Trending Application Security Discussions

Follow

Ask the Community


Ask any professional question and get answers from other specialists.

Stream language
Default profile image
Question added by Deleted user
10 years ago

How do you protect your application from Cross-Site Request Forgery (CSRF)?‎

What products and scanners have you used successfully for detection and remediation of CSRF?‎

Answers:
10
Followers:
Views:
1031
Vote Count:
5
Answer should contain a minimum of 25 characters.
Muhammad Wasif Riaz's image
Question added by Muhammad Wasif Riaz Senior Manager IS Audits Pakistan Telecommunication Limited
11 years ago
Answers:
2
Followers:
Views:
234
Vote Count:
1
Answer should contain a minimum of 25 characters.
Anil Yadav's image
Question added by Anil Yadav Manager - Group Internal Audit Kotak Mahindra Bank
11 years ago
Answers:
2
Followers:
Views:
142
Vote Count:
0
Answer should contain a minimum of 25 characters.
Anil Yadav's image
Question added by Anil Yadav Manager - Group Internal Audit Kotak Mahindra Bank
11 years ago
Answers:
1
Followers:
Views:
377
Vote Count:
0
Answer should contain a minimum of 25 characters.
Default profile image  
Answer added by  Deleted user
10 years ago

1- Request confirmations to the user for critical actions, the risk of burdening the sequence of forms. 2- Request confirmation of the old password for the user to change ... See More

Prashant Soni's image  
Answer added by  Prashant Soni, Module Lead, Persistent Systems Ltd.
10 years ago

Anti-forgery tokens work because the malicious page cannot read the user’s tokens, due to same-origin policies. To prevent CSRF attacks, use anti-forgery tokens with any ... See More

Rameez Ahmed Sayad's image  
Answer added by  Rameez Ahmed Sayad, .Net Consultant, Proximus Luxembourg
10 years ago

The simplest method is to use AntiForgery token , the antiforgery token should comprise of a Salt (which needs to be changed regularly) , some User specific data(username ... See More

Anil Yadav's image  
Answer added by  Anil Yadav, Manager - Group Internal Audit, Kotak Mahindra Bank
3 years ago

Yes it is secure as it is asking you to re enter your credentials

Mohamed sayed's image  
Answer added by  Mohamed sayed, Senior Information Security consultant, SecureMisr
7 years ago

1-Using unpredictable random Anti-forgery tokens 2-Using samesite flag in cookies 3-avoid using HTTP GET requests in sensitive actions