This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
User contributions
- 02:57, 11 November 2013 (diff | hist) . . (-969) . . OWASP Application Security FAQ (md5 is a broken primitive and should never be used for password. The "salted md5 trick" does not improve security. HTTPS should be used instead.)
- 17:20, 5 November 2013 (diff | hist) . . (+4) . . Talk:Cross Frame Scripting (current)
- 17:20, 5 November 2013 (diff | hist) . . (0) . . Talk:Cross Frame Scripting
- 17:20, 5 November 2013 (diff | hist) . . (+288) . . Talk:Cross Frame Scripting
- 17:13, 5 November 2013 (diff | hist) . . (-6) . . Cross Frame Scripting
- 17:11, 5 November 2013 (diff | hist) . . (-1) . . Cross Frame Scripting
- 18:20, 24 September 2013 (diff | hist) . . (+6) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (reorganization)
- 18:19, 24 September 2013 (diff | hist) . . (+388) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 17:07, 8 August 2013 (diff | hist) . . (+16) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (Fixing grammar)
- 20:31, 7 August 2013 (diff | hist) . . (+29) . . Talk:Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 20:28, 7 August 2013 (diff | hist) . . (+115) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (Better mitigation guidelines for CSRF tokens within the URL.)
- 20:25, 7 August 2013 (diff | hist) . . (+1,860) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (Mozilla introduced the "Origin" standard to prevent CSRF, and therefore must be talked about in this page. Referer checking is commonly used and commonly accepted method of defense, this cannot be removed without a damn good explanation.)
- 19:44, 13 May 2013 (diff | hist) . . (-1) . . Clickjacking Defense Cheat Sheet
- 19:43, 13 May 2013 (diff | hist) . . (-14) . . Clickjacking Defense Cheat Sheet
- 19:42, 13 May 2013 (diff | hist) . . (+1,351) . . Clickjacking Defense Cheat Sheet (Adding an additional method of clickjacking protection, the use of window.confirm().)
- 17:41, 21 October 2012 (diff | hist) . . (+21) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (Any XSS vulnerability can be used to bypass these CSRF protection systems.)
- 22:47, 24 August 2012 (diff | hist) . . (+377) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (misleading...)
- 22:42, 24 August 2012 (diff | hist) . . (-871) . . Talk:Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 22:41, 24 August 2012 (diff | hist) . . (+465) . . Talk:Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (→Don't post theoretical attacks, or "here say" on any OWASP page.: new section)
- 22:37, 24 August 2012 (diff | hist) . . (+1) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 22:35, 24 August 2012 (diff | hist) . . (+98) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (Wow, the "Checking The Referer Header" was flat out incorrect and totally missleading. The Mozilla Security team would be upset if they read that garbage.)
- 15:03, 21 November 2011 (diff | hist) . . (0) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 15:02, 21 November 2011 (diff | hist) . . (+183) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 04:50, 30 August 2011 (diff | hist) . . (+17) . . Talk:Cross-site Scripting (XSS) (current)
- 04:50, 30 August 2011 (diff | hist) . . (+124) . . Talk:Cross-site Scripting (XSS)
- 00:13, 6 August 2010 (diff | hist) . . (-15) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 19:33, 4 August 2010 (diff | hist) . . (+7) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 19:32, 4 August 2010 (diff | hist) . . (+286) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 19:27, 4 August 2010 (diff | hist) . . (-4) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 19:26, 4 August 2010 (diff | hist) . . (0) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 19:26, 4 August 2010 (diff | hist) . . (+736) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (qui)
- 19:10, 4 August 2010 (diff | hist) . . (+339) . . N Talk:Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet (Created page with 'Checking Referer Header is used to patch the most dangerous CSRF vulnerability ever discovered (which was by me http://www.kb.cert.org/vuls/id/643049 Michael Brooks). This arti…')
- 19:08, 4 August 2010 (diff | hist) . . (+9) . . Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
- 01:03, 16 May 2010 (diff | hist) . . (+20) . . Cross-Site Request Forgery (CSRF) (→Related Controls)
- 01:02, 16 May 2010 (diff | hist) . . (-9) . . Cross-Site Request Forgery (CSRF) (→Related Controls)
- 00:58, 16 May 2010 (diff | hist) . . (-76) . . Cross-Site Request Forgery (CSRF) (→Related Controls)