Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Facebook CSRF and XSS vulnerabilities

Go down

Facebook CSRF and XSS vulnerabilities Empty Facebook CSRF and XSS vulnerabilities

Post  andry Fri Nov 19, 2010 1:17 am

Facebook comes with an anti-CSRF system based on two tokens, respectively called post_form_id and fb_dtsg. These tokens change frequently, and are certainly built upon several parameters including time of day, time of account creation, user id, and many others. Determining the values of these tokens for a specific user is, to our view, impossible.

Fortunately, Facebook provides a functionality called “profile preview”, allowing users to see how their own profile appears to any other user. It can be accessed using the URL

More Details:http://www.wargan.com
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum