Do you think SIGN-UP form has #CSRF protection or not? // cc @ircmaxell @homakov @padraicb @johnwilander
-
-
@soaj1664ashar@homakov@padraicb@johnwilander I don't think it's *necessary*. I wouldn't knock code that didn't... -
@ircmaxell@soaj1664ashar CAPTCHAs counteract nuisance signups or timing attacks on username list /cc@homakov@johnwilander -
@padraicb@ircmaxell@soaj1664ashar@johnwilander any form must have CSRF prot, no excuses -
@homakov@padraicb@ircmaxell@soaj1664ashar@johnwilander What's the need of CSRF token inside of Sign up form?@homakov -
@rafaybaloch@padraicb@ircmaxell@soaj1664ashar@johnwilander it doesn't matter, every changing request must have it by default -
@homakov@padraicb@ircmaxell@soaj1664ashar But it's not necessary, Capacha is enough to protect.. -
@rafaybaloch@padraicb@ircmaxell@soaj1664ashar captcha mitigates automated registration — unrelated. if signup logs in — session fixation -
@homakov@padraicb@ircmaxell@soaj1664ashar What can you accomplish, when sign up form does not have CSRF token, but has capacha...answers -
@rafaybaloch@padraicb@ircmaxell@soaj1664ashar easy. i get solve captcha myself and send the solution along with my own recaptcha_token
@homakov @padraicb @soaj1664ashar Capacha can be used instead of CSRF protection on Sign up form, and it cannot also be bypassed by xss ;)
-
@rafaybaloch I assume bypass would be to re-display CAPTCHA to target as something innocuous (e.g UI confirm check)@homakov@soaj1664ashar -
@padraicb@rafaybaloch@soaj1664ashar challenge and answer are both parameters. Not cookie
Ashar Javed
Anthony Ferrara
Pádraic Brady
Egor Homakov
Rafay baloch