The vulnerability known as A5 – Cross-Site Request Forgery (CSRF) has many names including session riding and one-click attack. It’s a blind attack in the sense that the attacker is not directly attacking the application, but rather tricks a user into doing the attack for him. In this article we’ll look at what’s going on, how to fix it and also look at an attack specific to single page web applications.
-
Tema
.net app brukeropplevelse c# clojure DevOps driftbarhet feilhåndtering Forretningsmodell forretningsutvikling friprog funksjonalitet og brukeropplevelse git innovasjon Innovasjonsledelse interaksjonsdesign it-strategi java javascript jvm kanban konferanse kontinuerlige leveranser kvalitet maven metode mobil open source owasp psykologi og design scala security Sikkerhet smidig sosiale medier sosiale nettverk sosial programvare spring strategi tdd testing twitter Virksomhet 2.0 webrammeverk xss