PEAK XOOPS - Re: under the topic of against CSRF ... (2) in englishin japanese

Re: under the topic of against CSRF ... (2)

Target News
Subject under the topic of against CSRF ... (2)
Summary XOOPS has a simple system preventing from CSRF in DB layer. POST && Good Referer --> allow all SQL !POST || Bad Referer --> allow only SQL starting with "SELECT"This is troublesome.If someone post a news with referer off, he will get message "Your post...

List posts in the topic

normal Re: under the topic of against CSRF ... (2)

msg# 1
depth:
0
Previous post - Next post | Parent - Children.1 | Posted on 2006/6/1 8:38
skalpa  Private   Posts: 4
The fact operations that modify the state of the Web should only be allowed during a POST request is part of the Web axioms, as describe in Tim Berners-Lee's notes.
So, although I'm almost sure this has not been implemented for this reason on purpose, it forces non-knowledged developers to respect this rule, and I think it is positive in fact.
Also, on a sidenote: I think something additional has to be found... Tokens are not more secure and can be tricked and bypassed (don't forget CSRF starts with the assumption that Javascript code can be inserted ).
Votes:1 Average:10.00

Posts tree

  Advanced search


Login
Username or e-mail:

Password:

Remember Me

Lost Password?

Register now!