메뉴 건너뛰기




Volumn , Issue , 2008, Pages 75-87

Robust defenses for cross-site request forgery

Author keywords

Cross site request forgery; HTTP referer header; Same origin policy; Web application firewall

Indexed keywords

CROSS SITE SCRIPTING; CROSS-SITE REQUEST FORGERY; DEFENSE TECHNIQUES; EXPERIMENTAL OBSERVATION; LONG TERM; PRIVACY CONCERNS; SAME-ORIGIN POLICY; WEB APPLICATION FIREWALL;

EID: 70349266257     PISSN: 15437221     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/1455770.1455782     Document Type: Conference Paper
Times cited : (302)

References (51)
  • 1
    • 70349279698 scopus 로고    scopus 로고
    • David Airey. Google's Gmail security failure leaves my business sabotaged, December 2007. http://www. davidairey.co. uk/google-gmail-security- hij ack/.
    • David Airey. Google's Gmail security failure leaves my business sabotaged, December 2007. http://www. davidairey.co. uk/google-gmail-security- hij ack/.
  • 2
    • 70349281202 scopus 로고    scopus 로고
    • Robert Auger. The cross-site request forgery (CSRF/XSRF) FAQ, 2007. http: //www.cgisecurity.com/articles/csrf-faq.shtml.
    • Robert Auger. The cross-site request forgery (CSRF/XSRF) FAQ, 2007. http: //www.cgisecurity.com/articles/csrf-faq.shtml.
  • 3
    • 34250013678 scopus 로고    scopus 로고
    • A face is exposed for AOL searcher no. 4417749.
    • August
    • Michael Barbaro and Tom Zeller Jr. A face is exposed for AOL searcher no. 4417749. The New York Times, August 2006. http://www.aytimes.com/2006/ 08/09/ technology/09aol.htm.
    • (2006) The New York Times
    • Barbaro, M.1    Zeller Jr., T.2
  • 4
    • 85055250091 scopus 로고    scopus 로고
    • Adam Barth, Collin Jackson, and John C. Mitchell. Securing frame communication in browsers. In In Proceedings of the 17th USENIX Security Symposium(USENIX Security 2008), July 2008.
    • Adam Barth, Collin Jackson, and John C. Mitchell. Securing frame communication in browsers. In In Proceedings of the 17th USENIX Security Symposium(USENIX Security 2008), July 2008.
  • 5
    • 33744475312 scopus 로고
    • Hypertext Transfer Protocol-HTTP/1.0
    • May
    • Tim Berners-Lee, Roy Fielding, and Henrik Frystyk. Hypertext Transfer Protocol-HTTP/1.0. RFC 1945, May 1996.
    • (1945) RFC
    • Berners-Lee, T.1    Fielding, R.2    Frystyk, H.3
  • 6
    • 84869623424 scopus 로고    scopus 로고
    • Douglas Crockford. JSONRequest, 2006. http://json.org/JSONRequest.html.
    • (2006)
  • 8
    • 84869619643 scopus 로고    scopus 로고
    • Rogan Dawes. Session Fixation, 2008. http://www.owasp.org/index.php/ Session-Fixation-Protection.
    • (2008) Session Fixation
    • Dawes, R.1
  • 13
    • 85013748296 scopus 로고    scopus 로고
    • Seth Fogie, Jeremiah Grossman, Robert Hansen, Anton Rager, and Petko D. Petkov. XSS Attacks: Cross Site Scripting Exploits and Defense. Syngress, 2007.
    • Seth Fogie, Jeremiah Grossman, Robert Hansen, Anton Rager, and Petko D. Petkov. XSS Attacks: Cross Site Scripting Exploits and Defense. Syngress, 2007.
  • 14
    • 84869622814 scopus 로고    scopus 로고
    • Mozilla Foundation, September
    • Mozilla Foundation. Security advisory 2005-58, September 2005. http://www.mozilla.org/security/ announce/2005/mfsa2005-58.html.
    • (2005) Security advisory , vol.2005 -58
  • 15
    • 70349271940 scopus 로고    scopus 로고
    • Google. Security for GW'T Applications, http: //groups.google.com/group/ Google-Web-Toolkit/ web/security-for-gwt-applications.
    • Google. Security for GW'T Applications, http: //groups.google.com/group/ Google-Web-Toolkit/ web/security-for-gwt-applications.
  • 17
    • 84869631925 scopus 로고    scopus 로고
    • Block Referer headers in Firefox, October
    • Elliotte Rusty Harold. Privacy tip #3: Block Referer headers in Firefox, October 2006. http://cafe.elharo.com/privacy/privacy-tip-3 -block-referer- headers-in-firefox/.
    • (2006) Privacy tip , Issue.3
    • Rusty Harold, E.1
  • 21
    • 84869601207 scopus 로고    scopus 로고
    • August
    • Dan Holevoet. Changes to inline gadgets, August 2008. http://igoogledeveloper.blogspot.com/ 2008/08/changes-to-inlined-gadgets.html.
    • (2008) Changes to inline gadgets
    • Holevoet, D.1
  • 22
    • 70349284230 scopus 로고    scopus 로고
    • Defeating frame busting techniques
    • http: //crypto. Stanford, edu/f ramebust
    • Collin Jackson. Defeating frame busting techniques, 2005. http: //crypto. Stanford, edu/f ramebust/.
    • (2005)
    • Jackson, C.1
  • 31
    • 70349276479 scopus 로고    scopus 로고
    • Amit Klein. Exploiting the XMLHttpRequest object in IE-Referrer spoofing and a lot more..., September 2005. http: //www.cgisecurity.com/lib/ XmlHTTPRequest.shtml.
    • Amit Klein. Exploiting the XMLHttpRequest object in IE-Referrer spoofing and a lot more..., September 2005. http: //www.cgisecurity.com/lib/ XmlHTTPRequest.shtml.
  • 32
    • 70349288883 scopus 로고    scopus 로고
    • Peter-Paul Koch. Frame busting. http://www.quirksmode.org/j s/framebust.html.
    • Peter-Paul Koch. Frame busting. http://www.quirksmode.org/j s/framebust.html.
  • 38
    • 70349299622 scopus 로고    scopus 로고
    • Microsoft. XDomainRequest object. http://msdn2.microsoft.com/en-us/ library/ cc288060(VS.85).aspx.
    • Microsoft. XDomainRequest object. http://msdn2.microsoft.com/en-us/ library/ cc288060(VS.85).aspx.
  • 39
    • 84869625969 scopus 로고    scopus 로고
    • http://wp.netscape.com/newsref/std/cookie-spec.html
    • Netscape. Persistent client state: HTTP cookies. http: //wp.netscape.com/newsref/std/cookie-spec.html.
    • Persistent client state
  • 40
    • 70349291868 scopus 로고    scopus 로고
    • Greg Pass, Abdur Chowdhury, and Cay ley Torgeson. A picture of search. In InfoScale '06: Proceedings of the 1st International Conference on Scalable Information Systems, 2006.
    • Greg Pass, Abdur Chowdhury, and Cay ley Torgeson. A picture of search. In InfoScale '06: Proceedings of the 1st International Conference on Scalable Information Systems, 2006.
  • 42
    • 0003533519 scopus 로고    scopus 로고
    • IETF Internet Draft. February 2008
    • Yngve Pettersen. HTTP state management mechanism v2. IETF Internet Draft. February 2008. http://www.ietf.org/internet-drafts/ draft-pettersen-cookie-v2- 02.txt,
    • HTTP state management mechanism v2
    • Pettersen, Y.1
  • 43
    • 70349279695 scopus 로고    scopus 로고
    • phpBB. http://phpbb.com/.
    • phpBB. http://phpbb.com/.
  • 45
    • 56549121497 scopus 로고    scopus 로고
    • Ruby on rails, http://www.rubyonrails.org/.
    • Ruby on rails
  • 46
    • 84869612603 scopus 로고    scopus 로고
    • September
    • Secunia. Microsoft Internet Explorer "XMLHTTP" HTTP request injection, September 2005. http://secunia.com/advisories/16942/.
    • (2005) Microsoft Internet Explorer XMLHTTP
  • 48
    • 84869604931 scopus 로고    scopus 로고
    • Trac. http://trac.edgewall.org/.
    • Trac
  • 50
    • 70349293417 scopus 로고    scopus 로고
    • Nick Hopper Manuel Blum, and John Langford. CAPTCHA: Using hard AI problems for security
    • Luis von Ahn, Nick Hopper Manuel Blum, and John Langford. CAPTCHA: Using hard AI problems for security. In Eurocrypt 2003.
    • Eurocrypt 2003
    • Luis von Ahn1
  • 51
    • 70349290322 scopus 로고    scopus 로고
    • Weilin Zliong. Session Fixation, 2008. http: //www.owasp.org/index.php/ Session-Fixation.
    • Weilin Zliong. Session Fixation, 2008. http: //www.owasp.org/index.php/ Session-Fixation.


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.