首页    期刊浏览 2025年02月21日 星期五
登录注册

文章基本信息

  • 标题:Strategies and scenarios of CSRF attacks against the CAPTCHA forms
  • 本地全文:下载
  • 作者:Hossein Moradi ; Hossein Kardan Moghaddam
  • 期刊名称:Journal of Advanced Computer Science & Technology
  • 印刷版ISSN:2227-4332
  • 电子版ISSN:2227-4332
  • 出版年度:2015
  • 卷号:4
  • 期号:1
  • 页码:15-22
  • DOI:10.14419/jacst.v4i1.3935
  • 出版社:Science Publishing Corporation
  • 摘要:In this article, we’ve tried to examine the hypothesis of the robustness of a form by using CAPTCHA against CSRF and login CSRF attacks. Our investigations showed that unlike public opinion, common attacks to bypass CAPTCHAs such as Optical Character Recognition (OCR) and 3rd party human attacks are not applicable in the CSRF case and instead, Clickjacking is the most important scenario of CSRF and login CSRF attacks against a secure session-dependent CAPTCHA form. Remember that the Clickjacking is also applicable to bypass the well-known CSRF protections, such as the secret token and the Referer header. Therefore, although the frequent application of CAPTCHA on every page of a website negatively impacts the user experience, but the robustness of a robust session-dependent CAPTCHA against the CSRF and login CSRF attacks is almost the same as the session-dependent security token. Moreover, when a website is using a session-independent or week pattern of CAPTCHA, attackers can bypass the CAPTCHAs and launch the CSRF or login CSRF attacks by using XSS, session hijacking, replay attacks or submitting a random response.
  • 关键词:CAPTCHA;CSRF;HTTPS;CSRF Attacks.
国家哲学社会科学文献中心版权所有