new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

csrf/token_injection

1 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

XMLHttpRequest CSRF token header injection

Override XMLHttpRequest.prototype.open() to automatically add CSRF token header to unsafe HTTP methods. JavaScript code: const csrf_token = document.querySelector("meta[name='csrf-token']").getAttribute("content"); const csrfSafeMethod = (method) => /^(GET|HEAD|OPTIONS)$/.test(method); const originalOpen = XMLHttpRequest.prototype.open; XMLHttpRequest.prototype.open = function(...args) { const result = originalOpen.apply(this, args); if (!csrfSafeMethod(args[0])) { this.setRequestHeader('X-CSRF-Token', csrf_token); } return result; };

Give your agent this brain