Cross-site request forgery - Is CSRF dead?
Main Author: | Dominik Altermatt |
---|---|
Other Authors: | Marc Ruef |
Format: | Article Journal |
Bahasa: | eng |
Terbitan: |
, 2017
|
Subjects: | |
Online Access: |
https://zenodo.org/record/3521839 |
Daftar Isi:
- CSRF stands for cross-site request forgery. This is a technique used for attacking web applications. By inadvertently calling a resource externally, a legitimate user may carry out an action involuntarily. Advanced settings for cookies reduce the possibility of attack. Dynamic CSRF tokens can prevent this type of attack.
- This paper was written in 2017 as part of a research project at scip AG, Switzerland. It was initially published online at https://www.scip.ch/en/?labs.20170921 and is available in English and German. Providing our clients with innovative research for the information technology of the future is an essential part of our company culture.