Thursday, June 5, 2008


At the OWASP conference in San Jose last year, the Java OWASP CSRFGuard was presented and I met Eric Sheridan, its author. I noted that there was not an analogue for .Net so I started coding right then.

Well, it's been a hobby project for some time. Eric and I have gone back and forth with design/feature ideas and are working toward feature-equivalent solutions for each language, albeit implemented within the appropriate language paradigms.

I have been coding away for the past several weeks, whittling down my TODO list, and am ready to release an alpha version soon. I need to figure out some logistical issues and get the assembly a strong name so it can be installed in the GAC. So, check it out and watch this space for the release announcement.

I also have lots of work to do to flesh out the full documentation on the wiki page.

.Net CSRF Guard - OWASP

