Update article.md
This commit is contained in:
parent
a38ab40724
commit
3d4a5ccd43
1 changed files with 1 additions and 1 deletions
|
@ -192,7 +192,7 @@ To understand how it works and when it's useful, let's take a look at XSRF attac
|
|||
|
||||
Imagine, you are logged into the site `bank.com`. That is: you have an authentication cookie from that site. Your browser sends it to `bank.com` with every request, so that it recognizes you and performs all sensitive financial operations.
|
||||
|
||||
Now, while browsing the web in another window, you occasionally come to another site `evil.com`. That site has JavaScript code that submits a form `<form action="https://bank.com/pay">` to `bank.com` with fields that initiate a transaction to the hacker's account.
|
||||
Now, while browsing the web in another window, you accidentally come to another site `evil.com`. That site has JavaScript code that submits a form `<form action="https://bank.com/pay">` to `bank.com` with fields that initiate a transaction to the hacker's account.
|
||||
|
||||
The browser sends cookies every time you visit the site `bank.com`, even if the form was submitted from `evil.com`. So the bank recognizes you and actually performs the payment.
|
||||
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue