4 ms·
I think that in 2011, checking referer headers can be considered an acceptable form of CSRF prevention. Some very old browsers and plugins allow referer header
by dfranke 16y ago
I think that in 2011, checking referer headers can be considered an acceptable form of CSRF prevention. Some very old browsers and plugins allow referer headers to be spoofed, but by now so many other vulnerabilities have been found in all those that if you're still using them then CSRF is the least of your problems.