When good XSRF defence turns bad
Summary
Two-step nonce defences against XSRF fail when implemented carelessly: in one app the second step was an HTTP redirect, leaking the nonce and leaving the standard protection ineffective.
- Published
- Collected
Skip to content