Re: [RFC DRAFT] Automatic CSRF Protection

From: Date: Wed, 11 May 2016 18:39:18 +0000
Subject: Re: [RFC DRAFT] Automatic CSRF Protection
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18  Groups: php.internals 
Request: Send a blank email to internals+get-93247@lists.php.net to get a copy of this message
On Wed, May 11, 2016 at 7:16 PM, Niklas Keller <me@kelunik.com> wrote: > > 2016-05-11 17:41 GMT+02:00 Andrey Andreev <narf@devilix.net>: > >> >> Your login form too needs CSRF protection. It's a chicken and egg problem. >> > > Not really. As long as you don't have the credentials. > You can't make any requests as the authenticated user, as there is no > authenticated user. > > Riding an authenticated user's session is the obvious, and indeed most serious CSRF attack, but not the only one ... An attacker-chosen account could be leveraged for phishing, and depending on the functionality of the website - possibly also XSS, malicious software distribution, who knows what else. Cheers, Andrey.

« previous php.internals (#93247) next »