A brief introduction to cross-site forgery of CSRF request
First, what is CSRF:
As shown in the figure:
1. Users normally visit websites with CSRF vulnerabilities through browsers.
If I go to visit http://127.0.0.1:8080/DVWA/login.php
We log in to the account: admin password is: password, find a place to change the password
Change the password to 123456, and the modified url is:
Http://127.0.0.1:8080/DVWA/vulnerabilities/csrf/password_new=123456&password_conf=123456&Change=Change#
2. We construct a malicious website B to save the code as index.html
This is a malicious web page.
We visit the website B: click *
We can see that the password has been changed (changed to password)
Defense:
1. Try to use POST and limit GET
two。 Browser Cookie policy
3.Anti CSRF Token
Official account of Wechat: