
PagerDuty’s Security Training for Engineers, Penultimate
Coding Blocks
00:00
What's the Difference Between a Log Out and a Synchronizer Token?
request forging is all about getting the server to run some arbitrary script, or geting thi is about tricking the server into do something. The one thing that they said that they that they used is a synchronizer token. So if you were to disallow that log out to be called from a git then it wouldn't have affected you. But then to go further, this whole syncronization token was a sad ha.
Transcript
Play full episode