CSRF Double Submit Cookie is basically “not Secure”

前端 未结 0 1225
臣服心动
臣服心动 2021-01-23 07:10

From OWASP page : A CSRF attack works because browser requests automatically include all cookies including session cookies.

To prevent it, we can use double-submit cookie

相关标签:
回答
  • 消灭零回复
提交回复
热议问题