Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial The Difference Between OSRF and CSRF filter_list
Author
Message
The Difference Between OSRF and CSRF #1
Here yet with another tutorial. Here goes nothing.

On-site request forgery (OSRF) -

This is often confused with CSRF. The difference is that the stored XSS vulnerability is on the site that the attack payload makes a request to. An example would be the previous OSRF vulnerability in myBB that allowed users to place the URL to the give award function in IMG tags. You made a thread with the payload, an admin views it, and you get a reward because the logged in admin's browser visited the link. The vulnerability was on the same site that the payload made a request to, making it an on-site request forgery thingy.

This vulnerability can be prevented by completely filtering user input before it's incorporated into responses.


Cross-site request forgery (CSRF) -

In a CSRF attack, the victim visits a website or page with a script that makes a request to a another website to perform something beneficial to the attacker. We'll use another forum example for this. Suppose a user sends a user a link to a website with a script that makes a POST request to the forum, giving the user rep. When the user visits the website, like OSRF, the script gets executed in the user's browser, ultimately giving the 1st user rep.

The script would look like this -
Code:
<html> <body> <form action="https://sinister.ly/giveuserrep.php" method="POST"> <input type="hidden" name="user" value="Nebulous"> <input type="hidden" name="amount" value="3"> <input type="hidden" name="reason" value="cocks"> </form> <script> document.forms[0].submit(); </script> </body> </html>

The form tag specifies what website to make a request to, and sets the type of request as a POST request.

The input tags are all of the POST values necessary to give the user rep.

The script executes the form and input tags, making the request to https://sinister.ly/giveuserrep.php with all of the POST data values.

CSRF vulnerabilities exist when browsers automatically submit cookies back to the vulnerable web server with the requests following it and the web application allows it. If a webapp only depends on HTTP cookies for tracking sessions, it's greatly at risk to this type of attack.

To prevent CSRF: anti-CSRF tokens

Hope you all learned something.

Reply

RE: The Difference Between OSRF and CSRF #2
That's actually still pretty surface level. You should go into the why, not just the how. In the words of @Reiko you are just giving the user a fish, not teaching him how to fish.

It's a basic MITM attack. If anybody wants to see an explanation on how they work, shoot me a PM.

Reply