Comment on Adult sites are stashing exploit code inside svg filesComments−QAkICoU7IDNkpFu1y“The user will have to be logged in on Facebook for this to work, but we know many people keep Facebook open for easy access.”Well there's your problem right there.−mananaysiempre1yBog-standard CSRF is what that is. It’s essentially the second thing you guard against, right after sanitizing inputs to prevent XSS and SQL injection.
Comments
“The user will have to be logged in on Facebook for this to work, but we know many people keep Facebook open for easy access.”
Well there's your problem right there.
Bog-standard CSRF is what that is. It’s essentially the second thing you guard against, right after sanitizing inputs to prevent XSS and SQL injection.