I think this may be the first PURE CSRF vulnerability that I’ve seen that resulted in compromise of a victims machine
Ouch.
If you’re using Django, by the way, you really have no excuse if you get caught by a CSRF attack.
Comments for this link are closed. If you'd like to share your thoughts on this link with me, please contact me directly.