web安全
Cross Site Request Forgery (CSRF) 跨站请求伪造. 攻击例子 考虑以下请求, 登陆后通过下面的请求进行转账操作. POST /transfer HTTP/1.1 Host: bank.example.com Cookie: JSESSIONID=randomid; Domain=bank.example.com; Secure; HttpOnly Content-Type: application/x-www-form-urlencoded amount=100.00&routingNumber=1234&account=9876 如果在没有退出登陆的情况下,登陆了另外一个网站,在网站中有如下一个按钮: <form action="https://bank.example.com/transfer" method="post"> <input type="hidden" name="amount" value="100.00"/> <input type="hidden" name="routingNumber" value="evilsRoutingNumber"/> <input type="hidden" name="account" value="evilsAccountNumber"/> <input type="submit" value