<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:s="http://updates.zdnet.com/">
<channel>
	<title><![CDATA[csrf flaw Resources | ZDNet]]></title>
	<link><![CDATA[http://updates.zdnet.com/tags/csrf+flaw.html]]></link>
	<description><![CDATA[White papers, case studies, technical articles, and blog posts relating to csrf flaw]]></description>
	<s:counts start="0" returned="1" found="1" />
	<language>en-us</language>
	<item>
		<title><![CDATA[Google downplays severity of Gmail CSRF flaw]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=2773]]></link>
		<description><![CDATA[Yesterday, Vicente Aguilera Diaz from Internet Security Auditors released proof of concept of a CSRF (Cross-Site Request Forgery) vulnerability in Google's Gmail, which he originally communicated to Google two years ago. The CSRF flaw affects Gmail's "Change Password" function, since according to Diaz the session cookie is automatically sent by...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Wed, 04 Mar 2009 14:44:05 -0800</pubDate>
		<category domain="http://updates.zdnet.com/tags/google+inc..html"><![CDATA[Google Inc.]]></category>
		<category domain="http://updates.zdnet.com/tags/google+gmail.html"><![CDATA[Google Gmail]]></category>
		<category domain="http://updates.zdnet.com/tags/password.html"><![CDATA[Password]]></category>
		<category domain="http://updates.zdnet.com/tags/flaw.html"><![CDATA[Flaw]]></category>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/xss.html"><![CDATA[XSS]]></category>
		<category domain="http://updates.zdnet.com/tags/csrf+flaw.html"><![CDATA[CSRF Flaw]]></category>
		<category domain="http://updates.zdnet.com/tags/e-mail+providers.html"><![CDATA[E-mail Providers]]></category>
		<category domain="http://updates.zdnet.com/tags/cloud+computing.html"><![CDATA[Cloud Computing]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/internet.html"><![CDATA[Internet]]></category>
		<category domain="http://updates.zdnet.com/tags/dancho+danchev.html"><![CDATA[Dancho Danchev]]></category>
		<category domain="http://updates.zdnet.com/tags/dancho+danchev.html"><![CDATA[Dancho Danchev]]></category>
		<category domain="http://rss.financialcontent.com/stocksymbol">GOOG</category>
		<category domain="tickers">GOOG</category>
	</item>
</channel>
</rss>
