Sphinn Home » SEM
If you are logged into Sphinn and visit this story, you will vote it up, automatically. A perfect example of cross-site request forgery (XSRF)
10 Comments     

Comments

from DianeV 324 days ago #
Votes: 0 | Vote:
+ -

So, that's what multiple browsers are for. :)

from Sebastian 324 days ago #
Votes: 0 | Vote:
+ -

Autovote didn't work. I had to click the link in your post.

from aimClear 324 days ago #
Votes: 0 | Vote:
+ -

I would have Sphunn it anyway!

from evilgreenmonkey 324 days ago #
Votes: 0 | Vote:
+ -

1x1 pixel iframes are soooo y2k dude, why don't you stick an iframe in the page for each of your websites so that it boosts their Alexa rank as well?! 

Modern browsers don't usually fool for these tricks anymore, it's not exactly an urgent fix :o)

No Sphinn from me... 


from SimonHeseltine 324 days ago #
Votes: 0 | Vote:
+ -

Hmm, I was logged in, it didn't autovote for me either...

from dannysullivan 324 days ago #
Votes: 0 | Vote:
+ -

Yep, we know there are issues with the underlying Pligg software. For the moment, we're upgrading the software itself to speed up the site. Then we're going to push forward witht the customization we've already been doing, to make it harder to fake friends or voting. In the end, things that are unusual tend to stick out, and since we don't rely solely on automation, we kill stuff off.

from planetc1 324 days ago #
Votes: 0 | Vote:
+ -

And it's probably not ever a good idea to instigate the evilgreenmonkey.

from janecopland 324 days ago #
Votes: 0 | Vote:
+ -

Lol, I seriously considered not clicking through from thegooglecache, because I didn't necessarily want my avatar showing up under "who Sphunn this", but I couldn't help myself. I'm the kid who always wanted to touch the CD player's lens after reading the notice that said "do not touch the lens." Hey Danny! Here's a good reason for an "unsphinn" button :D

from rjonesx 324 days ago #
Votes: 0 | Vote:
+ -

:) Thanks folks - yes, the XSRF is not fool-proof, I threw it together this morning after I noticed that I could cast a vote via redirect w/o ever going through additional authentication.

I will take down the XSRF now :)


from samantha85 322 days ago #
Votes: 0 | Vote:
+ -

NO AUTO VOTE :-|


Log in to comment or register here.
Search Marketing Expo

Save the date for:
SMX China (Nanjing) - Sept. 23-24
SMX Stockholm - Sept. 23-24: See who's speaking or register now.
SMX East (New York City) - Oct. 6-8: See the agenda or register today and save!
SMX London - Nov. 4-5: Pre-agenda rate now available. Click here.