<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.cenzic.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.cenzic.com/public/?>

<MySmartChannels Public="true" UserID="202607" dT="132" t0="1283905741593">
     <GetChannelItem_Result>
      <Item>
       <Resource>
        <ObjectID>221255</ObjectID>
        <ObjectClass>Resource</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="[Weblog] Web Application Security Insights">202615</OwnerID>
        <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
        <CreateTime Title="2008-12-19 20:44:11 EST">1229737451585</CreateTime>
        <ModifyTime Title="2008-12-19 20:51:08 EST">1229737868683</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>Real World Hacking Example:  The New York Times</Name>
        <Summary>CSRF vulnerability in the New York Times Website allows hackers to detect email addresses of users</Summary>
        <Description>&lt;p&gt;&lt;a href="http://www.freedom-to-tinker.com/blog/wzeller/popular-websites-vulnerable-cross-site-request-forgery-attacks"&gt;&lt;img alt="Real-world hacking example - the new york times" hspace="10" src="http://www.cenzic.com/images/blog/hacker_gold.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;According to a recent &lt;a title="Real world examples of hacking - the new york times" href="http://www.freedom-to-tinker.com/blog/wzeller/popular-websites-vulnerable-cross-site-request-forgery-attacks" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;post&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and &lt;a title="CRSF vulnerability examples - 4 popular Websites hacked" href="http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;paper&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; by Bill Zeller, &lt;strong&gt;The New York Times&lt;/strong&gt; was among four popular Websites that got hacked through a &lt;strong&gt;CSRF vulnerability&lt;/strong&gt;.&amp;nbsp; &lt;/p&gt;&lt;p&gt;This CSRF vulnerability was exploited to extract the email address of a user.&amp;nbsp; The attack can be used for identification (e.g., finding the email addresses of all users who visit an attacker's site) or for spam. This attack is particularly dangerous because of the large number of users who have NYTimes' accounts and because the NYTimes keeps users logged in for over a year.&amp;nbsp; &lt;/p&gt;&lt;p&gt;According to the report, the New York Times fixed this issue after a few months of prodding by the author.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Here&amp;rsquo;s a great summary by the author about CSRF and how little the IT and security community know about this vulnerability:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The Sleeping Giant&lt;br /&gt;&lt;/strong&gt;Cross-Site Request Forgery (CSRF) attacks occur when a malicious Website causes a user&amp;rsquo;s Web browser to perform an unwanted action on a trusted site. These attacks have been called the &amp;ldquo;sleeping giant&amp;rdquo; of Web-based vulnerabilities, because many sites fail to protect against them and they&amp;rsquo;ve been &lt;strong&gt;largely ignored by the Web development and security communities&lt;/strong&gt;.&amp;nbsp; CSRF attacks do not appear in the Web Security Threat Classification and are rarely discussed in academic or technical literature.&amp;nbsp; CSRF attacks are simple to diagnose, simple to exploit and simple to fix. They exist because Web developers are uneducated about the cause and seriousness of CSRF attacks.&amp;nbsp; Web developers also may be under the mistaken impression that defenses against the better-known Cross-Site Scripting (XSS) problem also protect against CSRF attacks.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
        <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
        <ContentType>application/xml</ContentType>
        <ContentDocument>
         <ItemProperties>
               <CommonProperties>
                <Hidden>false</Hidden>

                <Keywords>
                 <Keyword>hack</Keyword>

                 <Keyword>new york times</Keyword>

       </Keywords>

                <Links>
                 <Link>
                  <Title>Popular Websites Vulnerable to Cross-Site Request Forgery Attacks</Title>

                  <Synopsis>4 real-world example of how hackers attack Websites</Synopsis>

                  <URL>http://www.freedom-to-tinker.com/blog/wzeller/popular-websites-vulnerable-cross-site-request-forgery-attacks</URL>

        </Link>

                 <Link>
                  <Title>Cross-Site Request Forgeries: Exploitation and Prevention</Title>

                  <Synopsis>Read this 13 page paper on CSRF</Synopsis>

                  <URL>http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf</URL>

        </Link>

       </Links>

      </CommonProperties>

               <RemoteInfo>
                <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)</UserAgent>

                <RemoteHost>127.0.0.1</RemoteHost>

                <RemoteAddr>127.0.0.1</RemoteAddr>

                <RemoteUser>eswanson</RemoteUser>

                <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
        </ContentDocument>
       </Resource>
       <Shares/>
       <Subjects/>
       <UserPermissions>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanRead>true</CanRead>
       </UserPermissions>
       <CommentInfo>
        <CommentChannelRef AllowAnonymous="true" Inherited="true">
         <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
         <UserPermissions>
          <CanCreateChannelItem>false</CanCreateChannelItem>
          <CanDelete>false</CanDelete>
          <CanDiscover>true</CanDiscover>
          <CanEdit>false</CanEdit>
          <CanEditPermissions>false</CanEditPermissions>
          <CanPublish>false</CanPublish>
          <CanRead>true</CanRead>
         </UserPermissions>
        </CommentChannelRef>
        <Comments>
         <Comment>
          <Item>
           <Resource>
            <ObjectID>247601</ObjectID>
            <ObjectClass>Resource</ObjectClass>
            <OwnerID ObjectClass="Domain" Title="[Public] Public Comments">204329</OwnerID>
            <CreatedByID ObjectClass="User" Title="$Anonymous">173239</CreatedByID>
            <ModifiedByID ObjectClass="User" Title="$Anonymous">173239</ModifiedByID>
            <CreateTime Title="2009-12-23 20:56:58 EST">1261619818987</CreateTime>
            <ModifyTime Title="2009-12-23 20:56:58 EST">1261619818987</ModifyTime>
            <SecurityModel>Controlled</SecurityModel>
            <Name>RE: Real World Hacking Example:  The New York Times</Name>
            <Summary/>
            <Description>Winter is coming ,many people are afraid of cold,especially the feet.then you must something to keep warm,I think you need a pair of snow boots,made of wool.such as UGG boots,tall boots,short boots or mini boots,Very warm to wear them.And the style ,the color also the material,the quality are very good .Walking in the fashion front.
welcome to my web http://www.uggboots-space.com</Description>
            <ResourceTypeID ObjectClass="ResourceType" Title="Item:Content">10</ResourceTypeID>
            <ContentType>application/xml</ContentType>
            <ContentDocument>
             <ItemProperties>
                   <CommonProperties>
                    <Hidden>true</Hidden>

      </CommonProperties>

                   <ns3:Details xmlns="urn:MyST-Technology.Structured.Details" xmlns:ns3="urn:MyST-Technology.Structured.Details">
                    <ns3:Collection name="han" type="urn:MyST-Technology.Structured.Collection.Contact">
                     <ns3:Attribute name="EMail" type="email" value="han-yi-good@163.com"/>

                     <ns3:Attribute name="Web" type="url" value="http://www.uggboots-space.com"/>

                     <ns3:Attribute name="Twitter" type="twitter" value=""/>

       </ns3:Collection>

      </ns3:Details>

                   <RemoteInfo>
                    <UserAgent>Mozilla/5.0 (Windows; U; Windows NT 5.1; zh-CN; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6 GTB6</UserAgent>

                    <RemoteHost>127.0.0.1</RemoteHost>

                    <RemoteAddr>127.0.0.1</RemoteAddr>

                    <ForwardedFor>59.58.175.182</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
            </ContentDocument>
           </Resource>
           <UserPermissions>
            <CanDelete>false</CanDelete>
            <CanDiscover>true</CanDiscover>
            <CanEdit>false</CanEdit>
            <CanEditPermissions>false</CanEditPermissions>
            <CanRead>true</CanRead>
           </UserPermissions>
           <CommentInfo>
            <CommentChannelRef>
             <ChannelID/>
            </CommentChannelRef>
            <Comments/>
           </CommentInfo>
          </Item>
         </Comment>
        </Comments>
       </CommentInfo>
       <Views>
        <SourceID ObjectClass="Channel" Title="[Weblog] Web Application Security Insights">202615</SourceID>

               <View>
                <Name>blog</Name>

                <Model>blogsite/Cenzic/web</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>edit-item</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>left</Name>

                <Model>blogsite/Cenzic/left-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>right</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>wide</Name>

                <Model>blogsite/Cenzic/wide-content</Model>

                <Style/>

                <Scheme/>

       </View>

      </Views>
        <Views>
         <SourceID ObjectClass="Channel" Shared="true" Title="[Public] What's New">202621</SourceID>

                <View>
                 <Name>blog</Name>

                 <Model>blogsite/Cenzic/whatsnew</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>edit-item</Name>

                 <Model>blogsite/Cenzic/right-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>left</Name>

                 <Model>blogsite/Cenzic/left-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>right</Name>

                 <Model>blogsite/Cenzic/right-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>wide</Name>

                 <Model>blogsite/Cenzic/wide-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

      </Views>
        </Item>
       </GetChannelItem_Result>
      </MySmartChannels>
