Security/Features/Intranet CSRF Blocker: Difference between revisions

Jump to navigation Jump to search
no edit summary
No edit summary
No edit summary
Line 7: Line 7:
|Feature product manager=Lucas Adamski
|Feature product manager=Lucas Adamski
|Feature lead engineer=Steve Workman
|Feature lead engineer=Steve Workman
|Feature additional members=Brian Smith
}}
}}
{{FeaturePageBody
{{FeaturePageBody
Line 19: Line 20:
* [http://www.symantec.com/avcenter/reference/Driveby_Pharming.pdf "Drive-By Pharming"]
* [http://www.symantec.com/avcenter/reference/Driveby_Pharming.pdf "Drive-By Pharming"]
* [http://ha.ckers.org/blog/20080108/cross-site-printing/ "Cross site printing"]
* [http://ha.ckers.org/blog/20080108/cross-site-printing/ "Cross site printing"]
|Feature dependencies=See related bug https://bugzilla.mozilla.org/show_bug.cgi?id=354493
|Feature non-goals=The reverse case, where a web page on a private network sends requests for non-private resources, is common and is not considered an attack case that we are trying to prevent.
|Feature non-goals=The reverse case, where a web page on a private network sends requests for non-private resources, is common and is not considered an attack case that we are trying to prevent.
}}
}}
Confirmed users
717

edits

Navigation menu