4 ms·
checking referer will work 99% and without cluttering your urls.
by stopcyring 13y ago
checking referer will work 99% and without cluttering your urls.
- jere 13y ago>However, checking the referer is considered to be a weaker from of CSRF protection. For example, open redirect vulnerabilities can be used to exploit GET-based requests that are protected with a referer check. https://owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet#Checking_The_Referer_Header https://owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF...
- diffsir 13y agoNot to mention one can leverage flash to spoof headers or the odd IE bug that splits headers using \t
- stesch 13y agoPlease stop relying on the Referer header. It can be forged and is often enough removed completely for privacy reasons.
- trxblazr 13y agoabsolutely not. Just forge the referrer header.
- skyraider 13y agoThat's incorrect in this context, which is trying to get a victim to use their own browser to submit a request that uses cookies on said browser for authentication (CSRF). Please take a look at the following link: "Although it is trivial to spoof the referer header on your own browser, it is impossible to do so in a CSRF attack." (https://owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet#Checking_The_Referer_Header https://owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF...)
- stopcyring 13y agoridiculous, say forging again, i double dare you. how you ninjas going to do that? flash 10 was released 2008. thanks for down voting, single mind hn as usual.
- homakov 13y agoi don't downvote, but referer never been a good protection. never
- skyraider 13y agoThanks for pointing this out. A lot of people here don't seem to realize that exploiting a CSRF vulnerability involves tricking the victim's browser into doing something. You cannot both a) forge the Referer header and b) trick the victim's browser into submitting a request - at the same time. It's true that the REFERER header isn't always included in requests, BUT when it is included, you can consider the request cookies you receive plus the REFERER header accurate when taken together, barring a browser vulnerability. If there is no browser vulnerability, the attacker doesn't get to mess with the REFERER header on the victim's browser. Note: It is NOT safe to trust an empty REFERER header.
- ljd 13y agoYou can forge the referrer by putting it in the header of an HTTP request. It's a rather simple procedure.
- deleted 13y ago[deleted]
- pdeuchler 13y agoWho said this attack was coming from a browser? Never. Trust. User. Input.
- skyraider 13y agoIf a CSRF attack is not coming from a browser, how are you going to get the victim's session cookies? If you do get them, it's not called CSRF anymore.
- homakov 13y agoNoooooooo