List: websecurity@lists.webappsec.org
From: Sripathi Krishnan
Re: [WEB SECURITY] CSRF: Flash + 307 redirect = Game Over
Thu, Feb 10, 2011 8:50 PM
Web server frameworks can no
> longer rely on the implied security of additional HTTP Request Headers alone
> to prevent CSRF.
>
> I think it would be more reasonable to convince Adobe to fix it, than
> to write off this mechanism as an XSRF defense... unfortunately, as I
> understand it, they are aware of this problem for a longer while (> 6
> months), and it's