No-CSRF

Prevent cookies from being client-side sent cross-origin.

Hvad er No-CSRF?

No-CSRF er en Chrome-udvidelse udviklet af brandonio21, og dens hovedfunktion er "Prevent cookies from being client-side sent cross-origin.".

Udvidelsesskærmbilleder

screenshot

Download No-CSRF-udvidelses-CRX-fil

Download No-CSRF-udvidelsesfiler i crx-format, installer Chrome-udvidelser manuelt i browseren eller del crx-filer med venner for nemt at installere Chrome-udvidelser.

Brugsanvisning til Udvidelsen

                        Cross-Site Request Forgery is a major problem when it comes to browsing the web. If an attacker were to craft a request toward a server that performs an action, the request would contain any identifying cookies you have. As pointed out in academic literature, this can be used to empty bank accounts, change passwords, or anything in between.

This extension attempts to prevent Cross-Site Request Forgery by stripping cookies from any (non-GET) request that does not follow the same-origin policy. In this way, normal browsing remains uninterrupted while any possible CRSF attacks are blocked!

The extension is easily disabled and contains a small report of all requests which had cookies stripped. 

This extension is open source and the source code is viewable at https://github.com/brandonio21/no-csrf

This extension is based on a similar extension by avlidienbrunn                    

Grundlæggende oplysninger om udvidelsen

Navn No-CSRF No-CSRF
ID amababajdpoioajiapncbkhcbpkncepk
Officiel URL https://chromewebstore.google.com/detail/no-csrf/amababajdpoioajiapncbkhcbpkncepk
Beskrivelse Prevent cookies from being client-side sent cross-origin.
Filstørrelse 9.58 KB
Antal Installationer 392
Nuværende Version 0.42
Senest Opdateret 2016-07-05
Udgivelsesdato 2016-07-04
Bedømmelse 5.00/5 Samlet 1 Bedømmelser
Udvikler brandonio21
E-mail [email protected]
Betalingsmetode free
Udvidelseswebsted https://github.com/brandonio21/no-csrf
Hjælpeside-URL https://github.com/brandonio21/no-csrf
Understøttede Sprog en
manifest.json
{
    "update_url": "https:\/\/clients2.google.com\/service\/update2\/crx",
    "manifest_version": 2,
    "name": "No-CSRF",
    "version": "0.42",
    "description": "Prevent cookies from being client-side sent cross-origin.",
    "icons": {
        "128": "badge.png"
    },
    "permissions": [
        "webRequest",
        "webRequestBlocking",
        "tabs",
        "webNavigation",
        ""
    ],
    "background": {
        "scripts": [
            "background.js"
        ]
    },
    "browser_action": {
        "default_icon": "badge.png",
        "default_popup": "popup.html"
    }
}