Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Keynote: Request Forgery on the Web - SSRF, CSRF and Clickjacking

OWASP Foundation via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This technical talk explains cross-site request forgery, server-side request forgery, and clickjacking in web applications. It examines attack examples and defensive techniques, including nonce tokens, SameSite cookies, origin checks, and X-Frame-Options.

Syllabus

Introduction
What is request forgery
Examples
Crosssite request forgery
Netflix request forgery
Single signon
Traditional Web Apps
Get Requests
Double Submit
Browser Standards
Same site lacks
Cookie defense
Check origin header
Control origin header
Crosssite scripting
Twitter attack
Crosssite request forgery cheat sheet
Serverside request forgery
Capital One case
From another angle
SSRF attack
How to fix
URL Encoding
SSRF
Summary
Questions
Web Frameworks
Service on request forgery
Clickjacking
XFrameOptions

Taught by

OWASP Foundation

Reviews

Start your review of Keynote: Request Forgery on the Web - SSRF, CSRF and Clickjacking

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.