Главная
Study mode:
on
1
Introduction
2
What is request forgery
3
Examples
4
Crosssite request forgery
5
Netflix request forgery
6
Single signon
7
Traditional Web Apps
8
Get Requests
9
Double Submit
10
Browser Standards
11
Same site lacks
12
Cookie defense
13
Check origin header
14
Control origin header
15
Crosssite scripting
16
Twitter attack
17
Crosssite request forgery cheat sheet
18
Serverside request forgery
19
Capital One case
20
From another angle
21
SSRF attack
22
How to fix
23
URL Encoding
24
SSRF
25
Summary
26
Questions
27
Web Frameworks
28
Service on request forgery
29
Clickjacking
30
XFrameOptions
Description:
Explore the intricacies of request forgery on the web in this comprehensive 47-minute keynote presentation by Jim Manico, Founder and CEO of Manicode Security. Delve into various forms of request forgery, including Cross-Site Request Forgery (CSRF), Server-Side Request Forgery (SSRF), and Clickjacking. Learn about real-world attack scenarios, such as the Netflix request forgery and the Capital One case, and discover effective defensive strategies like nonce tokens, SameSite cookies, and the double-cookie submit pattern. Gain valuable insights into protecting web applications from these security threats, including best practices for URL encoding, origin header checks, and X-Frame-Options implementation. Enhance your understanding of web security and equip yourself with the knowledge to build more secure applications in this OWASP Foundation-managed talk.

Keynote: Request Forgery on the Web - SSRF, CSRF and Clickjacking

OWASP Foundation
Add to list
0:00 / 0:00