Skip to content

Comment on Faking votes on Hacker Newsparent

Comments

XSS, yes. CSRF, no, or at least not completely. You still need to know the user's username, which is better than it could have been.

This was a CSRF attack, which is mostly unrelated to XSS.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.