Foundations of Web Security: Defending Against CSRF and XSRF
Learn how cross-site request forgery exploits trusted browser sessions and master modern defense strategies to secure your web applications.
-
๐ฌ
AI instructor
Magtanong tungkol sa anumang aralin at makakuha ng malinaw na sagot agad, anumang oras. -
๐
Magsimula anumang oras
Walang iskedyul o deadline โ mag-aral sa sarili mong bilis, kahit kailan. -
๐
Sa Filipino
Mga aralin, gawain at sertipiko โ lahat ay ganap na nasa wika mo.
Tungkol sa kursong ito
When users log into web applications, they trust that their sessions are secure. Yet, malicious websites can secretly force browsers to execute unwanted actions on their behalf through Cross-Site Request Forgery (CSRF/XSRF).
This text-based course guides you through the mechanics of CSRF attacks, helping you identify vulnerabilities in your web applications and implement robust defenses. You will progress from understanding basic HTTP request behavior to configuring modern security headers and token-based protection systems.
What you'll learn:
- Understand the foundational concepts of browser-server trust, session cookies, and state management
- Analyze how attackers exploit stateful sessions to perform unauthorized actions on behalf of authenticated users
- Implement anti-CSRF tokens to validate incoming requests and block malicious payloads
- Configure modern SameSite cookie attributes to restrict cross-site credential sharing
- Apply defense-in-depth strategies, including custom request headers and double-submit cookie patterns
- Evaluate how modern API architectures and token-based authentication impact CSRF vulnerability
The course starts with essential web security terminology and browser mechanics before diving into simulated attack scenarios. You will then explore practical, step-by-step defense implementations, exploring both traditional token methods and modern browser-level protections.
This course is designed for beginner web developers, security enthusiasts, and software engineers who want to build secure applications from scratch. No prior security experience is required.
Read through the core concepts and start securing your web applications against session hijacking today.
Ang makukuha mo
-
๐
Certificate ng pagtatapos
Idagdag sa LinkedIn profile mo -
๐ฌ
Personal na AI tutor
Natigil sa isang aralin? Itanong sa iyong built-in na tutor ang kahit ano, kahit kailan. -
๐ง
Kasama ang audio version
Mag-aral kahit saan โ hindi kailangan ng screen -
โพ๏ธ
Lifetime access
Bumalik anumang oras, walang expiry -
๐ฑ
Telepono o computer
Gumagana saanman, kahit anong device -
๐ธ
14-day refund
Walang tanong -
โก
Maikli at focused
2 oras 42 min ng practical content
Mga Review
Wala pang review โ ikaw ang unang magbahagi.
Kinuha rin ng iba
๐ฅ Sikat
๐ May sertipiko
Isang Praktikal na Gabay sa Pagsunod sa MLPS 2.0
Sertipiko
Pagsasanay
SR 50.00
→
๐ฅ Sikat
๐ May sertipiko
Mga Pundasyon ng Cybersecurity Engineering para sa Sertipikasyon
Sertipiko
Pagsasanay
SR 50.00
→
๐ผ Handa sa trabaho
๐ May sertipiko
Praktikal na Pamamahala at Pamumuno sa Cybersecurity
Sertipiko
Pagsasanay
SR 50.00
→
๐ฅ Sikat
๐ May sertipiko
Web Penetration Testing para sa mga Nagsisimula: SQL Injection at Pagtuklas ng Vulnerability
Sertipiko
Pagsasanay
SR 50.00
→
Mga madalas itanong
Ano ang kailangan ko para sa kursong ito? +
Telepono o computer na may internet lang. Walang install, walang special hardware.
Paano ako magbabayad? +
Sa pamamagitan ng card via Stripe. Hindi namin iniimbak ang detalye ng card โ secure na hinahawakan ng Stripe.
Pwede ba akong mag-refund? +
Oo โ full refund sa loob ng 14 araw, walang tanong.
Hanggang kailan ang access ko? +
Habang buhay. Sa pagbili, sa iyo na ang course โ balikan mo kahit kailan.
Makakakuha ba ako ng certificate? +
Oo. Pagkatapos, makakatanggap ka ng certificate na maidadagdag sa LinkedIn profile mo.
Para sa mga learner sa
Tech
Design
Finance
Marketing
Healthcare
Edukasyon
Hospitality
Manufacturing