3 ms·
Oh wow, I wrote this post a while ago! :-) It was a neat little idea to play around with when I first wrote the post, since setting X-Requested-With on an arbi
by nbpoole 14y ago
Oh wow, I wrote this post a while ago! :-)
It was a neat little idea to play around with when I first wrote the post, since setting X-Requested-With on an arbitrary domain requires a violation of the same-origin policy. But as I point out at the top of the post, there was at least one recent case of a same-origin violation (via the Flash 307 bug) that allowed for arbitrary headers to be written.
CSRF tokens, whether they're in headers or in a form, are the more secure way to prevent an attack. They require a violation of the same-origin policy where an attacker can read (at least part of) the HTTP response sent by your server. If an attacker can do that, you already have larger issues.