Understanding CSRF

后端 未结 4 924
不知归路
不知归路 2020-12-01 06:06

I don\'t understand how using a \'challenge token\' would add any sort of prevention: what value should compared with what?

From OWASP:

In gen

4条回答
  •  一个人的身影
    2020-12-01 07:05

    The attacker has no way to get the token. Therefore the requests won't take any effect.

    I recommend this post from Gnucitizen. It has a pretty decent CSRF explanation: http://www.gnucitizen.org/blog/csrf-demystified/

提交回复
热议问题