by Scott Brooks
Cross-site scripting attacks are becoming more and more popular amongst hackers. According to the annual OWASP Foundation Top 10 report XSS (Cross-site scripting) and CSRF (Cross-site request forgery) attacks both remain in the high on this list (#3 & #6). Since cybercrime is on the rise, it is imperative for organizations to secure their web applications from these types of attacks. What is CSRF? OWASP CSRF definition: CSRF is a type of attack that occurs when a malicious web site, email, blog, instant message, or program causes a user’s web browser to perform an unwanted action on a trusted site for which the user is currently authenticated. The impact of a successful CSRF attack is limited to the capabilities exposed by the vulnerable application. For example, this attack could result in a transfer of funds, changing a password, or purchasing an item in the user's context. In effect, CSRF attacks are used by an attacker to make a target system perform a function via the target's brows ...

