new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

csrf/login

1 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

CSRF vulnerability on unauthenticated login forms

CSRF vulnerabilities can occur on login forms where user is not authenticated. While traditional CSRF requires authentication, login CSRF attacks can still exploit unprotected login endpoints. For example, attacker uses CSRF to assume authenticated identity on shopping site with attacker's account, then victim enters credit card details, enabling attacker to purchase items using victim's stored card. Mitigation: create pre-sessions (sessions before user authentication), include CSRF tokens in login forms, destroy pre-session and create new session upon authentication to avoid session fixation attacks, or use custom request headers in AJAX requests.

Give your agent this brain