![]() |
VOOZH | about |
This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
OWASP CSRF Protector ProjectOWASP CSRF Protector Project is an effort by a group of developers in securing web applications against Cross Site Request Forgery, providing php library and an Apache Module (to be used differently) for easy mitigation. GitHub Repo - php library
What is CSRF Protector?CSRF Protector Project has two parts:
Why CSRF Protector?CSRF Protector is suitable for three group of developers:
Project leader |
How to useSee github wiki - How to use Major Contributors
Features OfferedCSRF Protection provide protection for:
Damages Mitigated
Get InvolvedTo contribute to the code fork and send a pull to: For discussions, join our mailing list: - Mailing List |
Salient Features
Quick DownloadQuick LinksNews and EventsClassifications
| |||||
Its an Apache 2.x.x Module (Currently 2.2.x) under development. It can be installed and configured in any Apache Server to protect it against Cross Site Request Forgery attacks. mod_csrfprotector provides protection to both POST and GET requests (not enabled by default).
Once installed in Apache Server, every request that is made to the server, and validated against CSRF attacks by the input filters. Input filter follows a protocol as mentioned by developer in configuration, which helps the module to decide weather to validated the request. The input filter checks for appropriate token sent with request. Request if forwarded to other filters or content generator (like php or cgi) in validation is successful. Otherwise, appropriate actions are taken as per configuration. For ex: 403, Forbidden header is send to client. The Output filter, checks for content type of output generated by content generator and if it is `text/html` or `text/xhtml` it appends javascript code to the output. This js code in client side is responsible for attaching CSRFP_token with every required request sent from client.
CSRF Protection provide protection for:
To contribute to the code fork and send a pull to:
GitHub Repo - mod_csrfprotector
For discussions, join our mailing list: - Mailing List
All todos for mod_csrfprotector are listed at: todofy: mod_csrfprotector
Under Development
Its a standalone php library for mitigating Cross Site Request Forgery (CSRF) vulnerabilities in web applications, which can be used with any existing web application or while developing a new one. More information available at github wiki
CSRF Protection provide protection for:
To contribute to the code fork and send a pull to:
GitHub Repo
For discussions, join our mailing list: - Mailing List
Version 1.0.0 Released!
All todos for CSRF Protector PHP are listed at: todofy - CSRF Protector PHP