<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Vimeo highly vulnerable to CSRF attacks &#8211; now fixed</title>
	<atom:link href="http://www.barklund.org/blog/2010/02/12/vimeo-vulnerable-csrf/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.barklund.org/blog/2010/02/12/vimeo-vulnerable-csrf/</link>
	<description>work smarter when building current web trends</description>
	<lastBuildDate>Wed, 23 Nov 2011 11:48:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
	<item>
		<title>By: Barklund</title>
		<link>http://www.barklund.org/blog/2010/02/12/vimeo-vulnerable-csrf/comment-page-1/#comment-103494</link>
		<dc:creator>Barklund</dc:creator>
		<pubDate>Fri, 12 Feb 2010 14:23:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.barklund.org/blog/?p=683#comment-103494</guid>
		<description>Well, it is not like anyone could use this to attack &quot;random&quot; accounts - only to attack visitors to a malicious website, that happened to have a Vimeo account as well.

Vimeo keep the auto-login-cookie for 10 years as default, so if you have just logged in once and not logged out, switched browser or cleared cookies, you&#039;re still logged in most likely.

And thus, your account could only have been &quot;attacked&quot; in the above-mentioned way (by appending something to your bio) if you had visited the above web page while Vimeo had the wrong policy in place.</description>
		<content:encoded><![CDATA[<p>Well, it is not like anyone could use this to attack &#8220;random&#8221; accounts &#8211; only to attack visitors to a malicious website, that happened to have a Vimeo account as well.</p>
<p>Vimeo keep the auto-login-cookie for 10 years as default, so if you have just logged in once and not logged out, switched browser or cleared cookies, you&#8217;re still logged in most likely.</p>
<p>And thus, your account could only have been &#8220;attacked&#8221; in the above-mentioned way (by appending something to your bio) if you had visited the above web page while Vimeo had the wrong policy in place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: felisan</title>
		<link>http://www.barklund.org/blog/2010/02/12/vimeo-vulnerable-csrf/comment-page-1/#comment-103450</link>
		<dc:creator>felisan</dc:creator>
		<pubDate>Fri, 12 Feb 2010 07:46:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.barklund.org/blog/?p=683#comment-103450</guid>
		<description>scary!
just had to check information on my own account, to see if I had been attacked :O)</description>
		<content:encoded><![CDATA[<p>scary!<br />
just had to check information on my own account, to see if I had been attacked :O)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Shiflett</title>
		<link>http://www.barklund.org/blog/2010/02/12/vimeo-vulnerable-csrf/comment-page-1/#comment-103377</link>
		<dc:creator>Chris Shiflett</dc:creator>
		<pubDate>Fri, 12 Feb 2010 01:36:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.barklund.org/blog/?p=683#comment-103377</guid>
		<description>Nice find. I&#039;m glad you contacted them, and I&#039;m glad they fixed it.</description>
		<content:encoded><![CDATA[<p>Nice find. I&#8217;m glad you contacted them, and I&#8217;m glad they fixed it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
