
Episode 28: Surfin' with CSRFs
Critical Thinking - Bug Bounty Podcast
00:00
Rails: A Quirk to Know About
A head request behaves more like a get request than a post request. If it's not a get request, then it does this alternative behavior which would be to grant permissions. I wonder if options does the same thing. Why I absolutely anticipate that this bug has, is present in other code bases as well.
Transcript
Play full episode