Talk:Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet

Revision as of 16:42, 24 August 2012 by Michael Brooks (Talk | contribs)

Jump to: navigation, search

Don't post theoretical attacks, or "here say" on any OWASP page.

Look people. A referer check is a valid form of protection and is currently being used to stop the most dangerous CSRF vulnerability ever discovered (according to the DHS: If you think it be exploited, PROVE IT. Stop spreading clearly false information on OWASP.

Write an exploit and show me that it works. Then you can change the owasp wiki.