CSRF Attacks and Web Forms

Posted by: youve been HAACKED, on 02 Apr 2009 | View original | Bookmarked: 0 time(s)

In my last blog post, I walked step by step through a Cross-site request forgery (CSRF) attack against an ASP.NET MVC web application. This attack is the result of how browsers handle cookies and cross domain form posts and is not specific to any one web platform. Many web platforms thus include their own mitigations to the problem. It might seem that if youre using Web Forms, youre automatically safe from this attack. While Web Forms has many mitigations turned on by default, it turns out that...

Advertisement
Free Agile Project Management Tool from Telerik
TeamPulse Community Edition helps your team effectively capture requirements, manage project plans, assign and track work, and most importantly, be continually connected with each other.
Category: JavaScript | Other Posts: View all posts by this blogger | Report as irrelevant | View bloggers stats | Views: 998 | Hits: 26

Similar Posts

  • ASP.NET 4 Web Server Here Shell Extension more
  • Announcing Microsoft Ajax Library (Preview 6) and the Microsoft Ajax Minifier more
  • Announcing the WebsiteSpark Program more
  • Accessing Images On Flickr From An ASP.NET Website Using The Flickr.Net Library more
  • Announcing the Microsoft AJAX CDN more
  • Intersoft Solutions Announces WebUI Studio 2009 Service Pack 1 more
  • ASP.NET MVC: DevExpress Mail Demo more
  • Put Your Views (and Pages) On a Diet more
  • WebResource access in ASP.NET MVC more
  • Using the latest Web Testing Tools along with the latest RadControls more

News Categories

.NET | Agile | Ajax | Architecture | ASP.NET | BizTalk | C# | Certification | Data | DataGrid | DataSet | Debugger | DotNetNuke | Events | GridView | IIS | Indigo | JavaScript | Mobile | Mono | Patterns and Practices | Performance | Podcast | Refactor | Regex | Security | Sharepoint | Silverlight | Smart Client Applications | Software | SQL | VB.NET | Visual Studio | W3 | WCF | WinFx | WPF | WSE | XAML | XLinq | XML | XSD