Ad

EnglishFrenchSpanish

Free editor online | DOC > | XLS > | PPT >


OffiDocs favicon

No CSRF in Chrome with OffiDocs

No CSRF  screen for extension Chrome web store in OffiDocs Chromium

Ad


DESCRIPTION


Cross-Site Request Forgery is a major problem when it comes to browsing the web.

If an attacker were to craft a request toward a server that performs an action, the request would contain any identifying cookies you have.

As pointed out in academic literature, this can be used to empty bank accounts, change passwords, or anything in between.

This extension attempts to prevent Cross-Site Request Forgery by stripping cookies from any (non-GET) request that does not follow the same-origin policy.

In this way, normal browsing remains uninterrupted while any possible CRSF attacks are blocked! The extension is easily disabled and contains a small report of all requests which had cookies stripped.

This extension is open source and the source code is viewable at https://github.

com/brandonio21/no-csrf This extension is based on a similar extension by avlidienbrunn

Additional Information:


- Offered by brandonio21
- Average rating : 5 stars (loved it)
- Developer This email address is being protected from spambots. You need JavaScript enabled to view it.

No CSRF web extension integrated with the OffiDocs Chromium online


Run Chrome Extensions

Ad