<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7122745763234660283.post8349355000742867336..comments</id><updated>2011-11-28T23:17:07.245-08:00</updated><category term='jQuery'/><category term='Web Attacks'/><category term='Advisory'/><category term='Applet Security'/><category term='Http Request Splitting'/><category term='Application Security'/><category term='Http Parameter Pollution'/><category term='malware'/><category term='Cross Site Scripting'/><category term='Dom Xss'/><category term='DOMinator'/><category term='WWeb Security'/><category term='Banking'/><category term='Java'/><category term='Information Disclosure'/><category term='Omniture'/><category term='Spring MVC'/><category term='Expression Language Injection'/><category term='Java Security'/><category term='twitter'/><category term='Sharepoint'/><category term='Web Security'/><category term='Client Side HTTP Parameter Pollution'/><category term='JNLP Security'/><category term='JSON'/><category term='Liferay'/><category term='Same Origin Policy'/><category term='Arbitrary Code Execution'/><title type='text'>Comments on Minded Security Blog: Client side Http Parameter Pollution - Yahoo! Clas...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.mindedsecurity.com/feeds/8349355000742867336/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html'/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-4596002951994510891</id><published>2011-11-23T22:36:25.389-08:00</published><updated>2011-11-23T22:36:25.389-08:00</updated><title type='text'>Cool. nice post.</title><content type='html'>Cool. nice post.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/4596002951994510891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/4596002951994510891'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1322116585389#c4596002951994510891' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2064692422'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-2091474919018986140</id><published>2011-02-03T06:23:53.660-08:00</published><updated>2011-02-03T06:23:53.660-08:00</updated><title type='text'>good one</title><content type='html'>good one</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/2091474919018986140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/2091474919018986140'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1296743033660#c2091474919018986140' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1587623090'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-324341898955945301</id><published>2010-04-21T02:00:53.485-07:00</published><updated>2010-04-21T02:00:53.485-07:00</updated><title type='text'>@Satyajit
It&amp;#39;s up to you, I just tested it whe...</title><content type='html'>@Satyajit&lt;br /&gt;It&amp;#39;s up to you, I just tested it when I was researching HPP.&lt;br /&gt;&lt;br /&gt;@all&lt;br /&gt;The Yahoo! Classic Mail HPP has been fixed by Yahoo.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/324341898955945301'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/324341898955945301'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1271840453485#c324341898955945301' title=''/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1570645034'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-2215972178762405446</id><published>2009-08-12T23:38:40.850-07:00</published><updated>2009-08-12T23:38:40.850-07:00</updated><title type='text'>Any other site, where we could test it</title><content type='html'>Any other site, where we could test it</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/2215972178762405446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/2215972178762405446'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1250145520850#c2215972178762405446' title=''/><author><name>Satyajit Das</name><uri>http://www.blogger.com/profile/08712147633806825801</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-269352999'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-5787542657524285493</id><published>2009-08-04T00:27:27.988-07:00</published><updated>2009-08-04T00:27:27.988-07:00</updated><title type='text'>As you can read in the blog post:
&amp;quot;
Please no...</title><content type='html'>As you can read in the blog post:&lt;br /&gt;&amp;quot;&lt;br /&gt;Please note that every action has anti CSRF measures so it&amp;#39;s not possible to perform those ones from an external evil page.&lt;br /&gt;&amp;quot;&lt;br /&gt;&lt;br /&gt;So, no, Client side HPP isn&amp;#39;t classified as CSRF because it could be used to bypass anti CSRF tokens, the same way I did on Yahoo! Mail.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/5787542657524285493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/5787542657524285493'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1249370847988#c5787542657524285493' title=''/><author><name>Stefano Di Paola</name><uri>http://www.blogger.com/profile/18241677936736054546</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-157727315'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-8470235537230295561</id><published>2009-08-03T15:25:17.873-07:00</published><updated>2009-08-03T15:25:17.873-07:00</updated><title type='text'>If the action a result of a GET request why isn&amp;#3...</title><content type='html'>If the action a result of a GET request why isn&amp;#39;t this classified as CSRF?  Since you could embed &lt;br /&gt;&lt;br /&gt;&amp;lt; img src=&amp;#39;http://yahoo.com?par=val&amp;amp;action=delete&amp;#39; / &amp;gt; and have the request made on behalf of the user</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/8470235537230295561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/8470235537230295561'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1249338317873#c8470235537230295561' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1469038049'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-4532203829346248055</id><published>2009-05-21T09:10:27.565-07:00</published><updated>2009-05-21T09:10:27.565-07:00</updated><title type='text'>Great work here!  The PoC videos make it very clea...</title><content type='html'>Great work here!  The PoC videos make it very clear that there is an issue, but not how it ties in to HPP.  However, the blog post itself covers all those details nicely.  Well done!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/4532203829346248055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8349355000742867336/comments/default/4532203829346248055'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html?showComment=1242922227565#c4532203829346248055' title=''/><author><name>thornmaker</name><uri>http://p42.us</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/client-side-http-parameter-pollution.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8349355000742867336' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8349355000742867336' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-830609356'/></entry></feed>
