|
|
|
|
|
by kelvin0
3530 days ago
|
|
I've read the article twice, and I'm not totally clear as to what the problem is, and how it's being addressed (web n00b here). Also, this bit: "Browsers will not send the Referer for resources fetched via HTTP from a document loaded via HTTPS" So using HTTPS resolves the issue? But breaks analytics? Any further clarification would be nice, thanks! |
|
For instance, someone places Google Analytics in the head of the default layout for a given site. Now traffic to and from the password reset page, which uses that layout, is being recorded. This means an attacker would only need to gain access to that account, which is probably much less guarded, and gather referrers containing password reset tokens. From there they could quickly try the last few--which might still be active--and easily gain access to one or more accounts within the site.