Cross-site Request Forgery - Forging Login Requests

Forging Login Requests

An attacker may forge a request to log the victim in to a target website using the attacker's credentials; this is known as login CSRF. Login CSRF makes various novel attacks possible; for instance, an attacker can later log in to the site with his legitimate credentials and view private information like activity history that has been saved in the account. The attack has been demonstrated against YouTube.

Read more about this topic:  Cross-site Request Forgery

Famous quotes containing the words forging and/or requests:

    The anvil of justice is planted firm, and fate who makes the sword does the forging in advance.
    Aeschylus (525–456 B.C.)

    Do not worry about anything, but in everything by prayer and supplication with thanksgiving let your requests be made known to God.
    Bible: New Testament, Philippians 4:6.