nitter
Jeff Williams
@planetlevel
14 Jun 2011
RT
@WeldPond
: RT
@chriseng
: Re Citigroup http://nyti.ms/mi2v0N inserting acct
#s
into address bar = direct object reference OWASP T10-A4
1
1
1
Bil Corry
@bilcorry
14 Jun 2011
Replying to
@planetlevel
@planetlevel
@weldpond
@chriseng
I wonder which 'security experts' claimed it was 'especially ingenious' - hardly seems so...
Jun 14, 2011 · 4:04 AM UTC