<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7122745763234660283.post8349355000742867336..comments</id><updated>2010-04-21T02:00:53.500-07:00</updated><title type='text'>Comments on Minded Security Blog: Client side Http Parameter Pollution - Yahoo! Clas...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.mindedsecurity.com/feeds/8349355000742867336/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html'/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-324341898955945301</id><published>2010-04-21T02:00:53.485-07:00</published><updated>2010-04-21T02:00:53.485-07:00</updated><title type='text'>@Satyajit
It's up to you, I just tested it when I ...</title><content type='html'>@Satyajit&lt;br /&gt;It&amp;#39;s up to you, I just tested it when I was researching HPP.&lt;br /&gt;&lt;br /&gt;@all&lt;br /&gt;The Yahoo! Classic Mail HPP has been fixed by Yahoo.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/324341898955945301'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/324341898955945301'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1271840453485#c324341898955945301' title=''/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14551455925158707405'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-2215972178762405446</id><published>2009-08-12T23:38:40.850-07:00</published><updated>2009-08-12T23:38:40.850-07:00</updated><title type='text'>Any other site, where we could test it</title><content type='html'>Any other site, where we could test it</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/2215972178762405446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/2215972178762405446'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1250145520850#c2215972178762405446' title=''/><author><name>Satyajit Das</name><uri>http://www.blogger.com/profile/08712147633806825801</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-5787542657524285493</id><published>2009-08-04T00:27:27.988-07:00</published><updated>2009-08-04T00:27:27.988-07:00</updated><title type='text'>As you can read in the blog post:
"
Please note th...</title><content type='html'>As you can read in the blog post:&lt;br /&gt;&amp;quot;&lt;br /&gt;Please note that every action has anti CSRF measures so it&amp;#39;s not possible to perform those ones from an external evil page.&lt;br /&gt;&amp;quot;&lt;br /&gt;&lt;br /&gt;So, no, Client side HPP isn&amp;#39;t classified as CSRF because it could be used to bypass anti CSRF tokens, the same way I did on Yahoo! Mail.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/5787542657524285493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/5787542657524285493'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1249370847988#c5787542657524285493' title=''/><author><name>Stefano Di Paola</name><uri>http://www.blogger.com/profile/18241677936736054546</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10007430601667226836'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-8470235537230295561</id><published>2009-08-03T15:25:17.873-07:00</published><updated>2009-08-03T15:25:17.873-07:00</updated><title type='text'>If the action a result of a GET request why isn't ...</title><content type='html'>If the action a result of a GET request why isn&amp;#39;t this classified as CSRF?  Since you could embed &lt;br /&gt;&lt;br /&gt;&amp;lt; img src=&amp;#39;http://yahoo.com?par=val&amp;amp;action=delete&amp;#39; / &amp;gt; and have the request made on behalf of the user</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/8470235537230295561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/8470235537230295561'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1249338317873#c8470235537230295561' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-4532203829346248055</id><published>2009-05-21T09:10:27.565-07:00</published><updated>2009-05-21T09:10:27.565-07:00</updated><title type='text'>Great work here!  The PoC videos make it very clea...</title><content type='html'>Great work here!  The PoC videos make it very clear that there is an issue, but not how it ties in to HPP.  However, the blog post itself covers all those details nicely.  Well done!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/4532203829346248055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/4532203829346248055'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1242922227565#c4532203829346248055' title=''/><author><name>thornmaker</name><uri>http://p42.us</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/></entry></feed>