Forum Discussion
APM SessionCookie MRHSession and CSRF
Does the APM MRHSession Cookie have any protections against a CSRF based attack?
If we have a Spring application behind APM, do I need to worry about CSRF at the application level? http://docs.spring.io/spring-security/site/docs/current/reference/html/csrf.html
I do not have an ASM license.
2 Replies
Hi Walther,
the MRHSession session cookie is used for APM per-request authorization.
So the cookie "as is" can't be used to protect against CSRF attacks, if the user remains logged on. You'll would need additional iRule codings to use this cookie to protect against CSRF attacks (e.g. STREAM inject the MRHSession cookie value as a hidden
to your pages). But doing so would introduce additional risks to the MRHSession cookie, so better use an independent and randon cookie value for CSRF mitigation).Cheers, Kai
- Walter_Kacynski
Cirrostratus
I thought I saw a reference to a "rolling" cookie value from the APM docs. Maybe this is only used during policy evaluation?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com