摘要
CSRF依赖HTTP请求无状态的特性,借助带有强制被攻击者浏览器提交请求的HTML,从而达到攻击的目的。CSRF很难被捕捉,危害极大。本文将深入研究CSRF的工作原理以及有效的防护措施,努力把CSRF危害程度降到最低。
CSRF relies on HTTP stateless request, uses HTML to force the attracted browser to submit the request, so as to achieve the attack purpose. CSRF is hard to be found and has great harm. This paper deeply studies the principle of CSRF and the protective measures, strives to minimize the CSRF damage.
出处
《电脑与电信》
2016年第3期81-83,共3页
Computer & Telecommunication
关键词
CSRF
捕捉
欺骗
防护
攻击
Cross-Site Request Forgery
catch
cheating
protection
attack