nov 2008 09:59:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1348</guid>
		<description>Thanks you. i look this ;)</description>
		<content:encoded><![CDATA[<p>Thanks you. i look this <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yakup</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1343</link>
		<dc:creator>yakup</dc:creator>
		<pubDate>Mon, 27 Oct 2008 23:49:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1343</guid>
		<description>Positive comment. thanks you.</description>
		<content:encoded><![CDATA[<p>Positive comment. thanks you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blog</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1219</link>
		<dc:creator>blog</dc:creator>
		<pubDate>Fri, 09 May 2008 11:39:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1219</guid>
		<description>thanks you.. john :-)</description>
		<content:encoded><![CDATA[<p>thanks you.. john <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1130</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 12 Feb 2008 10:10:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1130</guid>
		<description>The account has been deleted now, I can&#039;t be bothered setting up another one. I may change the POC to allow multiple chatrooms or if anyone wants to take the code and improve it then please do.</description>
		<content:encoded><![CDATA[<p>The account has been deleted now, I can&#8217;t be bothered setting up another one. I may change the POC to allow multiple chatrooms or if anyone wants to take the code and improve it then please do.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1129</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 11 Feb 2008 19:13:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1129</guid>
		<description>btw I&#039;m not saying tokens themselves are useless but in this instance they are. To defend against this type of attack a simple framebreaker would help.</description>
		<content:encoded><![CDATA[<p>btw I&#8217;m not saying tokens themselves are useless but in this instance they are. To defend against this type of attack a simple framebreaker would help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1128</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 11 Feb 2008 19:01:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1128</guid>
		<description>@chris

The only requirement is central storage of data. This could be Wordpress blog, GMail account, delicious account, flickr account etc. You must also be able to read that data externally, in this case I used the delicious JSON functionality.

Delicious contains a form token to prevent posting of new urls to an account, however I simply bypass this by asking the user to confirm the post.</description>
		<content:encoded><![CDATA[<p>@chris</p>
<p>The only requirement is central storage of data. This could be WordPress blog, GMail account, delicious account, flickr account etc. You must also be able to read that data externally, in this case I used the delicious JSON functionality.</p>
<p>Delicious contains a form token to prevent posting of new urls to an account, however I simply bypass this by asking the user to confirm the post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Shiflett</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1127</link>
		<dc:creator>Chris Shiflett</dc:creator>
		<pubDate>Mon, 11 Feb 2008 18:48:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1127</guid>
		<description>Very creative. :-)

For my own clarification, and perhaps that of others, this technique requires the ability to manipulate the page, correct?

An anti-CSRF token should be pretty strong unless there are lurking XSS problems, which I think we all agree is easier said than done. It&#039;s nice to be clear about where the risk lies.

Thanks!</description>
		<content:encoded><![CDATA[<p>Very creative. <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>For my own clarification, and perhaps that of others, this technique requires the ability to manipulate the page, correct?</p>
<p>An anti-CSRF token should be pretty strong unless there are lurking XSS problems, which I think we all agree is easier said than done. It&#8217;s nice to be clear about where the risk lies.</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1126</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 11 Feb 2008 14:07:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1126</guid>
		<description>Thanks John yeah you&#039;re right but it&#039;s all in the name of fun :)</description>
		<content:encoded><![CDATA[<p>Thanks John yeah you&#8217;re right but it&#8217;s all in the name of fun <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Ther</title>
		<link>http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1125</link>
		<dc:creator>John Ther</dc:creator>
		<pubDate>Mon, 11 Feb 2008 14:06:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/11/csrf-chat/#comment-1125</guid>
		<description>Good stuff Gareth, good CSS Overlay demonstration. Although it&#039;s matter of time someone to change password and settings and other stuff for xsschat from delicious :)</description>
		<content:encoded><![CDATA[<p>Good stuff Gareth, good CSS Overlay demonstration. Although it&#8217;s matter of time someone to change password and settings and other stuff for xsschat from delicious <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

