Cross-site request forgery, also known as one-click attack or session riding and abbreviated as CSRF or XSRF, is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. There are many ways in which a malicious website can transmit such commands; specially-crafted image tags, hidden forms, and JavaScript XMLHttpRequests, for example, can all work without the user's interaction or even knowledge. Unlike cross-site scripting (XSS), which exploits the trust a user has for a particular site, CSRF exploits the trust that a site has in a user's browser. [Wikipedia]
Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts
Passive Information Gathering - Online Hacking tools
Google Hacking
Locate security vulnerabilities on the
internet using search engines, such as Google can called as Google hacking. We
can identify Google Hacking as a passive information gathering techniques.
Generally, there are two types of vulnerabilities we can found on the web:
Software vulnerabilities and misconfigurations.
For the example, imagine we need to gather
information about hotels in United State. Most of the people that didn’t aware
of Google Footprint Techniques do it like following,
Subscribe to:
Posts (Atom)
