Cross-Protocol Request Forgery
By NCC Group
Added
This whitepaper formalizes a class of attacks called Cross-Protocol Request Forgery (CPRF) which enables non-HTTP listeners to be exploited through Cross-Site Request Forgery (CSRF) and Server-Side Request Forgery (SSRF). This paper both references existing research and expands upon it in later sections.
Tags
Web browser CSRF Threat actor Vulnerability Boundary defense Credentials Database Endpoint Mobile device Embedded systemTopic Map
