Slashdot Mirror


Cross Site Cooking

Liudvikas Bukys writes "Michal Zalewski identifies a new class of attacks on users of web applications, dubbed Cross Site Cooking. Various browsers' implementations of restrictions on where cookies come from and where they're sent are weaker than you think. Web applications that depend on the browser enforcing much will offer many opportunities for mischief."

3 of 125 comments (clear)

  1. Cross Site Cooking? by Anonymous Coward · · Score: 1, Funny

    Don't you bake cookies?

  2. Re:Nasty by dasil003 · · Score: 2, Funny

    ...unless you want all your AOL-based visitors to keep getting logged out.

    Uhhhhmmmm...

    Nah, it's too easy.

    Seriously, good point, it just underscores the problem.

  3. Re:Opera by mrdaveb · · Score: 2, Funny

    Kryten: RFC Directive 2965 'No officer above the rank of mess sergeant is permitted to go into combat with pierced nipples'. Sorry sir, I fail to see the relevance

    --
    Homme petit d'homme petit, s'attend, n'avale