官术网_书友最值得收藏!

GET CSRF

The applications could call the methods using an HTTP GET request. In this case, you will see when an external resource will be called in the HTTP proxy. It is important to pay attention to the information sent by the HTTP headers, because all of the parameters sent in the request could be used by the method, for example:

https://www.mysocialnetwork.com/process.php?from=rick&to=morty&credits=10008000

In this URL, we can see that the application is sending all of the parameters directly. So, we do not need any additional parameters; the important thing is to execute the request. To do that, the most common method is to include the request in an <img> tag without the user knowing it, for example, in an external website:

<img src=" https://www.mysocialnetwork.com/process.php?from=rick&to=morty&credits=10008000">

The result is that when the <img> tag is parsed by the browser, the request is made, and the attack is executed. You can use other tags, even JavaScript.

主站蜘蛛池模板: 天柱县| 余姚市| 祁东县| 呈贡县| 日喀则市| 和平县| 留坝县| 雷州市| 青岛市| 襄垣县| 岳池县| 手游| 会理县| 鸡西市| 洛扎县| 成武县| 承德市| 墨竹工卡县| 浦江县| 翼城县| 涪陵区| 克什克腾旗| 醴陵市| 宾川县| 娄烦县| 扎赉特旗| 克山县| 海安县| 南丰县| 鹤山市| 尉犁县| 江华| 永年县| 乌审旗| 交城县| 乐清市| 阜新| 天柱县| 武陟县| 西城区| 辰溪县|