
Episode 28: Surfin' with CSRFs
Critical Thinking - Bug Bounty Podcast
00:00
The Limits of CSRF Vulnerability
I think it's really interesting to think about how CSRF is one of the more like old school type of vulnerabilities. We do still exploit CSRFs via form elements. And I'm looking right now, you can set the content type on a form element using the enc type attribute and the method by the method attribute. It would be really cool if we could specify not only the content type, but the character encoding in here as well.
Transcript
Play full episode