|
Are cross-site request forgery (CSRF) really as dangerous as vendor hype suggests? |
|
|
|
Source: SearchSoftwareEquality - Posted by Alex
|
Even with some of the best commercial Web vulnerability scanners, it's very rare that I find cross-site request forgery (CSFR). That doesn't mean it's not there. Given the complexity of CSRF, it's actually pretty difficult to find.
The good news is it's even more difficult to exploit CSFR which essentially takes advantage of the trust a Web application has for a user. So, based on what I'm seeing in my work I don't think CSFR is as big of a deal - or perhaps I should say as top of a priority. As some of the vendors and Top 10 lists characterize it. This doesn't mean you shouldn't use a high-quality vulnerability scanner to look for it. I'm just saying that you likely have many simpler and more obvious problems to fix first.[All of article]
Read this full article at SearchSoftwareEquality
Only registered users can write comments. Please login or register. Powered by AkoComment! |