YoVDO

OWASP CSRFGuard: Understanding and Preventing Cross-Site Request Forgery

Offered By: OWASP Foundation via YouTube

Tags

Web Security Courses CORS Courses Same-Origin Policy Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the intricacies of Cross-Site Request Forgery (CSRF) and learn how to effectively prevent it using OWASP CSRFGuard in this comprehensive conference talk. Delve into classic examples and recent CSRF attacks, understand the implications of relaxing the Same-Origin Policy, and examine the role of CORS in web security. Discover techniques for identifying CSRF vulnerabilities, including real-world attack payloads and methods for searching for exploits. Gain insights into prevention strategies, with a focus on the game-changing SameSite attribute and its impact on CSRF protection. Examine the CSRF Guard flow and explore new features in version 4.x, including JSP Tag support. Conclude with practical recommendations and learn how to automate CSRF detection using nuclei templates. Equip yourself with the knowledge to safeguard web applications against CSRF attacks and implement robust security measures.

Syllabus

Intro
What is Cross-Site Request Forgery
The classic example
More recent CSRF Attack
Relaxing the SOP (1)
Anything else? Yes, ofCORS!
When it's safe to fly?
CORS Server side headers
Real world CSRF attack payloads
Searching for CSRF exploits
Searching for recent CSRF exploits
How to prevent it?
SameSite - the game changer
So when would you need CSRF Guaru..
CSRF Guard flow (2)
What's new in CSRF Guard 4.x
CSRF Guard JSP Tag support
Conclusions and recommendations
Automation with nuclei templates
Nuclei detect CSRFGuard defaults
References


Taught by

OWASP Foundation

Related Courses

Amazon API Gateway - Troubleshooting (Japanese)
Amazon Web Services via AWS Skill Builder
Advanced AJAX Techniques and Final Projects
Packt via Coursera
Build Web APIs using ASP.NET
Microsoft via edX
Angular Basics
egghead.io
Build a Corgi Up-boop Web App with Netlify Serverless Functions and Hasura
egghead.io