SLIDE 1
How it works
1-user goes to evil.fish
2 - evil.fish includes form on bank.com
3 - form is submitted
- n bank.com
4 - bank.com helpfully transfers money into trout’s account
XSRF How it works 3 - form is submitted on bank.com 4 - bank.com - - PowerPoint PPT Presentation
XSRF How it works 3 - form is submitted on bank.com 4 - bank.com helpfully transfers money into trouts account 2 - evil.fish includes form on bank.com 1-user goes to evil.fish Defenses Form keys Check HTTP referer CSRF
1-user goes to evil.fish
2 - evil.fish includes form on bank.com
3 - form is submitted
4 - bank.com helpfully transfers money into trout’s account