<p dir="ltr">I have been trying to figure out a scenario where the XSRF attack could be used to do real hard. Just now I got an idea. </p>
<p dir="ltr">Say you have a payment service like amazon or PayPal. You could then use this attack to get a victim to enter his/her credit card info on another users account. </p>
<p dir="ltr">What do you think, good example? </p>
<div class="gmail_quote">On 26 Dec 2014 19:43, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 12/26/14, 11:10 AM, "Stefan Rasmusson" <<a href="mailto:rasmusson.stefan@gmail.com">rasmusson.stefan@gmail.com</a>><br>
wrote:<br>
<br>
>Ok, so you can force a user to be signed in to a back account that you<br>
>have valid credentials for. Any idea what this attack can be used for?<br>
<br>
If you're depositing money?<br>
<br>
> Or is it just a general problem that you are able to make the user do<br>
>that?<br>
<br>
XSRF attacks are a general class of attack. I have no special expertise in<br>
understanding them.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>