Get the App
SLTechnology News&Howtos  ›  Network Security  › 

A brief introduction to cross-site forgery of CSRF request

Shulou Source: shulou.com Published: 2022-06-01 01:20:55 10月04日 Update

First, what is CSRF:

As shown in the figure:

1. Users normally visit websites with CSRF vulnerabilities through browsers.

If I go to visit http://127.0.0.1:8080/DVWA/login.php

We log in to the account: admin password is: password, find a place to change the password

Change the password to 123456, and the modified url is:

Http://127.0.0.1:8080/DVWA/vulnerabilities/csrf/password_new=123456&password_conf=123456&Change=Change#

2. We construct a malicious website B to save the code as index.html

This is a malicious web page.

We visit the website B: click *

We can see that the password has been changed (changed to password)

Defense:

1. Try to use POST and limit GET

two。 Browser Cookie policy

3.Anti CSRF Token

Official account of Wechat:

Tags: Password malicious website browser web page this is browsing code public place vulnerability user policy account such as figure login defense restriction Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Redmi Shulou Tech Info Huawei MySQL MariaDB