CSRF, Cross-site request forgery


Qualche tempo fa sono state rubate alcune identità (user e pasword) da youtube, perchè è stato oggetto di un attacco CSRF.

Ma cos'è questo tipo di attacco?
Il sistema si basa sulla fiducia di un sito web verso un particolare utente.
Per capirlo meglio vediamo un esempio.

Supponiamo che un utente che chiameremo Mario vada in un forum o blog. Nello stesso forum un utente malizioso che chiameremo Giulio ha pubblicato un immagine con un link del tipo: www.latuabanca.it/faibonifico.php.

Quando Giulio carica la pagina, si carica anche il link in maniera remota, senza che Giulio sia a conoscenza di quello che sta facendo.

Se Giulio ha spuntato sul sito della sua banca (che Mario deve conoscere) di ricordare l'accesso, quindi tramite cookie, l'operazione viene eseguita senza richiedere l'autorizzazione a Giulio.

In questo modo è avvenuta una transazione bancaria senza che Giulio fosse minimamente cosciente del fatto.

E' chiaro che questo richiede alcune situazioni al contorno, che normalmente non ci sono:

  1. La banca di Giulio permette il login automatico
  2. La banca di Giulio permette l'invio di bonifici senza conferma da parte dell'utente ed in get.
  3. Mario conosce perfettamente tutti i parametri che devono essere passati per fare un bonifico alla banca di Giulio.

E' chiaro però che se queste condizioni sono raggiunte la frode va in porto.

Autore: Federico Bernardin

Categoria: Generici

ElmerMex ElmerMex 24 gennaio 2017, 04:51
Say Goodbye To Panic Attack With These Tips

Did you know that people with higher than normal intelligence are prone to panic attacks? If you experience these attacks, hopefully this knowledge along with the other helpful tips in this article will assist you with finding peace of mind in trying to deal with your situation.
Andreatoore Andreatoore 15 febbraio 2017, 02:45
Let me show you our route, a perfect way to cover a long distance saving time and energy, without pain and sweat.
Put your feet up, join us and let us make it unforgettable.
This is segway this, this is the future.

<a href=http://segwayverona.com/>Segway Verona Tours</a>
Andreatoore Andreatoore 16 febbraio 2017, 08:09
Enjoy an alternative sightseeing experience of Verona on a 3-hour Segway tour of the glittering city. With a professional guide, cruise to popular attractions like the Basilica of St Anastasia and Porta Palio while listening to illuminating commentary. Travel at a leisurely pace to visit ancient landmarks like the Arena di Verona, a colossal Roman amphitheatre, and the Castelvecchio. Receive personalized attention from your guide on this small-group tour, limited to eight people.

Verona,Piazza Cittadella 11b
+39 0455949
Andreatoore Andreatoore 20 febbraio 2017, 08:02
ThomasKeype ThomasKeype 23 febbraio 2017, 18:49
<a href="http://uploads.ru/YwE34.jpg"><img src="http://s0.uploads.ru/t/YwE34.jpg" border="0" /></a>

Buongiorno, siamo Segway Verona un’innovativa azienda formata da giovani e su misura per tutti. Usiamo nuovi mezzi chiamati Segway/Ninebot veicoli elettrici autobilancianti per muoverci in citta e permettere anche a chi ha poco tempo di vedere gran parte della citta.
Si tratta di noleggio assistito ovvero un nostro ragazzo vi fara da accompagnatore seguendo un itinerario prestabilito che puo avere durata di un’ora o due, inoltre si potra fermarsi per scattare qualche fotografia anche con l’aiuto del vostro accompagnatore.
Scegliamo di mandare con voi una terza persona per una maggiore sicurezza, sia vostra che nostra, avere qualcuno del posto che sa come muoversi nelle affollate strade veronesi e una garanzia in piu oltre al fatto che puo intervenire al sorgere di qualsiasi difficolta.
Tutto questo per garantirvi un’esperienza indimenticabile.

<a href="http://uploads.ru/tqaVy.jpg"><img src="http://s7.uploads.ru/t/tqaVy.jpg" border="0" /></a>

Hello, we are Segway Verona an innovative company set up by young for everyone.
We use new vehicle called Segway / Ninebot which is self-balancing and electric to move in the city and allow everyone who has little time to see great part of the city.
It is an assisted rental, one of our boy will be your accompanist along a planned route which can take an hour or two, in addition you can also stop to take some pictures also with help of your accompanist.
We choose to send with you a third person for higher security, both yours that ours having someone local who knows how to deal with crowded streets of Verona is an extra certitude, in addition he will act at the rise of any difficulty.
All this to guarantee an unforgettable experience.

<a href=http://segwayverona.com/>SEGWAY VERONA TOURS</a>
TimothyRet TimothyRet 24 febbraio 2017, 01:32
It can be daunting trying to figure out what you need to do once you have been diagnosed with sleep apnea. There are so many new things to learn, and you may feel a bit overwhelmed. Reading this article can provide you with some simple steps to take to make the transition much easier.

One way to improve your sleep apnea is to shed excess weight that you are carrying. Being overweight or obese places pressure on your neck, which can compress your windpipe as you sleep. Losing just 25 pounds can make a difference in your symptoms, and losing enough weight can eliminate the disorder altogether.

Consider doing a few very specific exercises before going to bed each night, to alleviate some of your sleep apnea symptoms. Exercising throat and tongue muscles has been proven in scientific studies to reduce snoring, improve breathing and lessen the more profound effects of sleep apnea when done according to doctor's orders.

On easy way to help limit your sleep apnea is to stick to regular sleeping hours. When you stick to a sleep schedule that is steady and consistent, you will be more relaxed and sleep much better. Apnea episode frequency will be greatly reduced if you can get plenty of sleep every night.

Sleeping at a high altitude can worsen your sleep apnea because of the lower levels of oxygen. If you are going to a place located higher than what you are used to, take a CPAP machine with you. The best thing to do would be to completely avoid high altitude.

Drink one cup of caffeinated coffee a few hours before you go to sleep. It may seem silly to drink a caffeine drink at night, but this can actually help keep your throat open while you sleep. You may have to play around with what time you drink the coffee to avoid restlessness.

Do not let sleep apnea ruin your relationship. If your partner has difficulties sleeping next to you because of your snoring or other symptoms linked to sleep apnea, communicate about the problem. be understanding and consider sleeping apart or getting a CPAP machine to reduce your snoring and other symptoms.

The most important aspect of dealing with sleep apnea is understanding exactly what it is. Unlike simple snoring, it is when a sleeper stop's breathing for a short period of time while he is sleeping. If your sleep partner tells you that sometimes you stop breathing, there is a good chance you have apnea.

People who use alcohol, sedatives, and sleeping pills are far more likely to suffer from sleep apnea. This is because these drugs will relax the throat and cause their breathing to be impaired. Using these drugs before bedtime is more likely to cause sleep apnea than using these drugs during the day.

There are several things that can trigger sleep apnea and there are many treatments. Since you have read this article, you have increased your knowledge about dealing with your sleep apnea. Pass this knowledge on to others whose lives may be affected by this condition. A great night of sleep is still very possible for you.

Hines Hines 21 marzo 2017, 11:05
This forum needed shkinag up and you've just done that. Great post!
JefferyBeirm JefferyBeirm 1 ottobre 2017, 10:01
If you have been feeling stressed lately, but you are not sure how to deal with it, the advice in this article can help. Feelings of stress are increasingly common in today's world, but there are ways to help. This article will teach you some easy ways to overcome your stress.

[url=https://www.acheterviagrafr24.com/viagra-pas-cher-inde-homme/]viagra pas cher inde homme[/url]
Philipanisy Philipanisy 1 dicembre 2017, 04:57
ome people, especially those running on busy daily schedules tend to use the pills to help maintain weight since they can not afford to follow all the diet programs. This is not advised. It is recommended that one seek advice from a professional in this field before using the pills. This can save one from many dangers associated with the misuse.

The diet pills should always be taken whole. Some people tend to divide the pills to serve a longer period of time. This is not advised and can lead to ineffectiveness. If it is required that one takes a complete tablet, it means that a certain amount of the ingredients are required to achieve the desired goal. It is also recommended that one does not crush the pill and dissolve it in beverages. Chemicals found in beverages have the potential of neutralizing the desired nutrients in the pill thereby leading to ineffectiveness. The best way to take the tablets is swallowing them whole with a glass of water.

DPlaudeo2zewes DPlaudeo2zewes 12 dicembre 2017, 06:41

* - campo obbligatorio


Immagine CAPTCHA per prevenire lo SPAM
Se non riesci a leggere la parola, clicca qui.