Prominent Web Sites Found to have Serious Coding Flaw
As of Sept. 24, the flaw had not been fixed, although the authors wrote they notified the newspaper in September 2007.
ING's problem had more alarming consequences. Zeller and Felten wrote the CSRF flaw allowed an additional account to be created on behalf of a victim. Also, an attacker could transfer a victim's money into their own account. ING has since fixed the problem, they wrote.
On MetaFile's Web site, a hacker could obtain a person's password. On YouTube, an attack could add videos to a user's "favorites" and send arbitrary messages on a user's behalf, among other actions. On both sites, the CSRF problems have been fixed.
Luckily, CSRF flaws are easy to find and easy to fix, which the authors give technical detail on in their paper. They've also created a Firefox add-on that defends against certain kinds of CSRF attacks.
$firstKeyword



