Re: [RFC DRAFT] Automatic CSRF Protection
| From: | Yasuo Ohgaki | Date: | Wed, 11 May 2016 04:37:19 +0000 |
| Subject: | Re: [RFC DRAFT] Automatic CSRF Protection | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-93191@lists.php.net to get a copy of this message | ||
Hi Kinn,
On Wed, May 11, 2016 at 11:56 AM, Kinn Julião <kinncj@gmail.com> wrote:
> The point with your example is:
> The cross site can request the "get_csrf_token.php", store on its session
> (even curl can save the session id cookie or whatever), get the token and
> request the endpoint with the retrieved token and session id.
>
> Got it?
Wrong assumption.
How would you set attacker's session ID to victim?
BTW, session hijack/adoption is not scope of this RFC, but precise
session management RFC.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net