Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

OWASP CSRFGuard: Understanding and Preventing Cross-Site Request Forgery

OWASP Foundation via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course examines cross-site request forgery attacks and prevention through OWASP CSRFGuard. It covers browser security policies, real-world payloads, CSRFGuard's flow and JSP tag support, and automated detection with Nuclei templates.

Syllabus

Intro
What is Cross-Site Request Forgery
The classic example
More recent CSRF Attack
Relaxing the SOP (1)
Anything else? Yes, ofCORS!
When it's safe to fly?
CORS Server side headers
Real world CSRF attack payloads
Searching for CSRF exploits
Searching for recent CSRF exploits
How to prevent it?
SameSite - the game changer
So when would you need CSRF Guaru..
CSRF Guard flow (2)
What's new in CSRF Guard 4.x
CSRF Guard JSP Tag support
Conclusions and recommendations
Automation with nuclei templates
Nuclei detect CSRFGuard defaults
References

Taught by

OWASP Foundation

Reviews

Start your review of OWASP CSRFGuard: Understanding and Preventing Cross-Site Request Forgery

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.