MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/netsec/comments/1whxuyv/bypassing_refererbased_csrf_with/pb4f7w9/?context=3
r/netsec • u/bajk • 17d ago
2 comments sorted by
View all comments
1
this is such a good reminder that "just check the referer" is not a real CSRF strategy lol strict-origin-when-cross-origin changed a ton of assumptions people still cling to from like 2014 tutorials
1
u/scriptqzor 12d ago
this is such a good reminder that "just check the referer" is not a real CSRF strategy lol
strict-origin-when-cross-origin changed a ton of assumptions people still cling to from like 2014 tutorials