Web Hack List

Later archive addition

Robust Defenses for Cross-Site Request Forgery (Login CSRF & the Origin header)

CCS 2008 paper introducing login CSRF, where a forged request to the login form signs the victim in as the attacker so their activity accrues to the attacker's account. It dissects secret-token, Referer and custom-header defences, and measures Referer suppression over 283,945 ad impressions: heavy on HTTP, negligible on HTTPS. Proposes the Origin header, with browser and Apache patches.

Record

Researcher
Adam Barth, Collin Jackson and John C. Mitchell
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Barth, Collin Jackson and John C. Mitchell, first published at the original source. Preserved copies are kept so the citation survives its host.