20 likes | 173 Views
Luyi Xing, GUCAS, China. Server:. Observation: Almost every POST target URL needs only a small number of different intended source URLs. And GET is similar. Client:. POST : { Dest1: /profile.php Same domain1: /update.php Cross domain1: trust.com/change.asp Dest2: /blog.php
E N D
Luyi Xing, GUCAS, China Server: Observation: Almost every POST target URL needs only a small number of different intended source URLs. And GET is similar. Client: POST:{ Dest1: /profile.php Same domain1: /update.php Cross domain1: trust.com/change.asp Dest2: /blog.php Same domain2: subdomain1.sns.com/* Cross domain2: none} A Client-Based and Server-Enhanced Defense Mechanism for Cross-Site Request Forgery Definition: The Super-Referer of a request is made up of its Referer and all URLs of the Referer’s ancestor frames, excluding the querying part. GET:{ Dest1: /transfer.php Same domain1: /account.php Cross domain1: trust.com/out_transfer.asp Dest2: /logout.php Same domain2: subdomain1.bank.com/* Cross domain2: none}