For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

2funky_105078's avatar
Sep 08, 2016

ASM uses TS cookies as well against CSRF

I understoof ASM injecting a token in fields on static HTML POST forms or cliende side scripts to protect against CSRF.

 

But i read somewhere that it uses as well the main TS cookie, how does it work exactly? An attacker can just replay the TS cookie...

 

2 Replies