Cross site request forgery

 Hey guys how are you, today we're going to discuss about cross site request forgery. so without doing further delay let's get started.

What is csrf?

Cross-site request forgery attacks (CSRF or XSRF for short) are used to send malicious requests from an authenticated user to a web application. 

When a website requests data from another website on behalf of a user, there are no security concerns as long as the request is unauthenticated, i.e. the session cookie is not sent. However, when the user’s session cookie is sent with the request, attackers can launch a cross-site request forgery attack that abuses the trust relationship between the victim’s browser and the web server.

Combined with social engineering to persuade users to open a malicious link, CSRF attacks can have serious consequences.

An attacker’s aim for carrying out a CSRF attack is to force the user to submit a state-changing request

Examples :

Submitting or deleting a record.

Submitting a transaction.

Purchasing a product.

Changing a password.

Sending a message.

Social engineering platforms are often used by attackers to launch a CSRF attack.

Want to understand in depth, what csrf is?

Do watch this video:

https://youtu.be/0OQ3Ajac5xU

How to do this attack?

For this do watch this video:

https://youtu.be/AHV9ThkRT9w

That's all for today guys and also don't forget to follow us on Instagram and GitHub and do like our content on Instagram:

https://instagram.com/__pytools__

https://GitHub.com/pytools786





Comments

Popular posts from this blog

what is log4j vulnerability

Secure your system from Pegasus spyware

Recovering all the saved passwords from target system using lazagne