Deprecated: str_replace(): Passing null to parameter #3 ($subject) of type array|string is deprecated in /dom910795/wp-content/themes/sanigo/includes/functions/frontend-functions.php on line 1421

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: Implicit conversion from float 1.05 to int loses precision in /dom910795/wp-content/themes/sanigo/includes/functions/frontend-functions.php on line 611

Deprecated: Implicit conversion from float 116.05 to int loses precision in /dom910795/wp-content/themes/sanigo/includes/functions/frontend-functions.php on line 611

Deprecated: Implicit conversion from float 171.05 to int loses precision in /dom910795/wp-content/themes/sanigo/includes/functions/frontend-functions.php on line 611
What is CSRF? - Siza Technologies

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496
Placeholder image with abstract shapes and circle.

What is CSRF?


Cross site request forgery (CSRF) is one of the more creative cyber attacks affecting both individuals and businesses.

Say you logged into the website of the bank where you have your small business checking account. When you do this, the site will issue your web browser a cookie containing an authentication token. Every other request you make is allowed by the site as it understands that you are authorized to take this action. Now, without logging out of your account or with your session at the site still valid (this is rare), you visit a third-party website or click on a spam link. The site or link sends a request to your bank’s website without your knowledge. Your browser follows suit, sending the authentication cookie back to the site, appearing to making a request on your behalf.

If you visit a chat forum or a carefully designed malicious website, the HTML image elements or image tags such as one below can enable the unwanted action.

There is no evidence of the attack as the forged request has all the information and originates from the same IP address as an authentic request from you. CSRF is usually employed to transfer money from your bank account to another (the attacker’s) account. It can target your content management system to add or delete content from your website. The attack is quite prevalent in cases where you or your website’s users stay logged in for a long time.


Related Posts



Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496

Deprecated: ltrim(): Passing null to parameter #1 ($string) of type string is deprecated in /dom910795/wp-includes/formatting.php on line 4496