• Twitter

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Čeština
    • Dansk
    • Deutsch
    • EnglishUK
    • Español
    • Filipino
    • français
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • română
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Русский
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • हिन्दी
    • বাংলা
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in New to Twitter? Join Today »
    Log in

    Forgot password?
    Already using Twitter via text message?

  1. Ashar Javed ‏@soaj1664ashar 18 May 2013

    Do you think SIGN-UP form has #CSRF protection or not? // cc @ircmaxell @homakov @padraicb @johnwilander

    Expand Collapse 0 replies 0 retweets 0 favorites
  2. Anthony Ferrara ‏@ircmaxell 18 May 2013

    @soaj1664ashar @homakov @padraicb @johnwilander I don't think it's *necessary*. I wouldn't knock code that didn't...

    Expand Collapse 0 replies 0 retweets 1 favorite
  3. Pádraic Brady ‏@padraicb 18 May 2013

    @ircmaxell @soaj1664ashar CAPTCHAs counteract nuisance signups or timing attacks on username list /cc @homakov @johnwilander

    Expand Collapse 0 replies 0 retweets 0 favorites
  4. Egor Homakov ‏@homakov 18 May 2013

    @padraicb @ircmaxell @soaj1664ashar @johnwilander any form must have CSRF prot, no excuses

    Expand Collapse 0 replies 0 retweets 1 favorite
  5. Rafay baloch ‏@rafaybaloch 19 May 2013

    @homakov @padraicb @ircmaxell @soaj1664ashar @johnwilander What's the need of CSRF token inside of Sign up form? @homakov

    Expand Collapse 0 replies 0 retweets 1 favorite
  6. Egor Homakov ‏@homakov 19 May 2013

    @rafaybaloch @padraicb @ircmaxell @soaj1664ashar @johnwilander it doesn't matter, every changing request must have it by default

    Expand Collapse 0 replies 0 retweets 0 favorites
  7. Rafay baloch ‏@rafaybaloch 19 May 2013

    @homakov @padraicb @ircmaxell @soaj1664ashar But it's not necessary, Capacha is enough to protect..

    Expand Collapse 0 replies 0 retweets 0 favorites
  8. Egor Homakov ‏@homakov 19 May 2013

    @rafaybaloch @padraicb @ircmaxell @soaj1664ashar captcha mitigates automated registration — unrelated. if signup logs in — session fixation

    Expand Collapse 0 replies 0 retweets 1 favorite
  9. Rafay baloch ‏@rafaybaloch 19 May 2013

    @homakov @padraicb @ircmaxell @soaj1664ashar What can you accomplish, when sign up form does not have CSRF token, but has capacha...answers

    Expand Collapse 0 replies 0 retweets 1 favorite
  10. Egor Homakov ‏@homakov 19 May 2013

    @rafaybaloch @padraicb @ircmaxell @soaj1664ashar easy. i get solve captcha myself and send the solution along with my own recaptcha_token

    Expand Collapse 0 replies 0 retweets 0 favorites
    Rafay baloch ‏@rafaybaloch 19 May 2013

    @homakov @padraicb @soaj1664ashar Capacha can be used instead of CSRF protection on Sign up form, and it cannot also be bypassed by xss ;)

    0 replies 0 retweets 1 favorite
    • Favorite 1
    • ᶠᶸᶜᵏ
    2:27 AM - 19 May 2013
    1. Pádraic Brady ‏@padraicb 19 May 2013

      @rafaybaloch I assume bypass would be to re-display CAPTCHA to target as something innocuous (e.g UI confirm check) @homakov @soaj1664ashar

      Expand Collapse 0 replies 0 retweets 0 favorites
    2. Egor Homakov ‏@homakov 19 May 2013

      @padraicb @rafaybaloch @soaj1664ashar challenge and answer are both parameters. Not cookie

      Expand Collapse 0 replies 0 retweets 0 favorites

      Don’t miss any updates from Rafay baloch

      • © 2014 Twitter
      • About
      • Help
      • Ads info

      Flag this media

      This has already been marked as containing sensitive content.

      Learn more about flagging media
      Dismiss
      Previous
      Next

      Go to a person's profile

      Saved searches

      • Remove
      • Verified account @
      Suggested users
      • Verified account @
      • Verified account @

      Retweet this to your followers?

      Are you sure you want to delete this Tweet?

      Block

      • Add a location to your Tweets

        When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more

      • Turn off location

      Profile summary

      Your lists

      Create a new list


      Under 100 characters, optional

      Privacy

      Embed this Tweet

      Add this Tweet to your website by copying the code below. Learn more

      Hmm, there was a problem reaching the server.

      Preview

      Sign up for Twitter

      Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

      Have an account? Log in »

      Two-way (sending and receiving) short codes:

      Country Code For customers of
      United States 40404 (any)
      Canada 21212 (any)
      United Kingdom 86444 Vodafone, Orange, 3, O2
      Brazil 40404 Nextel, TIM
      Haiti 40404 Digicel, Voila
      Ireland 51210 Vodafone, O2
      India 53000 Bharti Airtel, Videocon, Reliance
      Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
      Italy 4880804 Wind
      3424486444 Vodafone
      » See SMS short codes for other countries

      Confirmation

      Buy Now

      Hmm... Something went wrong. Please try again.