Don't Trust, Verify! - How I Found a CSRF Bug Hiding in Plain Sight

No ratings

Presented at BSides SF 2025 by

This talk explores the discovery of a long-standing CSRF (Cross-Site Request Forgery) vulnerability in the popular gorilla/csrf Go library. The goal is to encourage the audience to perform vulnerability research experiments in their own commonly used tools.