Cross-site request forgery - Is CSRF dead?

Main Author: Dominik Altermatt
Other Authors: Marc Ruef
Format: Article Journal
Bahasa: eng
Terbitan: , 2017
Subjects:
Online Access: https://zenodo.org/record/3521839
Daftar Isi:
  • CSRF stands for cross-site request forgery. This is a technique used for attacking web applications. By inadvertently calling a resource externally, a legitimate user may carry out an action involuntarily. Advanced settings for cookies reduce the possibility of attack. Dynamic CSRF tokens can prevent this type of attack.
  • This paper was written in 2017 as part of a research project at scip AG, Switzerland. It was initially published online at https://www.scip.ch/en/?labs.20170921 and is available in English and German. Providing our clients with innovative research for the information technology of the future is an essential part of our company culture.