After completing this video, the learner will understand cross-site request forgery attacks and prevention techniques.
- [Voiceover] Another danger facing web applications…is the threat of cross-site request forgery.…These attacks are similar to cross-site scripting attacks…but even more nefarious.…First, one quick note on terminology for the exam.…Cross-site request forgery also goes by two acronyms.…Some people call it CSRF while others use…the XSRF acronym.…Others even pronounce the acronym…and call it "sea surf."…All of these terms refer to the same attack.…
As you may recall, cross-site scripting attacks…occur when an attacker exploits a third-party website…to include scripts written by the attacker…in input shown to other users.…The user's web browser then executes that code…when it visits the site.…Cross-site request forgery attacks go a step further…and prey upon the fact that users often have…multiple sites open at the same time…and may be logged in to many different sites…in different browser tabs.…
As you may have noticed,…authenticated sessions cross over…between those browser tabs.…Cross-site request forgery attacks leverage this…
We are now a CompTIA Content Publishing Partner. As such, we are able to offer CompTIA exam vouchers at a 10% discount. For more information on how to obtain this discount, please download these PDF instructions.
- SQL injection prevention
- Cross-site scripting (XSS) prevention
- Fuzz testing
- Mobile device management (MDM)
- Mobile device tracking
- Operating system security
- Hardware security
- Virtualization security
- File permissions
- Data encryption
- Securing smart devices
Skill Level Intermediate
1. Application Security
2. Mobile Security
3. Host Security
4. Data Security
5. Static Environments
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.