官术网_书友最值得收藏!

GET CSRF

The applications could call the methods using an HTTP GET request. In this case, you will see when an external resource will be called in the HTTP proxy. It is important to pay attention to the information sent by the HTTP headers, because all of the parameters sent in the request could be used by the method, for example:

https://www.mysocialnetwork.com/process.php?from=rick&to=morty&credits=10008000

In this URL, we can see that the application is sending all of the parameters directly. So, we do not need any additional parameters; the important thing is to execute the request. To do that, the most common method is to include the request in an <img> tag without the user knowing it, for example, in an external website:

<img src=" https://www.mysocialnetwork.com/process.php?from=rick&to=morty&credits=10008000">

The result is that when the <img> tag is parsed by the browser, the request is made, and the attack is executed. You can use other tags, even JavaScript.

主站蜘蛛池模板: 方山县| 临澧县| 苏尼特左旗| 金平| 兰考县| 青龙| 霍山县| 蛟河市| 新丰县| 仁寿县| 瑞安市| 雅江县| 镇雄县| 合水县| 宁蒗| 连江县| 嘉善县| 五大连池市| 岳阳市| 威海市| 通州市| 长丰县| 崇文区| 县级市| 子长县| 普安县| 深州市| 祁连县| 太和县| 石棉县| 安溪县| 城固县| 邵武市| 西和县| 兴安县| 商河县| 宜城市| 科尔| 灵石县| 邵阳市| 双峰县|