target service while viewing compromised page • Chances would be raised if the mode of link delivery coincides with the account to be compromised – Link can be sent to vic&m via email if the aAacker is interested to take over the mail account
func&on of CSRF Cookie Token and Session ID – f(CSRF Cookie Token, Session ID) = Form Variable • Transform CSRF Cookie Token to hidden form variable through Session ID before comparing
C = FV ? Ideal abcd abcd ✔ Failed A3ack efgh abcd ✘ Successful A3ack efgh efgh ✔ Set by legi&mate web server Set by aAacker Controlled by aAacker due to cookie tossing
Cookie (CSRF) Session ID f(C, SID) = FV ? Mi@ga@on bd` abcd 1234 ✔ Failed A3ack abcd abcd 1234 ✘ No incen&ve to overwrite Not able to read or guess Set by legi&mate web server Set by aAacker
needed, clean migra&on for sites already using Double Submit Cookies • Bad: More challenging for administrators to fully comprehend • And that’s when vulnerabili&es come in, no?