Re: [RFC DRAFT] Automatic CSRF Protection

From: Date: Wed, 11 May 2016 04:37:19 +0000
Subject: Re: [RFC DRAFT] Automatic CSRF Protection
References: 1 2 3 4 5 6 7 8 9 10 11  Groups: php.internals 
Request: Send a blank email to internals+get-93191@lists.php.net to get a copy of this message
Hi Kinn, On Wed, May 11, 2016 at 11:56 AM, Kinn Julião <kinncj@gmail.com> wrote: > The point with your example is: > The cross site can request the "get_csrf_token.php", store on its session > (even curl can save the session id cookie or whatever), get the token and > request the endpoint with the retrieved token and session id. > > Got it? Wrong assumption. How would you set attacker's session ID to victim? BTW, session hijack/adoption is not scope of this RFC, but precise session management RFC. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#93191) next »