No-CSRF

Prevent cookies from being client-side sent cross-origin.

Qu'est-ce que No-CSRF ?

No-CSRF est une extension Chrome développée par brandonio21, et sa fonction principale est "Prevent cookies from being client-side sent cross-origin.".

Captures d'Écran de l'Extension

screenshot

Télécharger le fichier CRX de l'extension No-CSRF

Téléchargez les fichiers d'extension No-CSRF au format crx, installez manuellement les extensions Chrome dans le navigateur ou partagez les fichiers crx avec des amis pour installer facilement les extensions Chrome.

Instructions d'Utilisation de l'Extension

                        Cross-Site Request Forgery is a major problem when it comes to browsing the web. If an attacker were to craft a request toward a server that performs an action, the request would contain any identifying cookies you have. As pointed out in academic literature, this can be used to empty bank accounts, change passwords, or anything in between.

This extension attempts to prevent Cross-Site Request Forgery by stripping cookies from any (non-GET) request that does not follow the same-origin policy. In this way, normal browsing remains uninterrupted while any possible CRSF attacks are blocked!

The extension is easily disabled and contains a small report of all requests which had cookies stripped. 

This extension is open source and the source code is viewable at https://github.com/brandonio21/no-csrf

This extension is based on a similar extension by avlidienbrunn                    

Informations de Base sur l'Extension

Nom No-CSRF No-CSRF
ID amababajdpoioajiapncbkhcbpkncepk
URL Officiel https://chromewebstore.google.com/detail/no-csrf/amababajdpoioajiapncbkhcbpkncepk
Description Prevent cookies from being client-side sent cross-origin.
Taille du Fichier 9.58 KB
Nombre d'Installations 392
Version Actuelle 0.42
Dernière Mise à Jour 2016-07-05
Date de Publication 2016-07-04
Évaluation 5.00/5 Total 1 Évaluations
Développeur brandonio21
Email [email protected]
Type de Paiement free
Site Web de l'Extension https://github.com/brandonio21/no-csrf
URL de la Page d'Aide https://github.com/brandonio21/no-csrf
Langues Prises en Charge en
manifest.json
{
    "update_url": "https:\/\/clients2.google.com\/service\/update2\/crx",
    "manifest_version": 2,
    "name": "No-CSRF",
    "version": "0.42",
    "description": "Prevent cookies from being client-side sent cross-origin.",
    "icons": {
        "128": "badge.png"
    },
    "permissions": [
        "webRequest",
        "webRequestBlocking",
        "tabs",
        "webNavigation",
        ""
    ],
    "background": {
        "scripts": [
            "background.js"
        ]
    },
    "browser_action": {
        "default_icon": "badge.png",
        "default_popup": "popup.html"
    }
}