THE CENZIC BLOG
Read more articles in  Web Application Security Insights
.
July 31, 2008

XSRF Vulnerability Found on Singlesnet.com

Cross-site Request Forgery (XSRF) vulnerability found on Singlesnet.com

XSRF vulnerability found on singlesnet.comI reported this XSRF vulnerability almost a year ago to Singlesnet.com and got no response, so I've decided its time to share it with the community.  The root of the problem is Cross-Site Request Forgery (XSRF) using an off-domain POST.  Now some of you may not be familiar with XSRF attacks so I will summarize the root cause. 

XSRF attacks exploit a Web site's trust of its own user -- its a way of getting a user to make a request to the Web application that they are unaware of and do not authorize.  In other words, the attacker causes your browser to make a request to the Web site that has deleterious effects.  Now some of these attacks can involve malicious links (i.e. you follow the link and subsequently take an unintended action within the Web application).  Another variation of the attacks can involve forms. The attacker creates a malicious form that autosubmits with a piece of JavaScript.  You view the form, and your browser makes a request to the target application on your behalf and the attacker controls the content.

Now to Singlesnet.com:

Their site architecture allows you to change your password without supplying your current password. 

Bad idea. 

Basically, your account password, contact email, and username can all be automatically changed in one fell swoop.

The proof of concept has been removed.  If you wanna know how it works, you’ll have to figure it yourself ;-)

by
Tom Stracener
TStracener@cenzic.com

Comments
.

Massachusetts Attorney General investigating 21 complaints of Singlesnet.com

Massachusetts investigating growing mountain of complaints against dating site
Singlesnet.com has been amassing a growing mountain of complaints regarding its trade practices. As of November 25, 2008, the Massachusetts Attorney General's office (617-727-8400) has been investigating 21 complaints, all received within the past two years. The Better Business Bureau has taken down its review of this company, ostensibly for a "re-review". Reviews of this website abound on the Internet-please be careful.
.

Syndication OptionsRSS (Rich Site Summary) Feed Atom Feed OPML (Outline Processor Language) Feed MYST-ML (MyST Markup Language) Content Feed MS-Office Smart Tag Subscription