CSRF. Danger. Detection. Defenses презентация

Содержание

Слайд 2

Overview Discussion of the “Same Origin Policy” Overview of the

Overview

Discussion of the “Same Origin Policy”
Overview of the “Sleeping Giant”
The Introduction

of
2 New OWASP Tools
A Series of New WebGoat Labs
Enterprise CSRF Mitigation Strategy
Слайд 3

The Browser “Same Origin” Policy bank.com blog.net XHR XHR document, cookies TAG TAG JS

The Browser “Same Origin” Policy

bank.com

blog.net

XHR

XHR

document, cookies

TAG

TAG

JS

Слайд 4

Cross-Site Request Forgery bank.com attacker’s post at blog.net Go to

Cross-Site Request Forgery

bank.com

attacker’s post at blog.net

Go to Transfer Assets
https://bank.com/fn?param=1

Select FROM

Fund
https://bank.com/fn?param=1

Select TO Fund
https://bank.com/fn?param=1

Select Dollar Amount
https://bank.com/fn?param=1

Submit Transaction
https://bank.com/fn?param=1

Confirm Transaction
https://bank.com/fn?param=1

Слайд 5

How Does CSRF Work? Tags Autoposting Forms XmlHttpRequest Subject to same origin policy

How Does CSRF Work?

Tags


border="0">
Имя файла: CSRF.-Danger.-Detection.-Defenses.pptx
Количество просмотров: 66
Количество скачиваний: 0