Hi All

We have an application that lives behind a login and all requests are session 
based component requests.  We have been asked by a user about our vulnerability 
to Cross-site request forgery.

http://en.wikipedia.org/wiki/Cross-site_request_forgery
and 
https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29

What do you guys do to protect against this? Are component urls and an 
authenticated session enough to prevent this?

Advice much appreciated.


Regards


Giles
 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Webobjects-dev mailing list      ([email protected])
Help/Unsubscribe/Update your Subscription:
https://lists.apple.com/mailman/options/webobjects-dev/archive%40mail-archive.com

This email sent to [email protected]

Reply via email to