in reply to Is your web application really secure? ("CSRF")
One thing that might help a bit is to set up your webserver to prohibit POSTs that don't have a referer header from your trusted site(s). I'm pretty sure there's a way to do that in apache.
As far as I know you a malicious site can't fake a referer header* (unless maybe if you allow cross-site XMLHTTP - but all modern browsers prohibit that - right?)
Good suggestion on the tokens, by the way.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Is your web application really secure? ("CSRF")
by betterworld (Curate) on Mar 27, 2007 at 19:31 UTC | |
|
Re^2: Is your web application really secure? ("CSRF")
by MidLifeXis (Monsignor) on Mar 29, 2007 at 17:26 UTC | |
by Joost (Canon) on Mar 29, 2007 at 19:25 UTC |