A function design defect of the moment network leads to cross-site Request Forgery (CSRF) (can lead to full-site worm propagation with POC)

Source: Internet
Author: User

A function design defect of the moment network leads to cross-site Request Forgery (CSRF) (can lead to full-site worm propagation with POC)

Cross-Site Request Forgery (CSRF) due to functional design defects such as transient network fragmentation (can lead to whole-site worm propagation with POC)

It is estimated that CSRF attacks are not supported in many parts of the entire site. This section describes the vulnerabilities with the fragment function.

See poc.


<Html> 

Method of exploits: First open pianke. me and then open this poc page, you can successfully send fragments with the content of "test.

As for [worms]

You can use the insite email interface to send insite emails by traversing the user ID.

URL: http://pianke.me/api/message/send ::postmessage subject: withuid?user id&content=pocaddress
Solution:

1. The verification code is considered to be the most concise and effective defense method against CSRF attacks.

2. Referer Check.

3. Anti CSRF Token.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.