The Django flaw is interesting. Fortunately (or unfortunately), most of the modern browsers will be protected against the good old Flash redirect trick. Some applications even start to rely on a simple Content-Type check now to mitigate CSRF. Thanks for sharing and for the lab!
-
-
-
98% sure a Content-Type check can still be bypassed.
- Još 4 druga odgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.