November 2017
Intermediate to advanced
452 pages
11h 46m
English
|
Threat description |
Attacker could forge requests under the logged-in user account (CSRF) |
|
Threat target |
Embedded and vendor web app. |
|
Attack techniques |
Attacker identifies a vulnerable HTML form and creates code to forge the requested change in the context of the logged-in user. Such changes may include adding or sharing a user account to a third party. |
|
Countermeasures |
Implement anti-CSRF tokens for sensitive HTML forms that change application state. |
Read now
Unlock full access