COMMON WEAKNESS ENUMERATIONStable
CWE-352
Cross-Site Request Forgery (CSRF)
Abstraction
Compound
Structure
Composite
Likelihood of Exploit
Medium
Understand the problem
What is the problem?
Terminology
Alternate terms and usages
Session Riding
Cross Site Reference Forgery
XSRF
CSRF
Root cause
How and when does the problem arise?
Lifecycle phase
Architecture and Design
Risk
What does successful exploitation lead to?
Gain Privileges or Assume IdentityBypass Protection MechanismRead Application DataModify Application DataDoS: Crash, Exit, or Restart
Defence
How is it prevented and fixed?
Architecture and Design
Libraries or Frameworks
Detail
Architecture and Design
Libraries or Frameworks
Implementation
Implementation-phase defence
Detail
Implementation
Implementation-phase defence
Architecture and Design
Architecture and design approach
Detail
Architecture and Design
Architecture and design approach
Architecture and Design
Architecture and design approach
Detail
Architecture and Design
Architecture and design approach
Architecture and Design
Architecture and design approach
Detail
Architecture and Design
Architecture and design approach
Architecture and Design
Architecture and design approach
Detail
Architecture and Design
Architecture and design approach
Implementation
Implementation-phase defence
Detail
Implementation
Implementation-phase defence
Verification
How is it detected?
Manual Analysis
HighAutomated Static Analysis
LimitedAutomated Static Analysis - Binary or Bytecode
SOAR PartialManual Static Analysis - Binary or Bytecode
SOAR PartialDynamic Analysis with Automated Results Interpretation
HighDynamic Analysis with Manual Results Interpretation
HighManual Static Analysis - Source Code
SOAR PartialAutomated Static Analysis - Source Code
SOAR PartialArchitecture or Design Review
SOAR PartialMITRE diagram
Weakness relationships and flow
