Forum Discussion
[BIG-IP 4000s] Failed to protect Crosse-Site Request Forgery
Thank you for your comment Mr. Boneyard,
After reading your comments, our team got a different opinion about the fact of no protecting a request that doesn't carry data and would like to share it with you (his tone may be a bit strong but please think of him as your close friend OK! Mr. Boneyard ^_^)
"The request without parameter doesn't carry data ? Hey man, you're very wrong about this. How's about data coming from HTTP headers ? like cookie, HTTP referer ? does that make sense ?
Let's talk about an application that have one link to delete the account: /delete.php, user can access this link to delete their account. Application recognized user based on their session_id (send along with their cookie). So, user just access this link (without any parameters) to delete their account. Hey, tell me, guy, does it "carry data" ? And how to protect CSRF on this link ?"
Thank you
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com