DFIELDSOLUTIONS

Security

GlossaryCSRF

Cross-site request forgery — tricking a logged-in browser into sending a request the user never meant, riding on their cookies.

Browsers attach cookies to every request to a domain — including requests a hostile page causes. If example.com/evil submits a hidden form to bank.com/transfer while the victim is logged in, the bank sees a perfectly authenticated request. The browser cannot tell intent, only credentials.

The standard defences are CSRF tokens (a secret the real page knows and forgeries do not), SameSite cookies, and checking the Origin header. Modern frameworks ship most of it; the vulnerability survives where hand-rolled endpoints quietly skip it.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain