Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
cookies, csrf, and xss
Search
668Jerry
July 03, 2014
Education
69
0
Share
cookies, csrf, and xss
for Django Summer, 2014
668Jerry
July 03, 2014
Other Decks in Education
See All in Education
0506
cbtlibrary
0
180
Data Processing and Visualisation Frameworks - Lecture 6 - Information Visualisation (4019538FNR)
signer
PRO
1
3.1k
自己紹介 / who-am-i
yasulab
6
6.8k
SARA Annual Report 2025-26
sara2023
1
350
Virtual and Augmented Reality - Lecture 8 - Next Generation User Interfaces (4018166FNR)
signer
PRO
0
2.3k
共感から、つくる: 変わり続ける自分と、誰かのための創造
micknerd
1
370
Protecting Patrons with Digital Vendors
dsalo
0
180
2026年度春学期 統計学 第7回 データの関係を知る(2)ー 回帰と決定係数 (2026. 5. 21)
akiraasano
PRO
0
120
Laura Wilson - The Quarterly PR Pivot
laurawilsonbseo1
1
320
[2026前期火5] 論理学(京都大学文学部 前期 第4回)「 ならば(→)の導入と証明ネット」
yatabe
0
400
JAWS-UG初心者支部#81 GWにEduJAWSと何か作ろうもくもく会!
otsuki
0
120
View Manipulation and Reduction - Lecture 9 - Information Visualisation (4019538FNR)
signer
PRO
1
2.7k
Featured
See All Featured
Between Models and Reality
mayunak
4
320
B2B Lead Gen: Tactics, Traps & Triumph
marketingsoph
0
130
Connecting the Dots Between Site Speed, User Experience & Your Business [WebExpo 2025]
tammyeverts
11
930
How to Talk to Developers About Accessibility
jct
2
210
The #1 spot is gone: here's how to win anyway
tamaranovitovic
2
1.1k
Discover your Explorer Soul
emna__ayadi
2
1.1k
Fashionably flexible responsive web design (full day workshop)
malarkey
408
66k
Measuring Dark Social's Impact On Conversion and Attribution
stephenakadiri
2
200
WCS-LA-2024
lcolladotor
0
610
The Mindset for Success: Future Career Progression
greggifford
PRO
0
350
職位にかかわらず全員がリーダーシップを発揮するチーム作り / Building a team where everyone can demonstrate leadership regardless of position
madoxten
62
54k
Color Theory Basics | Prateek | Gurzu
gurzu
0
320
Transcript
2014Ն ਫՌ෩ຯతcsrf the Book (ֲढ़ّ)
ࢼஶ༻ၷݸෆಉతாᥒࡏෆಉᖣ᧸ث҃ిᡵ্ొೖ
࠶ಉ㑊ॴ༗cookie
ٙ!! 㠥ҰిᡵొೖྃɼෆधཁாີɺҰᒬత໊ࣈ!!!
ੋతɼେ෦త༻cookieመ࡞ᒟݶɻ গྃҰᴍᴍతᒾ查ɺ ༻ऀᱪᱛߋՂʂ ୠੋ...
༻ https://speakerdeck.com/mrorz/selected- topics-on-website-security-at-102-2-ccsp
csrfͱ ˒ሣ༻ऀࣕݴɼҰ छෆೳစᴍత౦
መ࡞csrf add_page.htmlతݪ࢝ᛰଘԼိɼመ࡞Ұݸ૬ ಉతෳɼهಘactionཁվ㘺ሣ࿏ኸ
csrf݁Ռ Djangoత႔ཧೳ㢨զ၇ᱛᨽग़csrfɼॴҎهಘ ࠾༻csrf_token૬᮫݅ɻ
xssͱ ˒ ሣᆦਓࣕݴɼҰछೳዱ ҙ࠹ೖทత౦
መ࡞xss ࡏ䓟తadd_categoryதpo্Ṝcategoryࢼࢼ ʮ”></a><script>while (true) {alert("ᔧܥ౷ཧһ");}</script><a>ʯ
༬ظత݁Ռࠨɼୠመࡍ্Django㢨զ၇၏ྃauto escape
-େࢿ㘤ܥCCSPॿڭ-MrOrz -େి௨ॴࢿ㘤҆શ-༶ -How to Tango with Django-David Maxwell ײँɺӨยჩߟ