Question
Which of the following is a characteristic of Cross-Site
Request Forgery (CSRF) attacks?Solution
Cross-Site Request Forgery (CSRF) exploits the trust a website has in a user’s browser. An attacker tricks an authenticated user into performing unintended actions, such as transferring money or changing account details, without their consent. For instance, a malicious email link might force a logged-in bank user to transfer money to the attacker’s account.
- Key Condition: The victim must be logged in, as CSRF exploits authenticated sessions.
- Impact: CSRF can lead to unauthorized transactions, changes in user settings, and other unintended operations.
- Prevention: Developers can use anti-CSRF tokens, verify the HTTP Referrer header, and require user re-authentication for sensitive actions.
- Browser vulnerabilities: CSRF exploits user actions and session trust, not browser vulnerabilities.
- SQL commands: This describes SQL Injection, not CSRF.
- Flooding servers: This characterizes DDoS attacks, unrelated to session misuse.
- Script injection: Script injection is XSS, not CSRF.
What is the tenure of the extended Production Linked Incentive (PLI) Scheme for Automobile and Auto Components, as per the recent government announcement?
On which date will Francis Ford Coppola receive the AFI Life Achievement Award?
The Securities and Exchange Board of India (SEBI) has debarred Zee Entertainment Enterprises (Zee) promoter and Essel group Chairman Subhash Chandra and...
Germany's new cannabis law allows individuals over 18 to carry and grow cannabis. How much can they legally carry?
Which company will enhance Norway’s critical financial infrastructure by partnering with BankID BankAxept AS, Norway’s national payment and electron...
How many blackbucks were initially translocated to Barnawapara Wildlife Sanctuary in Chhattisgarh for reintroduction?
On which dates is the National Agriculture Conference – Rabi Abhiyan 2025 scheduled?
As per RBI’s approval (letter dated 22 August 2025), what is the maximum percentage of stake that SMBC can acquire in Yes Bank?
What is the theme of Safer Internet Day 2022?
Consider the following statements about the Indian-French TRISHNA Satellite:
1. TRISHNA is a collaboration between ISRO and CNES.
2. The s...