paint-brush
Glossary of Security Terms: CSRFby@mozilla
173 reads

Glossary of Security Terms: CSRF

by Mozilla ContributorsAugust 22nd, 2020
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

CSRF (Cross-Site Request Forgery) is an attack that impersonates a trusted user and sends unwanted commands. This can be done, for example, by including malicious parameters in a URL behind a link that purports to go somewhere else:https://www.example.com.com: For users who have some permissions on the website, the element will execute action on the site without their noticed. There are many ways to prevent CSRF, such as implement RESTful API, add secure token, etc.

Company Mentioned

Mention Thumbnail
featured image - Glossary of Security Terms: CSRF
Mozilla Contributors HackerNoon profile picture

CSRF (Cross-Site Request Forgery) is an attack that impersonates a trusted user and sends a website unwanted commands. This can be done, for example, by including malicious parameters in a URL behind a link that purports to go somewhere else:

<img src="https://www.example.com/index.php?action=delete&id=123">

For users who have some permissions on

https://www.example.com
, the
<img>
element will execute action on
https://www.example.com
without their noticed, even if the element is not at
https://www.example.com
.

There are many ways to prevent CSRF, such as implement RESTful API, add secure token, etc.

Learn more

General knowledge

 View Previous Terms:

    Credits