CSRF protection bypass due to Google analytics and weird server cookie parsing

The Wolves of Vuln Street – System Dynamics Model of the 0day Market

$9000 bounty paid for Python bug