Proceedings of the 27th Annual Computer Security Applications Conference 2011
DOI: 10.1145/2076732.2076768
|View full text |Cite
|
Sign up to set email alerts
|

A server- and browser-transparent CSRF defense for web 2.0 applications

Abstract: Cross-Site Request Forgery (CSRF) vulnerabilities constitute one of the most serious web application vulnerabilities, ranking fourth in the CWE/SANS Top 25 Most Dangerous Software Errors. By exploiting this vulnerability, an attacker can submit requests to a web application using a victim user's credentials. A successful attack can lead to compromised accounts, stolen bank funds or information leaks. This paper presents a new server-side defense against CSRF attacks. Our solution, called jCSRF, operates as a s… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2012
2012
2019
2019

Publication Types

Select...
2
2
1

Relationship

0
5

Authors

Journals

citations
Cited by 6 publications
(1 citation statement)
references
References 8 publications
0
1
0
Order By: Relevance
“…The application is unaware that the tokens are being inserted and validated by the proxy. Proxy-based CSRF protection and WAVES do not interfere with one another as long as the proxy properly addresses AJAX requests, such as [14]. The fact that WAVES outfitted the original application to include additional JavaScript on the client and AJAX stubs on the server is irrelevant to the proxy; the developer could have added that code herself.…”
Section: Csrf Protection (Csrf)mentioning
confidence: 99%
“…The application is unaware that the tokens are being inserted and validated by the proxy. Proxy-based CSRF protection and WAVES do not interfere with one another as long as the proxy properly addresses AJAX requests, such as [14]. The fact that WAVES outfitted the original application to include additional JavaScript on the client and AJAX stubs on the server is irrelevant to the proxy; the developer could have added that code herself.…”
Section: Csrf Protection (Csrf)mentioning
confidence: 99%