官术网_书友最值得收藏!

GET CSRF

The applications could call the methods using an HTTP GET request. In this case, you will see when an external resource will be called in the HTTP proxy. It is important to pay attention to the information sent by the HTTP headers, because all of the parameters sent in the request could be used by the method, for example:

https://www.mysocialnetwork.com/process.php?from=rick&to=morty&credits=10008000

In this URL, we can see that the application is sending all of the parameters directly. So, we do not need any additional parameters; the important thing is to execute the request. To do that, the most common method is to include the request in an <img> tag without the user knowing it, for example, in an external website:

<img src=" https://www.mysocialnetwork.com/process.php?from=rick&to=morty&credits=10008000">

The result is that when the <img> tag is parsed by the browser, the request is made, and the attack is executed. You can use other tags, even JavaScript.

主站蜘蛛池模板: 馆陶县| 山东省| 绥棱县| 兰坪| 花莲县| 长沙市| 和田市| 乳山市| 赞皇县| 新宁县| 安国市| 历史| 罗田县| 理塘县| 太仆寺旗| 永善县| 宁德市| 凤城市| 太和县| 温泉县| 临安市| 定兴县| 枣阳市| 长葛市| 平武县| 靖州| 新营市| 花莲县| 广西| 来安县| 赤水市| 河西区| 东丽区| 洞头县| 丹江口市| 从江县| 陆丰市| 应城市| 景德镇市| 土默特右旗| 英德市|