Cross-Site Request Forgery (CSRF)
In a CSRF attack, a malicious website tricks the victim's browser into making an authenticated request to another site. Since browsers automatically send cookies, the bank thinks the request is legitimate.
Session State
Cookie
-
Session Status
-
Last Request Origin
-
CSRF Payload
-
Prevention
CSRF tokens
SameSite cookies
Check Origin header
Double-submit cookie
SameSite cookies
Check Origin header
Double-submit cookie
Event Log