What is Nostr?
Douglas Huff [ARCHIVE] /
npub1xpr…6eq0
2023-06-07 01:22:27
in reply to nevent1q…avcx

Douglas Huff [ARCHIVE] on Nostr: 📅 Original date posted:2011-06-19 🗒️ Summary of this message: A vulnerability ...

📅 Original date posted:2011-06-19
🗒️ Summary of this message: A vulnerability in ClearCoin was reported and fixed, with the reporter noting that CSRFs were particularly nasty due to Google account auth.
📝 Original message:I know. Please do not take this as a personal attack. Blame MagicalTux's
irresponsible behaviour as of late. :(
On Jun 19, 2011 5:34 PM, "Gavin Andresen" <gavinandresen at gmail.com> wrote:
> Some of us take private disclosures of vulnerabilities very seriously.
>
> In any case, the ClearCoin CSRF vulnerability is fixed. Thank you for
> bringing it to my attention.
>
> On Sun, Jun 19, 2011 at 5:54 PM, Doug Huff <dhuff at jrbobdobbs.org> wrote:
>> In light of this decision I would like to report multiple CSRF
vulnerabilities in http://clearcoin.appspot.com .
>>
>> This set of CSRFs are particularly nasty since this is hosted on appspot
and uses google account auth. So long as you stay logged into your google
account you are vulnerable to this CSRF.
>
>
> --
> --
> Gavin Andresen
> http://clearcoin.com/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20110619/7d4ef3fb/attachment.html>;
Author Public Key
npub1xpryrka5nmn2vq9uum4qfjcvkfdne95l3ug4sxhdkcnndu4uu6eqrc6eq0