This entry was posted
on Wednesday, September 5th, 2007 at 4:36 pm and is filed under Uncategorized.
You can follow any responses to this entry through the
RSS 2.0 feed.
Both comments and pings are currently closed.
582 Responseshttp%3A%2F%2Fblog.phishme.com%2F2007%2F09%2Fcsrf-is-not-xss%2FCSRF+is+not+XSS%21%21%212007-09-05+21%3A36%3A15Coreyhttp%3A%2F%2Fblog.phishme.com%2F2007%2F09%2Fcsrf-is-not-xss%2F to “CSRF is not XSS!!!”
[...] Benninger explained the difference between the often confused XSS and XSRF in a previous blog post. The root cause of XSRF is the predicability of key HTTP requests that result in transactions with [...]
[...] Benninger explained the difference between the often confused XSS and XSRF in a previous blog post. The root cause of XSRF is the predicability of key HTTP requests that result in transactions with [...]
[...] about Session Riding attacks? In these cases, we have a legitimately logged in user, coming from their normal IP address [...]