2009 May 22, 12:10
sequelguy posted a photo:
2009 May 22, 12:10
sequelguy posted a photo:
california hotel 2009 May 22, 12:10
sequelguy posted a photo:
california hotel 2009 May 22, 12:10
sequelguy posted a photo:
california hotel monterey 2009 May 22, 12:10
sequelguy posted a photo:
california hotel monterey 2009 May 22, 11:26
sequelguy posted a photo:
trees house home washington redmond 2009 May 3, 10:36
Looking at the HTTP traffic of Netflix under Fiddler I could see the HTTP request that added a movie to my queue and didn't see anything obvious that would
prevent a CSRF. Sure enough its pretty easy to create a page that, if the user has set Netflix to auto-login, will add movies to the user's queue without their knowledge. I thought this was pretty
neat, because I could finally get people to watch Primer. However, when I searched for Netflix CSRF I found that this issue has been known and reported to Netflix since 2006. Again my thoughts stolen from me and the
theif doesn't even have the common decency to let me have the thought first!
With this issue known for nearly three years its hard to continue calling it an issue. Really they should just document it in their API docs and be
done with it. Who knows what Netflix based web sites and services they'll break if they try to change this behavior? For instance, follow this link to add my Netflix recommended movies to your queue.
technical stolen-thoughts csrf netflix security 2009 May 2, 8:42
sequelguy posted a photo:
flower washington tulip 2009 May 2, 8:42
sequelguy posted a photo:
flower washington tulip 2009 May 2, 8:41
sequelguy posted a photo:
flower washington tulip crate 2009 May 2, 8:41
sequelguy posted a photo:
washington ladybug 2009 May 2, 8:41
sequelguy posted a photo:
flower sarah washington tulip 2009 May 2, 8:40
sequelguy posted a photo:
flower me washington tulip 2009 May 2, 8:40
sequelguy posted a photo:
red flower washington tulip 2009 May 2, 1:43
sequelguy posted a photo:
flower washington tulip 2009 Apr 23, 10:33
sequelguy posted a photo:
california napa