ASP.NET Core Security: Preventing CSRF and XSRF Attacks
Learn to secure your ASP.NET Core applications and APIs against Cross-Site Request Forgery using modern antiforgery tokens and defense-in-depth practices.
-
💬
ผู้สอน AI
ถามเกี่ยวกับบทเรียนใดก็ได้ แล้วรับคำตอบที่ชัดเจนทันที ทุกเมื่อ -
🕐
เริ่มเมื่อไรก็ได้
ไม่มีตารางหรือเดดไลน์ — เรียนตามจังหวะของคุณ เมื่อไรก็ได้ -
🌐
เป็นภาษาไทย
บทเรียน แบบฝึกหัด และใบรับรอง — ทั้งหมดเป็นภาษาของคุณอย่างครบถ้วน
เกี่ยวกับคอร์สนี้
Web security is a critical priority for any developer, yet Cross-Site Request Forgery (CSRF/XSRF) remains a common vulnerability that can compromise user accounts and data. Understanding how to block these unauthorized commands is essential for building trustworthy web applications. In this comprehensive text-based course, you will learn how to implement robust defense mechanisms in ASP.NET Core. You will progress from understanding the mechanics of a CSRF attack to configuring built-in antiforgery validation for both traditional MVC forms and modern API endpoints. What you'll learn: Understand the core concepts of CSRF and XSRF vulnerability mechanics; Configure automatic and manual antiforgery token validation in ASP.NET Core; Implement secure cookie attributes including SameSite, HttpOnly, and Secure; Handle antiforgery tokens in modern JavaScript clients for secure API requests; Apply defense-in-depth strategies with custom security headers and CORS policies; Troubleshoot common validation errors and token mismatch issues during development. The course begins with foundational web security concepts and threat modeling, then guides you through step-by-step configuration of antiforgery middleware, and concludes with securing modern web architectures. This course is designed for beginner-to-intermediate web developers looking to fortify their applications. No prior security experience is required, though a basic familiarity with C# and web concepts is helpful. Start reading today to master essential ASP.NET Core security practices and protect your users from malicious exploits.
สิ่งที่คุณจะได้รับ
-
📜
ใบประกาศนียบัตร
เพิ่มในโปรไฟล์ LinkedIn ของคุณ -
💬
ติวเตอร์ AI ส่วนตัว
ติดขัดในบทเรียน? ถามติวเตอร์ในตัวของคุณได้ทุกอย่าง ทุกเวลา -
🎧
รวมเวอร์ชันเสียง
เรียนได้ทุกที่ ไม่ต้องดูจอ -
♾️
เข้าถึงตลอดชีพ
กลับมาเรียนได้ตลอด ไม่มีหมดอายุ -
📱
โทรศัพท์หรือคอมพิวเตอร์
ใช้งานได้ทุกที่ ทุกอุปกรณ์ -
💸
คืนเงิน 14 วัน
ไม่ต้องอธิบาย -
⚡
กระชับและตรงประเด็น
3 ชม. เนื้อหาเชิงปฏิบัติ
รีวิว
ยังไม่มีรีวิว — เป็นคนแรกที่แชร์ประสบการณ์
ผู้เรียนคนอื่นเรียน
🎓 มีใบรับรอง
ออกแบบแอพพลิเคชัน.NET Core MVC ด้วยสถาปัตยกรรมที่สะอาด
ใบรับรอง
ลงมือทำ
฿1,800
→
🎓 มีใบรับรอง
การพัฒนา ASP.NET Core Web API: สร้างบริการ RESTful ที่ปลอดภัย
ใบรับรอง
ลงมือทำ
฿1,800
→
🔥 เป็นที่ต้องการ
🎓 มีใบรับรอง
อีคอมเมิร์ซแบบฟูลสแตกด้วย Blazor WebAssembly และ .NET
ใบรับรอง
ลงมือทำ
฿1,800
→
🔥 เป็นที่ต้องการ
🎓 มีใบรับรอง
การพัฒนาเว็บด้วย Wix และ Velo: สร้างเว็บไซต์กระดานงาน
ใบรับรอง
ลงมือทำ
฿1,800
→
คำถามที่พบบ่อย
ฉันต้องใช้อะไรในการเรียนคอร์สนี้? +
แค่โทรศัพท์หรือคอมพิวเตอร์ที่มีอินเทอร์เน็ต ไม่ต้องติดตั้งหรือใช้อุปกรณ์พิเศษ
ฉันชำระเงินอย่างไร? +
ผ่านบัตรด้วย Stripe เราไม่เก็บข้อมูลบัตร — Stripe จัดการอย่างปลอดภัย
ฉันขอคืนเงินได้ไหม? +
ใช่ — คืนเงินเต็มจำนวนใน 14 วัน ไม่ต้องอธิบาย
ฉันมีสิทธิ์เข้าถึงนานเท่าไร? +
ตลอดไป เมื่อซื้อแล้วคอร์สเป็นของคุณ กลับมาเรียนได้ตลอด
ฉันจะได้ใบประกาศนียบัตรไหม? +
ได้ เมื่อเรียนจบจะได้รับใบประกาศนียบัตรที่เพิ่มในโปรไฟล์ LinkedIn ได้
ออกแบบสำหรับผู้เรียนใน
เทคโนโลยี
ดีไซน์
การเงิน
การตลาด
สาธารณสุข
การศึกษา
ธุรกิจการบริการ
อุตสาหกรรม
×2
เติมครั้งเดียว จ่ายครึ่งเดียว
เพิ่ม ฿3,600 → รับเครดิต 200 เครดิต ทำให้แต่ละหลักสูตรมีราคาประมาณ ฿450.00 เครดิตไม่มีวันหมดอายุ
฿3,600
200 เครดิต
฿450.00 / คอร์ส
คุ้มที่สุด
฿9,000
550 เครดิต
฿409.09 / คอร์ส
฿18,000
1200 เครดิต
฿375.00 / คอร์ส
เครดิตใช้ได้กับทุกคอร์สและไม่หมดอายุ