isn't csrf browser confidence issue?
regarding cross-site ask forgery (csrf) attacks, cookies many used authentication method, since web browsers grant eventuality cookies domain (and domain) page generated another domain?
isn't csrf simply preventable browser disallowing such behavior?
as distant i know, kind confidence check isn't implemented web browsers, nonetheless i don't know why. i something wrong?
about csrf:
edit: i cruise cookies should sent http post above case. that's browser function surprises me.
Comments
Post a Comment