CSRF: not all defenses are created equal - Ari Elias-Bachrach
3,112 views · Published 3 February 2014 · 44:33 · Indexed 6 October 2026
Channel: OWASP Foundation · 2014 · Science & Technology
CSRF is an often misunderstood vulnerability. In this talk I will introduce CSRF and the basic defenses against it. Then I will go through all of the various major solutions and describe how they implement the general solution and the positives and negatives of each implementation. The general solution is to implement the synchronizer token pattern. This is usually done in the framework and not by the individual developer. For example .net applications can use the antiforgerytoken (for MVC applications) or viewstateuserkey. Tomcat web server and F5 load balancers also now include CSRF prevention filters. OWASP of course has the CSRF guard. All of these solutions though are slightly different and can lead to different side effects, some of which are little understood and poorly documented. Some side effects can impact usability, or cause worse security problems while trying to defend against CSRF. - Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
More from this channel
-
45:50
Revenge of the Geeks: Hacking Fantasy Sports Sites - Dan Kuykendall
-
51:38
Application Security at DevOps Speed and portfolio scale - Jeff Williams
-
35:56
HTML5 JS Security - maty siman
-
34:16
libinjection: from sqli to xss - Nick Galbreath
-
46:05
Next Generation Red Teaming - Robert Wood
-
44:28
Privacy vs Security Intricacies - Robert Hansen (keynote)
-
17:39
detecting and defending against state actor surveillance: robert r
-
50:12
OWASP Global Webinar - OWASP HIVE Project - Welcome to the Grid