类别

Xoops (5)
Blog (7)
General (3)

Blogs (网站)

昨天 15:12
昨天 15:00
3/22 15:49
3/7 3:00
2007/11/25 13:57
2007/10/16 13:50
2007/10/16 10:10
2007/10/14 11:52
2006/12/10 17:09
2006/10/25 22:39
天下博览 - There is no CSRF imag1

There is no CSRF


出处 | XOOPS development log
日期: 2006/6/1 9:29
点击: 63



I've seen several articles about CSRF and token/tickets systems lately, saying that such systems were secure, while I always was against token systems. The reason is simple: such systems complicate your code and bring absolutely no additional protection. Good developers out there spending their time on tickets system would rather work on something else than waste their precious time like that <img src=" style="display: inline; vertical-align: bottom;" class="emoticon" />.

The point is that there is no CSRF. This is a name given to another extremely dangerous type of attack: XSS. What some brainless people called CSRF is just a particular way to exploit XSS and nothing more. However they didn't discover anything, they just put another name on something else (the same applies to AJAX in fact: the emergence of these terms are just the symptoms of a society that has become so stupid and uncreative that it tries to disguize recycling into progress).




Continue reading "There is no CSRF"

URL: http://xoops.org.cn/modules/planet/view.article.php/940
Trackback: http://xoops.org.cn/modules/planet/trackback.php/940

网友个人意见,不代表本站立场。对于发言内容,由发表者自负责任。
发表者 树状展开