{"id":476481,"date":"2023-08-09T07:29:55","date_gmt":"2023-08-09T07:29:55","guid":{"rendered":""},"modified":"2023-09-05T11:12:51","modified_gmt":"2023-09-05T11:12:51","slug":"cross-site-requested-forgery","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/tr\/wiki\/cross-site-requested-forgery\/","title":{"rendered":"Siteler aras\u0131 talep edilen sahtecilik"},"content":{"rendered":"<p>Siteler Aras\u0131 \u0130stek Sahtecili\u011fi (CSRF), bir sald\u0131rgan\u0131n bir web uygulamas\u0131nda kimli\u011fi do\u011frulanan bir kullan\u0131c\u0131 ad\u0131na yetkisiz eylemler ger\u00e7ekle\u015ftirmesine olanak tan\u0131yan bir t\u00fcr web g\u00fcvenlik a\u00e7\u0131\u011f\u0131d\u0131r. CSRF sald\u0131r\u0131lar\u0131, bir web sitesinin kullan\u0131c\u0131n\u0131n bilgisi veya izni olmadan k\u00f6t\u00fc ama\u00e7l\u0131 isteklerde bulunmas\u0131 i\u00e7in kand\u0131rarak, kullan\u0131c\u0131n\u0131n taray\u0131c\u0131s\u0131na olan g\u00fcvenini k\u00f6t\u00fcye kullan\u0131r. Bu t\u00fcr sald\u0131r\u0131lar web uygulamalar\u0131n\u0131n b\u00fct\u00fcnl\u00fc\u011f\u00fc ve g\u00fcvenli\u011fi a\u00e7\u0131s\u0131ndan ciddi bir tehdit olu\u015fturmaktad\u0131r.<\/p>\n<h2>Siteler Aras\u0131 \u0130stek Sahtecili\u011finin k\u00f6keninin tarihi ve bundan ilk s\u00f6z<\/h2>\n<p>&quot;Siteler Aras\u0131 \u0130stek Sahtecili\u011fi&quot; terimi ilk olarak 2001 y\u0131l\u0131nda ara\u015ft\u0131rmac\u0131lar RSnake ve Amit Klein taraf\u0131ndan web uygulamas\u0131 g\u00fcvenli\u011fi \u00fczerine bir tart\u0131\u015fma s\u0131ras\u0131nda ortaya at\u0131ld\u0131. Ancak CSRF benzeri sald\u0131r\u0131 kavram\u0131 1990&#039;lar\u0131n ortalar\u0131ndan beri biliniyordu. Benzer bir sald\u0131r\u0131n\u0131n bilinen ilk s\u00f6z\u00fc, Adam Barth adl\u0131 bir ara\u015ft\u0131rmac\u0131n\u0131n Netscape Navigator taray\u0131c\u0131s\u0131nda bir sald\u0131rgan\u0131n HTTP isteklerini taklit etmesine izin veren bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131 tan\u0131mlad\u0131\u011f\u0131 1996 y\u0131l\u0131na kadar uzan\u0131yor.<\/p>\n<h2>Siteler Aras\u0131 \u0130stek Sahtecili\u011fi hakk\u0131nda detayl\u0131 bilgi<\/h2>\n<p>CSRF sald\u0131r\u0131lar\u0131 genellikle hesap ayarlar\u0131n\u0131 de\u011fi\u015ftirmek, sat\u0131n alma yapmak veya y\u00fcksek ayr\u0131cal\u0131klara sahip eylemler ger\u00e7ekle\u015ftirmek gibi durum de\u011fi\u015ftiren istekleri hedefler. Sald\u0131rgan, kullan\u0131c\u0131n\u0131n taray\u0131c\u0131s\u0131n\u0131 hedeflenen web uygulamas\u0131nda yetkisiz eylem ger\u00e7ekle\u015ftirmesi i\u00e7in tetikleyen, \u00f6zel haz\u0131rlanm\u0131\u015f bir URL veya form i\u00e7eren k\u00f6t\u00fc ama\u00e7l\u0131 bir web sitesi veya e-posta olu\u015fturur. Bunun nedeni, taray\u0131c\u0131n\u0131n otomatik olarak kullan\u0131c\u0131n\u0131n kimli\u011fi do\u011frulanm\u0131\u015f oturum kimlik bilgilerini k\u00f6t\u00fc ama\u00e7l\u0131 iste\u011fe dahil etmesi ve b\u00f6ylece iste\u011fin me\u015fru g\u00f6r\u00fcnmesini sa\u011flamas\u0131d\u0131r.<\/p>\n<h2>Siteler Aras\u0131 \u0130stek Sahtecili\u011finin i\u00e7 yap\u0131s\u0131 ve nas\u0131l \u00e7al\u0131\u015ft\u0131\u011f\u0131<\/h2>\n<p>CSRF&#039;nin arkas\u0131ndaki mekanizma a\u015fa\u011f\u0131daki ad\u0131mlar\u0131 i\u00e7erir:<\/p>\n<ol>\n<li>Kullan\u0131c\u0131 bir web uygulamas\u0131nda oturum a\u00e7ar ve genellikle bir \u00e7erezde veya gizli bir form alan\u0131nda saklanan bir kimlik do\u011frulama belirteci al\u0131r.<\/li>\n<li>Kullan\u0131c\u0131 h\u00e2l\u00e2 oturum a\u00e7m\u0131\u015f durumdayken k\u00f6t\u00fc ama\u00e7l\u0131 bir web sitesini ziyaret eder veya k\u00f6t\u00fc ama\u00e7l\u0131 bir ba\u011flant\u0131ya t\u0131klar.<\/li>\n<li>K\u00f6t\u00fc ama\u00e7l\u0131 web sitesi, taray\u0131c\u0131n\u0131n \u00e7erezlerinde veya oturum verilerinde saklanan kullan\u0131c\u0131n\u0131n kimlik bilgilerini kullanarak hedef web uygulamas\u0131na haz\u0131rlanm\u0131\u015f bir HTTP iste\u011fi g\u00f6nderir.<\/li>\n<li>Hedef web uygulamas\u0131 iste\u011fi al\u0131r ve kullan\u0131c\u0131n\u0131n ge\u00e7erli kimlik do\u011frulama belirtecini i\u00e7erdi\u011finden, iste\u011fi me\u015fru kullan\u0131c\u0131dan gelmi\u015f gibi i\u015fler.<\/li>\n<li>Sonu\u00e7 olarak k\u00f6t\u00fc niyetli eylem, kullan\u0131c\u0131n\u0131n bilgisi d\u0131\u015f\u0131nda onun ad\u0131na ger\u00e7ekle\u015ftirilir.<\/li>\n<\/ol>\n<h2>Siteler Aras\u0131 \u0130stek Sahtecili\u011finin temel \u00f6zelliklerinin analizi<\/h2>\n<p>CSRF sald\u0131r\u0131lar\u0131n\u0131n temel \u00f6zellikleri \u015funlar\u0131 i\u00e7erir:<\/p>\n<ol>\n<li><strong>G\u00f6r\u00fcnmez S\u00f6m\u00fcr\u00fc<\/strong>: CSRF sald\u0131r\u0131lar\u0131 kullan\u0131c\u0131n\u0131n haberi olmadan sessizce ger\u00e7ekle\u015ftirilebilir, bu da onlar\u0131 tehlikeli ve tespit edilmesi zor hale getirir.<\/li>\n<li><strong>Kullan\u0131c\u0131 G\u00fcvenine G\u00fcvenmek<\/strong>: CSRF, kullan\u0131c\u0131n\u0131n taray\u0131c\u0131s\u0131 ile web uygulamas\u0131 aras\u0131nda kurulan g\u00fcveni kullan\u0131r.<\/li>\n<li><strong>Oturum Tabanl\u0131<\/strong>: CSRF sald\u0131r\u0131lar\u0131 genellikle, istekleri taklit etmek i\u00e7in kullan\u0131c\u0131n\u0131n kimlik do\u011frulama durumunu kullanan aktif kullan\u0131c\u0131 oturumlar\u0131na dayan\u0131r.<\/li>\n<li><strong>Etkili Eylemler<\/strong>: Sald\u0131r\u0131lar, durum de\u011fi\u015ftiren operasyonlar\u0131 hedef al\u0131r ve veri de\u011fi\u015fikli\u011fi veya mali kay\u0131p gibi \u00f6nemli sonu\u00e7lara yol a\u00e7ar.<\/li>\n<\/ol>\n<h2>Siteler Aras\u0131 \u0130stek Sahtecili\u011fi T\u00fcrleri<\/h2>\n<table>\n<thead>\n<tr>\n<th>Tip<\/th>\n<th>Tan\u0131m<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Basit CSRF<\/td>\n<td>Hedef web uygulamas\u0131na tek bir sahte iste\u011fin g\u00f6nderildi\u011fi en yayg\u0131n t\u00fcr.<\/td>\n<\/tr>\n<tr>\n<td>K\u00f6r CSRF<\/td>\n<td>Sald\u0131rgan, yan\u0131t\u0131 almadan hedefe haz\u0131rlanm\u0131\u015f bir istek g\u00f6ndererek hedefi &quot;k\u00f6r&quot; hale getirir.<\/td>\n<\/tr>\n<tr>\n<td>XSS ile CSRF<\/td>\n<td>Sald\u0131rgan, kurbanlar \u00fczerinde k\u00f6t\u00fc ama\u00e7l\u0131 komut dosyalar\u0131 y\u00fcr\u00fctmek i\u00e7in CSRF&#039;yi Siteler Aras\u0131 Komut Dosyas\u0131 \u00c7al\u0131\u015ft\u0131rma (XSS) ile birle\u015ftirir.<\/td>\n<\/tr>\n<tr>\n<td>JSON u\u00e7 noktalar\u0131na sahip CSRF<\/td>\n<td>JSON u\u00e7 noktalar\u0131n\u0131 kullanan uygulamalar\u0131 hedef alan sald\u0131rgan, CSRF&#039;yi y\u00fcr\u00fctmek i\u00e7in JSON verilerini y\u00f6netir.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Siteler Aras\u0131 \u0130stek Sahtecili\u011fini kullanma yollar\u0131, sorunlar ve \u00e7\u00f6z\u00fcmleri<\/h2>\n<h3>Kullan\u0131m Y\u00f6ntemleri<\/h3>\n<ol>\n<li>Yetkisiz Hesap \u0130\u015flemleri: Sald\u0131rganlar, kullan\u0131c\u0131lar\u0131 hesap ayarlar\u0131n\u0131 veya \u015fifrelerini de\u011fi\u015ftirmeleri i\u00e7in kand\u0131rabilir.<\/li>\n<li>Finansal \u0130\u015flemler: CSRF, yetkisiz fon transferlerini veya sat\u0131n al\u0131mlar\u0131n\u0131 kolayla\u015ft\u0131rabilir.<\/li>\n<li>Veri Manip\u00fclasyonu: Sald\u0131rganlar uygulama i\u00e7indeki kullan\u0131c\u0131 verilerini de\u011fi\u015ftirir veya siler.<\/li>\n<\/ol>\n<h3>\u00c7\u00f6z\u00fcmler ve \u00d6nleme<\/h3>\n<ol>\n<li>CSRF Tokenlar\u0131: Me\u015fruiyetini do\u011frulamak i\u00e7in her iste\u011fe benzersiz tokenlar uygulay\u0131n.<\/li>\n<li>SameSite \u00c7erezleri: \u00c7erez kapsam\u0131n\u0131 k\u0131s\u0131tlamak i\u00e7in SameSite niteliklerini kullan\u0131n.<\/li>\n<li>\u00d6zel \u0130stek Ba\u015fl\u0131klar\u0131: \u0130stekleri do\u011frulamak i\u00e7in \u00f6zel ba\u015fl\u0131klar ekleyin.<\/li>\n<li>\u00c7ift G\u00f6nderim \u00c7erezleri: Belirte\u00e7 de\u011feriyle e\u015fle\u015fen ikincil bir \u00e7erez ekleyin.<\/li>\n<\/ol>\n<h2>Ana \u00f6zellikler ve benzer terimlerle kar\u015f\u0131la\u015ft\u0131rmalar<\/h2>\n<table>\n<thead>\n<tr>\n<th>Terim<\/th>\n<th>Tan\u0131m<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Siteler Aras\u0131 Komut Dosyas\u0131 \u00c7al\u0131\u015ft\u0131rma (XSS)<\/td>\n<td>Di\u011fer kullan\u0131c\u0131lar taraf\u0131ndan g\u00f6r\u00fcnt\u00fclenen web sayfalar\u0131na k\u00f6t\u00fc ama\u00e7l\u0131 komut dosyalar\u0131 yerle\u015ftirmeye odaklan\u0131r.<\/td>\n<\/tr>\n<tr>\n<td>Siteler Aras\u0131 \u0130stek Sahtecili\u011fi<\/td>\n<td>Yetkisiz istekleri y\u00fcr\u00fctmek i\u00e7in kullan\u0131c\u0131n\u0131n g\u00fcveninden yararlanarak durumu de\u011fi\u015ftiren eylemleri hedefler.<\/td>\n<\/tr>\n<tr>\n<td>Siteler Aras\u0131 Komut Dosyas\u0131 Ekleme<\/td>\n<td>Harici bir etki alan\u0131ndan gelen k\u00f6t\u00fc ama\u00e7l\u0131 komut dosyalar\u0131n\u0131n hedeflenen bir web uygulamas\u0131na dahil edilmesini i\u00e7erir.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Siteler Aras\u0131 Talep Sahtecili\u011fine ili\u015fkin gelece\u011fin perspektifleri ve teknolojileri<\/h2>\n<p>Web teknolojileri geli\u015ftik\u00e7e CSRF sald\u0131r\u0131lar\u0131na kar\u015f\u0131 koymak i\u00e7in yeni savunma mekanizmalar\u0131n\u0131n ortaya \u00e7\u0131kmas\u0131 muhtemeldir. Biyometri, tokenizasyon ve \u00e7ok fakt\u00f6rl\u00fc kimlik do\u011frulaman\u0131n entegrasyonu kullan\u0131c\u0131 do\u011frulamas\u0131n\u0131 g\u00fc\u00e7lendirebilir. Ek olarak, CSRF a\u00e7\u0131klar\u0131n\u0131 otomatik olarak alg\u0131layan ve \u00f6nleyen taray\u0131c\u0131 g\u00fcvenli\u011fi geli\u015ftirmeleri ve \u00e7er\u00e7eveleri, gelecekteki tehditlerin azalt\u0131lmas\u0131nda \u00f6nemli bir rol oynayacakt\u0131r.<\/p>\n<h2>Proxy sunucular\u0131 Siteler Aras\u0131 \u0130stek Sahtecili\u011fi ile nas\u0131l ili\u015fkilendirilebilir?<\/h2>\n<p>Proxy sunucular\u0131, kullan\u0131c\u0131lar ve web uygulamalar\u0131 aras\u0131nda arac\u0131 g\u00f6revi g\u00f6r\u00fcr. CSRF ba\u011flam\u0131nda, proxy sunucular, kullan\u0131c\u0131 isteklerinin do\u011frulanmas\u0131nda ek karma\u015f\u0131kl\u0131\u011fa neden olabilir ve CSRF g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 potansiyel olarak azaltabilir veya \u015fiddetlendirebilir. D\u00fczg\u00fcn yap\u0131land\u0131r\u0131lm\u0131\u015f proxy sunucular\u0131, gelen istekleri filtreleyip do\u011frulayarak ekstra bir g\u00fcvenlik katman\u0131 ekleyebilir ve CSRF sald\u0131r\u0131lar\u0131 riskini azaltabilir.<\/p>\n<h2>\u0130lgili Ba\u011flant\u0131lar<\/h2>\n<p>Siteler Aras\u0131 \u0130stek Sahtecili\u011fi ve web uygulamas\u0131 g\u00fcvenli\u011fi hakk\u0131nda daha fazla bilgi i\u00e7in a\u015fa\u011f\u0131daki kaynaklara bak\u0131n:<\/p>\n<ol>\n<li><a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html\" target=\"_new\" rel=\"noopener nofollow\">OWASP CSRF \u00d6nleme Hile Sayfas\u0131<\/a><\/li>\n<li><a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Glossary\/CSRF\" target=\"_new\" rel=\"noopener nofollow\">Mozilla Geli\u015ftirici A\u011f\u0131 \u2013 Siteler Aras\u0131 \u0130stek Sahtecili\u011fi (CSRF)<\/a><\/li>\n<li><a href=\"https:\/\/portswigger.net\/web-security\/csrf\" target=\"_new\" rel=\"noopener nofollow\">PortSwigger \u2013 Siteler Aras\u0131 \u0130stek Sahtecili\u011fi (CSRF)<\/a><\/li>\n<li><a href=\"https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet\" target=\"_new\" rel=\"noopener nofollow\">Siteler Aras\u0131 Talep Sahtecili\u011fi \u0130ncili<\/a><\/li>\n<\/ol>","protected":false},"featured_media":476482,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-476481","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Cross-Site Request Forgery (CSRF) - A Comprehensive Guide<\/mark>","faq_items":[{"question":"What is Cross-Site Request Forgery (CSRF)?","answer":"<p>Cross-Site Request Forgery (CSRF) is a type of web security vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users without their knowledge. It exploits the trust between a user's browser and a web application to trick the application into accepting malicious requests.<\/p>"},{"question":"How did CSRF originate, and when was it first mentioned?","answer":"<p>The term \"Cross-Site Request Forgery\" was coined in 2001, but the concept of similar attacks was known since the mid-1990s. Researchers first mentioned a vulnerability in the Netscape Navigator browser that allowed attackers to forge HTTP requests back in 1996.<\/p>"},{"question":"How does CSRF work?","answer":"<p>CSRF attacks involve the following steps:<\/p><ol><li>The user logs into a web application and receives an authentication token.<\/li><li>While the user is still logged in, they visit a malicious website or click on a malicious link.<\/li><li>The malicious website sends a crafted HTTP request to the target application using the user's credentials.<\/li><li>The target application processes the request as if it came from the legitimate user, performing the malicious action.<\/li><\/ol>"},{"question":"What are the key features of CSRF attacks?","answer":"<p>Key features of CSRF attacks include:<\/p><ol><li>Invisible Exploitation: CSRF attacks occur without the user's awareness.<\/li><li>Reliance on User Trust: The attacks rely on the trust between the user's browser and the application.<\/li><li>Session-Based: CSRF attacks depend on active user sessions.<\/li><li>Impactful Actions: The attacks target state-changing operations with significant consequences.<\/li><\/ol>"},{"question":"What types of CSRF attacks exist?","answer":"<p>There are several types of CSRF attacks, including:<\/p><ol><li>Simple CSRF: A single forged request is sent to the target application.<\/li><li>Blind CSRF: The attacker sends a crafted request without obtaining the response.<\/li><li>CSRF with XSS: Attackers combine CSRF with Cross-Site Scripting to execute malicious scripts.<\/li><li>CSRF with JSON endpoints: Targeting applications using JSON endpoints, attackers manipulate JSON data for CSRF.<\/li><\/ol>"},{"question":"How can CSRF be prevented and mitigated?","answer":"<p>Preventing and mitigating CSRF attacks involve implementing various techniques, such as:<\/p><ol><li>CSRF Tokens: Use unique tokens in each request to validate its legitimacy.<\/li><li>SameSite Cookies: Utilize SameSite attributes in cookies to restrict their scope.<\/li><li>Custom Request Headers: Add custom headers to validate requests.<\/li><li>Double Submit Cookies: Include a secondary cookie that matches the token value.<\/li><\/ol>"},{"question":"How does CSRF compare to other web vulnerabilities?","answer":"<p>CSRF differs from other web vulnerabilities like Cross-Site Scripting (XSS) and Cross-Site Script Inclusion (XSSI). While XSS focuses on injecting malicious scripts into web pages, CSRF targets state-changing actions by exploiting user trust.<\/p>"},{"question":"What does the future hold for CSRF defense?","answer":"<p>As web technologies evolve, new defense mechanisms, including biometrics, tokenization, and multi-factor authentication, will emerge to counter CSRF attacks. Browser security enhancements and frameworks detecting and preventing CSRF vulnerabilities will play vital roles in mitigating future threats.<\/p>"},{"question":"How are proxy servers associated with CSRF?","answer":"<p>Proxy servers act as intermediaries between users and web applications. In the context of CSRF, they can add an extra layer of security by filtering and validating incoming requests, reducing the risk of CSRF attacks. Properly configured proxy servers can enhance web application security.<\/p>"},{"question":"Where can I find more information about CSRF?","answer":"<p>For more in-depth knowledge about CSRF and web application security, refer to the following resources:<\/p><ol><li><a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html\" target=\"_new\">OWASP CSRF Prevention Cheat Sheet<\/a><\/li><li><a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Glossary\/CSRF\" target=\"_new\">Mozilla Developer Network - Cross-Site Request Forgery (CSRF)<\/a><\/li><li><a href=\"https:\/\/portswigger.net\/web-security\/csrf\" target=\"_new\">PortSwigger - Cross-Site Request Forgery (CSRF)<\/a><\/li><li><a href=\"https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet\" target=\"_new\">The Cross-Site Request Forgery Bible<\/a><\/li><\/ol>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/wiki\/476481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/wiki\/476481\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/media\/476482"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/media?parent=476481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}