Definition. CSRF (Cross-Site Request Forgery) is an attack that forces authenticated users to send a request to a Web application to which they are already authenticated. CSRF attacks take advantage of a Web application's trust in a logged-in user.
A successful CSRF attack has the potential to be disastrous for both the organisation and the user. Client relationships may be harmed, funds transferred without authorization, passwords changed, and data taken, including session cookies.
In a successful CSRF attack, the attacker makes the victim user accidentally do an action. This could be to update their account's email address, reset their password, or make a money transfer, for example.
CSRF can be avoided by using a hidden field to create a unique token that is transmitted in the body of the HTTP request rather than in the URL, which is more vulnerable to disclosure. To protect against CSRF, the user must be forced to re-authenticate or prove that they are users. Take, for instance, CAPTCHA.
A successful CSRF attack has the potential to be disastrous for both the organisation and the user. Client relationships may be harmed, funds transferred without authorization, passwords changed, and data taken, including session cookies.
Learner's Ratings
4.5
Overall Rating
80%
7%
5%
1%
7%
Reviews
V
Vinayak Mulay
4
From where and how can we download notes of these terminologies?
R
Rahul
5
Hum es course se bhut kuch sikh paye hai aur khash kr sir se smjhane ka jo concept hai o hme bhut hi acha lga
N
Nitin Kumar
5
Best 👌
M
Meet
5
Best curs
Best hecking methad
Good job 👍
S
Samuel Thompson
4
I want to humbly appeal on our behalf, the English speaker for help in subtitle the spoken words in English. Please make available English subtitles for us, because we really need to get this knowledg
G
Govinda Gupta
5
Good
R
Ramesh
5
Excellent course and trainer are very intelligent person 🙏❤️❤️
A
Arshad Husain
5
good
A
Abhishek Tiwari
5
sir mai ethical hacking se ghar bhata paisa kama sakta hu
S
sakib ansari
5
air jo apne arp spoofing main jo cod dala tha wo kark hi nhi kar raha jo apne likha tha cat /proc/sys/net/ipv4/ip_forward not work sir
Show More
Recommended Courses
Cyber Forensics Masterclass with Hands on learning
Share a personalized message with your friends.