官术网_书友最值得收藏!

GET CSRF

The applications could call the methods using an HTTP GET request. In this case, you will see when an external resource will be called in the HTTP proxy. It is important to pay attention to the information sent by the HTTP headers, because all of the parameters sent in the request could be used by the method, for example:

https://www.mysocialnetwork.com/process.php?from=rick&to=morty&credits=10008000

In this URL, we can see that the application is sending all of the parameters directly. So, we do not need any additional parameters; the important thing is to execute the request. To do that, the most common method is to include the request in an <img> tag without the user knowing it, for example, in an external website:

<img src=" https://www.mysocialnetwork.com/process.php?from=rick&to=morty&credits=10008000">

The result is that when the <img> tag is parsed by the browser, the request is made, and the attack is executed. You can use other tags, even JavaScript.

主站蜘蛛池模板: 吴江市| 瓦房店市| 许昌市| 衡阳市| 景德镇市| 康乐县| 平昌县| 泗水县| 南平市| 灌阳县| 蒙山县| 黄骅市| 鸡泽县| 象州县| 马山县| 施甸县| 同心县| 凌云县| 密云县| 泗水县| 津南区| 高碑店市| 乳山市| 时尚| 龙口市| 丹江口市| 乐昌市| 明溪县| 蓝山县| 博白县| 那曲县| 无为县| 乌恰县| 大田县| 论坛| 卢氏县| 海城市| 湖州市| 句容市| 六盘水市| 桃源县|