CSRF
cross site request forgery
Example¶
blog (or embedded element): click a link to
bank.com/transfer?to=124&amount=1000
already logged in to bank.com => it'll work
Avoiding a CSRF attack¶
- Same site cookie
- (Default is lax??)
- CSRF token
- hidden input in form
- Nonce
- HTTP only cookies
- Backend can check origin referrer header
- Captcha
Last update:
2023-04-24