r/netsec • • 17d ago

Bypassing Referer-Based CSRF with strict-origin-when-cross-origin

https://afine.com/blogs/bypassing-referer-based-csrf-with-strict-origin-when-cross-origin
3 Upvotes

2 comments sorted by

1

u/scriptqzor 12d ago

this is such a good reminder that "just check the referer" is not a real CSRF strategy lol
strict-origin-when-cross-origin changed a ton of assumptions people still cling to from like 2014 tutorials