Network Security Consulting Agency Since 1989 - Specialized in Unix, Windows, TCP/IP and Internet
You are here
:
Home
>
Resources
>
Lectures
> Evolution of Cross-Site Request Forgery Attacks
Go to:
HSC Trainings
Search
:
Services
Skills & Expertise
Consulting
ISO 27001 services
Vulnerabilities monitoring
Audit & Assessment
Penetration tests
Vunerability assessment (TSAR)
Forensics
ARJEL
Training courses
E-learning
Conferences
Agenda
Past events
Tutorials
Resources
Thematic index
Tips
Lectures
Courses
Articles
Tools (download)
Vulnerability watch
Company
Hervé Schauer
Team
Job opportunities
Credentials
History
Partnerships
Associations
Press and
communication
HSC Newsletter
Press review
Press releases
Publications
Contacts
How to reach us
Specific inquiries
Directions to our office
Hotels near our office
Evolution of Cross-Site Request Forgery Attacks
Access to the content
Beginning of the presentation
PDF version
[2048 KB]
Adobe Flash version
Description
Context & Dates
Talk presented during the SSTIC 2007, on 1 June 2007.
Author
Louis Nyffenegger, Renaud Feil
Type
[
-
]
Abstract &
Table of content
Flyleaf
Sommaire
Présentation des attaques de type Cross-Site Request Forgery
Le navigateur comme client léger universel
Une vulnérabilité enfin reconnue
Cinématique d'une attaque CSRF (1/4)
Cinématique d'une attaque CSRF (2/4)
Cinématique d'une attaque CSRF (3/4)
Cinématique d'une attaque CSRF (4/4)
Possibilités des attaques de type CSRF
Le "Session Riding"
Exemples d'applications Web vulnérables
Webmin
Webmin (l'attaque)
Site www.sstic.org
Site www.sstic.org : modification de l'entrée Email
Site www.sstic.org : récupération des informations de connexions
OWA, Horde, Blogspot, SMC...
Limites des attaques de type CSRF « traditionnelles » et évolution de la menace
Limites des CSRF "traditionnels"
Assurer la persistance du code hostile
Rendre l'attaque interactive
Consulter la réponse
CSRF avec XMLHttpRequest() (1/4)
CSRF avec XMLHttpRequest() (2/4)
CSRF avec XMLHttpRequest() (3/4)
CSRF avec XMLHttpRequest() (4/4)
Les protections contre les attaques de type CSRF
Protections
Conclusion
Questions
Related documents
Web
Web Servers and applications Security
Webef tool
[Bruteforcer of web server files and directories -
]
Webshells, or how to open your network's doors ?
[21 October 2010 -
]
JBoss AS: exploitation and reassure
[11 June 2010 -
]
Webshells, or how to open your network's doors ?
[16 March 2010 -
]
Webshells, real threat for information systems ?
[1 December 2009 -
]
Security issue seen in enterprises web applications
[27 November 2008 -
]
Application security
[23 October 2008 -
]
Feedback from PHP applications assessment
[21 November 2007 -
]
Encrypting hostile Web content over HTTP
[31 May 2007 -
]
Web 2.0 : more ergonomic... and less secure ?
[22 May 2007 -
]
Configuring and using modsecurity2
[24 April 2007 -
]
Presentation of Apache ModSecurity module
[14 June 2006 -
]
Database and ERP security
[15 June 2005 -
]
SSL VPN connection multiplexing techniques
[7 April 2005 -
]
PHP and security
[27 November 2003 -
]
Web Services and Security
[10 September 2003 -
]
HTTP/HTTPS authentication methods
[10 March 2003 -
]
The cross-site scripting
[27 February 2003 -
]
DBMS and security
[1 April 2002 -
]
Apache and web servers security
[1 February 2002 -
]
Implementing filtering on a reverse HTTP proxy using mod_eaccess
[3 September 2001 -
]
Subweb tool
[HTTP reverse proxy -
]
Babelweb tool
[Automatic information retrieving from of a web server -
]
Universal CGI wrapper
[5 August 2001 -
]
Why HTTPS is not web security
[7 May 2001 -
]
Filtering URLs in a reverse proxy
[5 May 2001 -
]
Hacking web servers
[14 March 2001 -
]
Why a reverse proxy
[13 February 2001 -
]
Apache as a reverse proxy
[11 November 2000 -
]
Secure internet services (email, DNS, web) under Linux
[26 September 2000 -
]
Secure internet services (email, DNS, web) under Linux
[26 April 2000 -
]
Secure Internet services (email, DNS, web) under Linux
[1 February 2000 -
]
Netscape
[16 January 1996 -
]
Secure Programming
Secure Programming
Application security
[23 October 2008 -
]
Feedback from PHP applications assessment
[21 November 2007 -
]
Web 2.0 : more ergonomic... and less secure ?
[22 May 2007 -
]
Security in software developments
[11 May 2007 -
]
PHP and security
[27 November 2003 -
]
How to design secure network applications based on privilege separation
[11 July 2002 -
]
Secure programming and software traps
[18 March 2002 -
]
E-Business
Web 2.0 : more ergonomic... and less secure ?
[22 May 2007 -
]
Web Services and Security
[10 September 2003 -
]
Risks and solutions of an e-business project
[28 September 2001 -
]
Controling the risks associated with e-business
[21 June 2000 -
]
Electronic Commerce on the Internet
[9 May 1996 -
]
Télémarket sur Multicâble
[26 February 1996 -
]
Globe-On-Line
[12 July 1995 -
]
EverGreen
[16 May 1995 -
]
Le réseau ARTUUS
[15 May 1995 -
]
Internet
Internet/intranet Security
Forcasting in French cyberdefence doctrines
[24 November 2010 -
]
Webshells, or how to open your network's doors ?
[21 October 2010 -
]
Webshells, or how to open your network's doors ?
[16 March 2010 -
]
Webshells, real threat for information systems ?
[1 December 2009 -
]
Deperimetrization or not ?
[22 November 2007 -
]
DOS on Internet infrastructure
[4 November 2003 -
]
HTTP/HTTPS authentication methods
[10 March 2003 -
]
Internet Familial by SmartValley
[29 June 2000 -
]
SIAM et l'Internet
[25 April 1996 -
]
KBT
[5 February 1996 -
]
La stratégie de France Télécom
[10 January 1996 -
]
Telekom On Line
[4 January 1996 -
]
Droit et l'Internet
[4 December 1995 -
]
Les décisions françaises concernant les projets sur les Autoroutes de l'Information
[23 October 1995 -
]
How to build a secure Internet access architecture?
[October 1995 -
]
Wanadoo
[6 July 1995 -
]
L'Homme Symbiotique
[18 April 1995 -
]
Intranet
Internet/intranet Security
About Intranets' Lack of Security
[August 1999 -
]
Intranet by Microsoft
[14 October 1996 -
]
Copyright
© 2007, Hervé Schauer Consultants, all rights reserved.
Last modified on 6 June 2007 at 15:09:41 CET - webmaster@hsc.fr
Information on this server
- © 1989-2010 Hervé Schauer Consultants