<div dir="ltr">Ok, so you can force a user to be signed in to a back account that you have valid credentials for. Any idea what this attack can be used for? Or is it just a general problem that you are able to make the user do that?</div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div><br></div><div>--</div>Stefan</div></div>
<br><div class="gmail_quote">On 23 December 2014 at 15:55, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 12/23/14, 1:25 PM, "Tom Scavo" <<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>> wrote:<br>
>><br>
>> It's also a XSRF attack by definition.<br>
><br>
>Wouldn't user consent effectively thwart that issue?<br>
<br>
</span>Not in the way that the attack would normally work here. What's unusual<br>
about this kind of XSRF attack is that it involves a user giving a valid<br>
response to a *different* user. That is, I log in via a request from my<br>
banking service and give your client the response so that you're logged<br>
into my bank, but you think you're logged into yours.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>