Princeton Security Researchers Find 4 Security Bugs In World’s Popular Sites

Reports have surfaced of four pernicious, exploitable vulnerabilities on some of the world’s most visited sites.
Discovered by Princeton University Center for Information Technology Policy Security Researchers Bill Zeller and Ed Felton, the vulnerabilities affect such sites as The New Your Times, YouTube and ING Direct.
From Bill Zellers’ post: “Today Ed Felten and I (Bill Zeller) are announcing four previously unpublished Cross-Site Request Forgery (CSRF) vulnerabilities. We’ve described these attacks in detail in a technical report titled Cross-Site Request Forgeries: Exploitation and Prevention.
We found four major vulnerabilities on four different sites. These vulnerabilities include what we believe is the first CSRF vulnerability that allows the transfer of funds from a financial institution. We contacted all the sites involved and gave them ample time to correct these issues. Three of these sites have fixed the vulnerabilities listed below, one has not.“
[1] Freedom To Tinker: Popular Websites Vulnerable to Cross-Site Request Forgery Attacks [2] Freedom To Tinker: Zeller & Felton Report




