Links published in April 2008

2 links published in this month. See also: all links published in 2008, latest links.

CSRF pwns your box?!?!

I think this may be the first PURE CSRF vulnerability that I’ve seen that resulted in compromise of a victims machine

Ouch.

If you’re using Django, by the way, you really have no excuse if you get caught by a CSRF attack.

(Via Planet Websecurity)

Visit site or read comments

When Should Isaac Laquedem Stop Reproducing?

First line says it all, really:

You’re the Wandering Jew. When do you start worrying about sleeping with your own descendants?

Most brilliant Ask Mefi question in a while.

Visit site or read comments

ponybadge