Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

When good XSRF defence turns bad

Summary

Two-step nonce defences against XSRF fail when implemented carelessly: in one app the second step was an HTTP redirect, leaking the nonce and leaving the standard protection ineffective.
Published
Collected

original ↗

Related coverage

back