Anatomy of a Cross-site Request Forgery Attack
Posted by: youve been HAACKED,
on 02 Apr 2009 |
View original | Bookmarked: 0 time(s)
A Cross-site request forgery attack, also known as CSRF or XSRF (pronounced sea-surf) is the less well known, but equally dangerous, cousin of the Cross Site Scripting (XSS) attack. Yeah, they come from a rough family. CSRF is a form of confused deputy attack. Imagine youre a malcontent who wants to harm another person in a maximum security jail. Youre probably going to have a tough time reaching that person due to your lack of proper credentials. A potentially easier approach to accomplish your...