FREE Registration is required
Overview:
Cross-Site Request Forgery (CSRF) is a widely exploited web site vulnerability. This paper presents a new variation on CSRF attacks, login CSRF, in which the attacker forges a cross-site request to the login form, logging the victim into the honest web site as the attacker. The severity of login CSRF vulnerability varies by site, but it can be as severe as a cross-site scripting vulnerability. It detailed three major CSRF defense techniques and find shortcomings with each technique. Its observations do suggest, however, that the header can be used today as a reliable CSRF defense over HTTPS, making it particularly well-suited for defending against login CSRF. It also proposes that browsers implement the Origin header, which provides the security benefits of the Referer header while responding to privacy concerns.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Size: | 3,023 KB | |
| Date: | Oct 2008 | ||
| Pages: | 13 |
Top results from Security Management
» View all Security Management listings
Top results from Network Security
White Papers, Webcasts, and Resources
- Selling through a Slump OraclePrepare for the recovery with practical tips and experience-based wisdom from 11 of todays top sales experts in this industry-by-industry playbook.
- Choosing the Best CRM for Your Organization OracleGet tips for evaluating CRM systems for their functionality, ease of integration, customization features, and cost. (Oracle)
- The Essential Guide: Real-Time High Availability for Exchange - Replicate Exchange Data for Improved Resiliency CA XOsoftSurvive major interruptions to your Exchange environment--and improve its resiliency and availability--with a real-time data replication solution.
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- SmartPlanet
Discover innovative insight and ideas that impact the world around you -
SmartPlanet offers expert advice on innovations in healthcare, including electronic personal health records, treatment, privacy and regulation, and the green technologies that make it happen.
- Learn more >>










