An even more subtle attack is that any page returned over HTTP can be potentially altered by an intruder — even URLs embedded in the page.
另一种更狡猾的攻击方法是,入侵者可以修改通过HTTP返回的任何页面——甚至包括页面中嵌入的URL。
During a CSRF attack, requests originate from an intruder site and are transmitted through an authenticated browser page to the server.
在CSRF攻击过程中,请求来自一个入侵者站点,然后通过一个经过验证的浏览器页面传输到服务器。
In this attack, an attacker USES weaknesses in the design of the database or Web page to extract information or even manipulate information within the database.
在这种攻击中,攻击者利用数据库或web页面的设计缺陷从数据库提取信息,甚至操纵数据库的信息。
应用推荐