Anatomy of a Cross-site Request Forgery Attack

Posted by: youve been HAACKED, on 02 Apr 2009 | View original | Bookmarked: 0 time(s)

A Cross-site request forgery attack, also known as CSRF or XSRF (pronounced sea-surf) is the less well known, but equally dangerous, cousin of the Cross Site Scripting (XSS) attack. Yeah, they come from a rough family. CSRF is a form of confused deputy attack. Imagine youre a malcontent who wants to harm another person in a maximum security jail. Youre probably going to have a tough time reaching that person due to your lack of proper credentials. A potentially easier approach to accomplish your...

Advertisement
Free Agile Project Management Tool from Telerik
TeamPulse Community Edition helps your team effectively capture requirements, manage project plans, assign and track work, and most importantly, be continually connected with each other.
Category: JavaScript | Other Posts: View all posts by this blogger | Report as irrelevant | View bloggers stats | Views: 1289 | Hits: 91

Similar Posts

  • How to Make crossdomain.xml Work with SharePoint more
  • IIS Security Settings for Silverlight 2.0 more
  • CSRF Attacks and Web Forms more
  • Twitter API - Submit a post in C# more
  • Update to SharePoint SSL Switching HttpModule more
  • Brokered authentication for REST active clients with SAML more
  • Script for Bulk Import of Active Directory Site Links more
  • Script for Bulk Import of Active Directory Subnets more
  • Silverlight Crossdomain Access Workarounds more
  • XM Radio Player Part II : Scraping more

News Categories

.NET | Agile | Ajax | Architecture | ASP.NET | BizTalk | C# | Certification | Data | DataGrid | DataSet | Debugger | DotNetNuke | Events | GridView | IIS | Indigo | JavaScript | Mobile | Mono | Patterns and Practices | Performance | Podcast | Refactor | Regex | Security | Sharepoint | Silverlight | Smart Client Applications | Software | SQL | VB.NET | Visual Studio | W3 | WCF | WinFx | WPF | WSE | XAML | XLinq | XML | XSD