Re: [RFC DRAFT] Automatic CSRF Protection
| From: | Andrey Andreev | Date: | Wed, 11 May 2016 18:39:18 +0000 |
| Subject: | Re: [RFC DRAFT] Automatic CSRF Protection | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-93247@lists.php.net to get a copy of this message | ||
On Wed, May 11, 2016 at 7:16 PM, Niklas Keller <me@kelunik.com> wrote:
>
> 2016-05-11 17:41 GMT+02:00 Andrey Andreev <narf@devilix.net>:
>
>>
>> Your login form too needs CSRF protection. It's a chicken and egg problem.
>>
>
> Not really. As long as you don't have the credentials.
> You can't make any requests as the authenticated user, as there is no
> authenticated user.
>
>
Riding an authenticated user's session is the obvious, and indeed most
serious CSRF attack, but not the only one ...
An attacker-chosen account could be leveraged for phishing, and depending
on the functionality of the website - possibly also XSS, malicious software
distribution, who knows what else.
Cheers,
Andrey.