Question
Which of the following attacks can occur when a user is
tricked into performing unintended actions on a trusted website without their knowledge?Solution
CSRF is an attack where an authenticated user is tricked into performing actions on a website without their consent. The attacker typically sends a malicious link or embeds it in a third-party site, and when the user clicks it, their browser unknowingly sends authenticated requests to the targeted application. This can result in unauthorized transactions, account modifications, or data theft. CSRF exploits the trust that the application places in the user's browser, relying on the lack of proper anti-CSRF measures like tokens. For example, a user logged into their bank account could unknowingly approve a transfer initiated by an attacker. Why Other Options Are Incorrect :
- SQL Injection : This involves injecting malicious queries into databases, unrelated to user actions.
- Distributed Denial-of-Service (DDoS) : This overwhelms servers, making websites unavailable, but doesnтАЩt involve tricking users.
- Credential Stuffing : This uses leaked credentials to gain unauthorized access, unrelated to unintended user actions.
- Buffer Overflow : This exploits memory allocation vulnerabilities, not user behavior.
рдирд┐рдореНрдирд▓рд┐рдЦрд┐рдд рдореЗрдВ рд╕реЗ рдХреМрди рд╕рд╛ рд╢рдмреНрдж рдкреБрдВрд▓реНрд▓рд┐рдВрдЧ рд╣реИ?
рд╡рд╛рдХреНрдп рд╕рдВрд░рдЪрдирд╛ рдХрд╛ рд╕рд╣реА рдХреНрд░рдо рдмрддрд╛рдЗрдпреЗ ?
1. рдХреБрд▓ рдорд┐рд▓рд╛рдХрд░ рдЖрддреНрдорд░рдХреНрд╖рд╛...
рд▓рд┐рдВрдЧ рдХрд┐рд╕ рднрд╛рд╖рд╛ рдХрд╛ рд╢рдмреНрдж рд╣реИ?
рдЕрдкреВрд░реНрдг рднреВрддрдХрд╛рд▓ рдХрд╛ рдЙрджрд╛рд╣рд░рдг рд╣реИ -
'рдЖрдзрд╛ рддреАрддрд░ рдЖрдзрд╛ рдмрдЯреЗрд░ ' рдХрд╛ рднрд╛рд╡рд╛рд░реНрде рд╣реИ :
рдЗрдзрд░-рдЙрдзрд░ рджреЗрдЦ рд░рд╣рд╛ рд╣реИред рдЗрд╕ рд╡рд╛рдХреНрдп рдореЗрдВ 'рдЗрдзрд░-рдЙрдзрд░ рдХреМрди-рд╕реА рдХреНрд░рд┐рдпрд╛ я┐╜...
рдирд┐рдореНрдирд▓рд┐рдЦрд┐рдд рдореВрд▓ рд╡рд╛рдХреНрдп рдФрд░ рдЗрд╕рдХреЗ рджреЛ рд╕рдВрднрд╛рд╡рд┐рдд рдЕрдиреВрджрд┐рдд рд╡рд╛рдХреНрдпя┐╜...
'рдЪрд┐рд░рдВрддрди' рдХрд╛ рд╡рд┐рд▓реЛрдо ________ рд╣реЛрдЧрд╛ред
рдирд┐рдореНрдирд▓рд┐рдЦрд┐рдд рдореЗрдВ рд╕реЗ рд╢реБрджреНрдз рд╡рд╛рдХреНрдп рдХрд╛ рдЪрдпрди рдХреАрдЬрд┐рдП:
'рдЬреЛ рддреЛрд▓рд╛ рдорд╛рдкрд╛ рдЬрд╛ рд╕рдХреЗ' рдХреЗ рд▓рд┐рдП рдирд┐рдореНрдирд▓рд┐рдЦрд┐рдд рдореЗрдВ рд╕реЗ рдХреМрдирд╕рд╛ рд╢рдмреНрдж рд╣реЛ...