Demo 1: CSRF ------------ Introduce BlabberOne blabberone.sitepen.com Show: all users making friends sending messages getting random friends Ensure the audience has seen tweets Hop over to Twitter Check out tweet from Dion http://localhost:8080/csrf-demo/ CSRF to remove all tweets The point: The page that Dion linked to, used CSRF to abuse my superuser privs on blabberone to delete all the tweets Demo 2: JavaScript Hijack ------------------------- Visit http://localhost:8080/csrf-demo/hijack.html Point out that this is using CSRF to READ Demo 3: XSS ----------- Change my BG to black Jeremiah: log into blabberone, and message this: Some random message