F5 is upgrading its customer support chat feature on My.F5.com. Chat support will be unavailable from 6am-10am PST on 1/20/26. Refer to K000159584 for details.

Forum Discussion

2funky_105078's avatar
Sep 08, 2016

ASM uses TS cookies as well against CSRF

I understoof ASM injecting a token in fields on static HTML POST forms or cliende side scripts to protect against CSRF.

 

But i read somewhere that it uses as well the main TS cookie, how does it work exactly? An attacker can just replay the TS cookie...

 

2 Replies