????????-CSRF????
???????????? ???????[ 2015/11/24 14:22:13 ] ??????????????? ????????
	?????.CSRF??????
	????CSRF??Cross-site request forgery????????????????????α??????????one click attack/session riding????д???CSRF/XSRF??
	??????.CSRF??????????
	?????????????????CSRF????????????????????????????????巢?????????CSRF???????????????????????巢??????????????????????????????**???????????????......????????????????????й????????????
	??????.CSRF??????
	????CSRF????????????2000?????????????????????????????????06????????????08???????????????**?????????????CSRF??????磺NYTimes.com???????????Metafilter??????????BLOG???????YouTube????HI......??????????????????????????????????????????????CSRF?“????????”??
	??????.CSRF?????
	???????????????CSRF?????????
	
	?????????????????????????CSRF????????????????????????????裺
	????1.????????????A?????????????Cookie??
	????2.??????A??????£?????Σ?????B??
	?????????????????????“???????????????????????е??????????????CSRF?????”???????????????????????????????????
	????1.????????????????????????????tab??沢??????????????
	????2.???????????????????????Cookie????????????ε??????????????????????????????????????????????????????????????????????????????/????????......??
	????3.???????ν????????????????????????????????????ε?????????????????
	?????????????????CSRF?????????????????ü?????????????????CSRF????????????????????????????????????????????????????????????????:>??
	???????1??
	???????????A??????GET???????????????????????磺http://www.mybank.com/Transfer.php?toBankId=11&money=1000
	????Σ?????B?????????????HTML????????£?
	????<img src=http://www.mybank.com/Transfer.php?toBankId=11&money=1000>
	??????????????????????A????????Σ?????B???????????????????????????1000??......
	????????????????????????????AΥ????HTTP?淶?????GET?????????????????Σ?????B???????????????????????A????B?е?<img>??GET??????????????????????????????????????????????????????????????????????????????????????????????????????????????A??Cookie????Get???????????“http://www.mybank.com/Transfer.php?toBankId=11&money=1000”????????????????????????????????????????????????????????????????????????????......
	???????2??
	?????????????????????о???????POST???????????????
	???????????A??WEB??????£?
	????<form action="Transfer.php" method="POST">
	????<p>ToBankId: <input type="text" name="toBankId" /></p>
	????<p>Money: <input type="text" name="money" /></p>
	????<p><input type="submit" value="Transfer" /></p>
	????</form>
	??????????????Transfer.php???£?
	????<?php
	????session_start();
	????if (isset($_REQUEST['toBankId'] &&??isset($_REQUEST['money']))
	????{
	????buy_stocks($_REQUEST['toBankId']????$_REQUEST['money']);
	????}
	?????>
	
??????
					
					???·???
App??С????H5?????????????????Щ??
2024/9/11 15:34:34?????????????????????????
2024/9/10 11:13:49P-One ???????????????????????????????????????
2024/9/10 10:14:12???????????????????????????
2024/9/9 18:04:26??????????????????
2023/3/23 14:23:39???д?ò??????????
2023/3/22 16:17:39????????????????????Щ??
2022/6/14 16:14:27??????????????????????????
2021/10/18 15:37:44
					
			
								
								
								
								
								
								
								
								
								
								
				
sales@spasvo.com