1/13
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the first step in a typical CSRF attack?
The victim logs into a vulnerable web application, such as a bank.
A victim is logged into a bank in one browser session and then visits a malicious website. Why is this important for CSRF?
The victim's authenticated session is still active, allowing the browser to potentially send authenticated requests to the bank.
How can a malicious website trigger a forged CSRF request?
It can contain code, such as JavaScript, that automatically submits the forged request.
Why can the browser authenticate a forged CSRF request?
Because the victim is already authenticated to the target application, the browser may automatically include their valid session cookies.
What happens when the vulnerable application receives a forged CSRF request?
It may process the request as a legitimate action initiated by the authenticated victim.
Put the basic CSRF process in the correct order.
1) Victim logs in → 2) Visits malicious site/link → 3) Malicious code submits forged request → 4) Browser includes session cookies → 5) Vulnerable application processes the request.
A user is logged into their bank, visits an attacker's website, and JavaScript causes a money-transfer request to be sent automatically. What attack is this?
Cross-Site Request Forgery (CSRF).
In the CSRF process, what does the malicious website actually send?
A forged request intended for the vulnerable web application.
What does the victim's browser contribute to a CSRF attack?
It sends the forged request in the context of the victim's authenticated session, including valid session credentials such as cookies when applicable.
What does XSS exploit compared with CSRF?
XSS exploits the trust a user has in a particular website, while CSRF exploits the trust a website has in a particular user's authenticated browser.
A malicious script is injected into a trusted website and executes in a victim's browser. Which attack is this?
Cross-Site Scripting (XSS).
A malicious site tricks a victim's browser into performing an action on another site where the victim is already logged in. Which attack is this?
CSRF.
What is the key difference between XSS and CSRF?
XSS attacks the user's interaction with a trusted website by injecting script, while CSRF tricks the user's authenticated browser into sending an unauthorized request to a trusted website.
Why does CSRF generally require an authenticated victim?
The target application needs to recognize the forged request as coming from an authenticated user.