Jump to content
mah_one

Header manipulate, se poate?

Recommended Posts

Posted (edited)

Buna,

Am gasit in google un request care nu are nici un fel de token pentru validarea acestuia si am crezut ca e CSRF.

Dar in header am gasit un parametru care se numeste:

"Authentication: X-Google-Auth" sau in alt request am gasit "X-Same-Domain: true" si nu au nici un fel de validare impotriva la atacuri CSRF.

Tin sa va spun ca fara acel parametru "Authentication: X-Google-Auth" in header requestul va esua.

Eu va intreb daca exista vreo posibilitate sa ii setez victimei sa trimita la google si acel parametru cu aceea constanta in header-> "Authentication: X-Google-Auth".

Toate cele bune,

Mah_one

Edited by mah_one

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...