Author: you've been HAACKED | Posted on: 4/2/2009 11:30:10 AM | Views : 1128

A Cross-site request forgery attack, also known as CSRF or XSRF (pronounced sea-surf) is the less well known, but equally dangerous, cousin of the Cross Site Scripting (XSS) attack. Yeah, they come from a rough family. CSRF is a form of confused deputy attack . Imagine you?re a malcontent who wants to harm another person in a maximum security jail. You?re probably going to have a tough time reaching that person due to your lack of proper credentials. A potentially easier approach to accomplish your misdeed is to confuse a deputy to misuse his authority to commit the dastardly act on your behalf. That?s a much more effective strategy for causing mayhem! In the case of a CSRF attack, the confused deputy is your browser. After logging into a typical...(read more) ...

Go to the complete details ...