Skip to content

Commit

Permalink
Update 程序猿必读-防范CSRF跨站请求伪造.md
Browse files Browse the repository at this point in the history
  • Loading branch information
mylxsw authored May 30, 2022
1 parent 62bb9a5 commit 1b0de68
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions doc/程序猿必读-防范CSRF跨站请求伪造.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# 程序猿必读-防范CSRF跨站请求伪造

![DSC00964](https://oayrssjpa.qnssl.com/2017-02-27-DSC00964.jpg?imageView2/2/w/600/h/1000/interlace/0/q/100)
![DSC00964](https://ssl.aicode.cc/2017-02-27-DSC00964.jpg?imageView2/2/w/600/h/1000/interlace/0/q/100)

CSRF(Cross-site request forgery,中文为**跨站请求伪造**)是一种利用网站可信用户的权限去执行未授权的命令的一种恶意攻击。通过**伪装可信用户的请求来利用信任该用户的网站**,这种攻击方式虽然不是很流行,但是却难以防范,其危害也不比其他安全漏洞小。

Expand Down Expand Up @@ -35,7 +35,7 @@ CSRF可以盗用受害者的身份,完成受害者在web浏览器有权限进
- 受害者已经登录到了目标网站(你的网站)并且没有退出
- 受害者有意或者无意的访问了攻击者发布的页面或者链接地址

![](https://oayrssjpa.qnssl.com/2017-02-27-14882028931608.jpg)
![](https://ssl.aicode.cc/2017-02-27-14882028931608.jpg)

(图片来自网络,出处不明,百度来的😂)

Expand Down

0 comments on commit 1b0de68

Please sign in to comment.