|
|
|
|
|
by jeremyloy_wt
65 days ago
|
|
I don’t understand your explanation on mitigating the confused deputy. If the attacker has access to the database, can’t they just read the IDs for the target row they are overriding first so they can generate the correct hash? |
|