smrrd.de/apache-wickets-encrypted-urls-dont-protect-from-csrf.html

Apache Wicket is a web application framework for Java and is used by quite a few big sites. During a pentest I had a closer look at the encrypted url feature which supposedly protects from cross-site request forgery. Unfortunately the proposed simple example is inherently flawed for two reasons. First ...


Comments (0)

Sign in to post comments.