Cross-site Request Forgery (CSRF) Attack Demo

preview_player
Показать описание

The slides themselves are creative commons licensed CC-BY-SA, and images used are licensed as individually attributed.
Рекомендации по теме
Комментарии
Автор

instead of csrf tokens, will having user enter current password on these forms safe?

moosegoose
Автор

Wow, just a question, who uses a GET request nowadays to change passwords haha, are you stoned or what???

gavriel_adi