CSRF Attack & Defense

BSidesROC 2016

Presented by: John N. King
Date: Saturday April 23, 2016
Time: 16:00 - 16:25
Location: Track 3

Cross-site request forgery vulnerabilities are often poorly understood and considered a low priority, making them strong candidates for exploitation. This session will feature an attack demonstration against a web application that utilizes a Java stack, followed by a defense demo using OWASP CSRFGuard.

John N. King

John is an application developer with 10+ years of experience, with a focus on product development and application security. He works for RIT, serves as an officer of the Rochester chapters of OWASP and ISSA, and assists with the annual Rochester Security Summit.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats