Cross site request forgery
Hey guys how are you, today we're going to discuss about cross site request forgery. so without doing further delay let's get started.
What is csrf?
Cross-site request forgery attacks (CSRF or XSRF for short) are used to send malicious requests from an authenticated user to a web application.
When a website requests data from another website on behalf of a user, there are no security concerns as long as the request is unauthenticated, i.e. the session cookie is not sent. However, when the user’s session cookie is sent with the request, attackers can launch a cross-site request forgery attack that abuses the trust relationship between the victim’s browser and the web server.
Combined with social engineering to persuade users to open a malicious link, CSRF attacks can have serious consequences.
An attacker’s aim for carrying out a CSRF attack is to force the user to submit a state-changing request.
Examples :
Submitting or deleting a record.
Submitting a transaction.
Purchasing a product.
Changing a password.
Sending a message.
Social engineering platforms are often used by attackers to launch a CSRF attack.
Want to understand in depth, what csrf is?
Do watch this video:
How to do this attack?
For this do watch this video:
That's all for today guys and also don't forget to follow us on Instagram and GitHub and do like our content on Instagram:
https://instagram.com/__pytools__
Comments
Post a Comment