Let's talk about your project

Cross-site request forgery

CSRF · Forcing a signed-in user's browser to send a request without the user's knowledge, through a link or form on another site.

  1. 01

    Why it matters

    The browser automatically adds the session cookie to every request to a site. If the site does not check that a request really came from the user's own screen, another page can change a password, update an address or start a transfer in the user's name. Per-form tokens and correctly configured cookies prevent this.

  2. 02

    Example

    An admin panel's change-email form has no verification token. While signed in, the administrator clicks a link shared on a forum; in the background the account's e-mail is changed to the attacker's.

  3. 03

    Common mistake

    Performing important actions through links that work from the address bar. Every state-changing action should be a form submission protected by a token, with re-authentication for critical ones.

  4. 04
Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.