Breaking Hacker News's CSRF Protections
hankstoever.com
hankstoever.com
Without the hidden 'fnid' input, it would be possible for other sites to vote on and post content to Hacker News on your behalf without your consent.
The "hack" outlined in the article requires knowing the username and password of the person you want to "hack". Of course CSRF tokens don't protect you when your credentials are lost.
More Info: https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(...
Please fix the spelling in the sidebar.
Recieve a digest of my best content every month about software, startups, and life.
"Recieve" should be "Receive"
Since this is in the sidebar of your site, it stands out and puts a negative spin on the rest of what you have to say. Unfair? Maybe, but this is such a basic error that people will judge you based on such a basic mistake, simply because it will be easily caught by any spell-checker.
A CSRF attack is the equivalent of blind-firing a gun at a domain, and the browser "helps" you by automatically attaching your cookies to that bullet. Depending on the situation, you usually don't get a response back. Here is a good preso from when CSRF was hot back then which explains the attack scenarios: https://www.blackhat.com/presentations/bh-dc-08/Willis/Prese...
Throwing CORS into the mix complicates things a bit but that relies on the site that is being attacked to explicitly allow calls from the malicious site or use an Access-Control-Allow-Origin: * which in itself is a security vulnerability. More details on CORS: https://developer.mozilla.org/en-US/docs/HTTP/Access_control...