August 2021
Intermediate to advanced
304 pages
8h 50m
English
This chapter covers
Referer headerThis chapter examines another large family of attacks, cross-site request forgery (CSRF). A CSRF attack aims to trick the victim into sending a forged request to a vulnerable website. CSRF resistance boils down to whether or not a system can distinguish a forged request from a user’s intentional requests. Secure systems do this via request headers, response headers, cookies, and state management conventions; defense in depth is not optional.
Suppose Alice deploys admin.alice.com, the administrative counterpart of her online ...
Read now
Unlock full access