new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

csrf/double_submit_naive

1 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Naive Double-Submit Cookie pattern vulnerability

The Naive Double-Submit Cookie pattern is bypassable by an attacker who can write cookies on the target domain (via vulnerable sibling subdomain, DNS takeover, or plaintext-HTTP cookie injection on non-__Host- cookies). This pattern should not be used for new code. It uses a cryptographically strong random value as both a cookie and a request parameter, but this provides minimal protection and remains vulnerable to cookie injection attacks. Always prefer the Signed Double-Submit Cookie pattern with session-bound HMAC tokens.

Give your agent this brain