Question
Which of the following attacks can occur when a user is
tricked into performing unintended actions on a trusted website without their knowledge?Solution
CSRF is an attack where an authenticated user is tricked into performing actions on a website without their consent. The attacker typically sends a malicious link or embeds it in a third-party site, and when the user clicks it, their browser unknowingly sends authenticated requests to the targeted application. This can result in unauthorized transactions, account modifications, or data theft. CSRF exploits the trust that the application places in the user's browser, relying on the lack of proper anti-CSRF measures like tokens. For example, a user logged into their bank account could unknowingly approve a transfer initiated by an attacker. Why Other Options Are Incorrect :
- SQL Injection : This involves injecting malicious queries into databases, unrelated to user actions.
- Distributed Denial-of-Service (DDoS) : This overwhelms servers, making websites unavailable, but doesnтАЩt involve tricking users.
- Credential Stuffing : This uses leaked credentials to gain unauthorized access, unrelated to unintended user actions.
- Buffer Overflow : This exploits memory allocation vulnerabilities, not user behavior.
рдирд┐рдореНрдирд▓рд┐рдЦрд┐рдд рдХрд╛ рд╕рд╣реА рдЕрдиреБрд╡рд╛рдж рдЪреБрдиреЗрдВ:
(i) рдЙрдкрднреЛрдХреНрддрд╛ рдиреЗ рд╕реЗрд╡рд╛ рдХреА я┐╜...
рдиреАрдЪреЗ рджрд┐рдП рдЧрдП рд╡рд╛рдХреНрдпреЛрдВ рдХрд╛ рдорд┐рд▓рд╛рди рдХрд░реЗрдВ:
(i) рдЖрдкрдХреЛ рд╕рднреА рдирд┐рдпрдореЛрдВ рдХрд╛...
рдХрд┐рд╕ рдирд┐рдпрдо рдХреЗ рдЕрдВрддрд░реНрдЧрдд рдкреНрд░рд╢рд╛рд╕рдирд┐рдХ рдкреНрд░рдзрд╛рди рдХреЛ рд░рд╛рдЬрднрд╛рд╖рд╛ рдЕрдзрд┐рдирд┐рдпрдо я┐╜...
рдиреАрдЪреЗ рджрд┐рдП рдЧрдП рд╡рд╛рдХреНрдпреЛрдВ рдХреЗ рд╕рд╣реА рдЕрдиреБрд╡рд╛рдж рдХрд╛ рдорд┐рд▓рд╛рди рдХрд░реЗрдВ рдФрд░ рдЙрдЪрд┐рдд рд╡рд┐я┐╜...
рдиреАрдЪреЗ рджрд┐рдП рдЧрдП рд╢рдмреНрджреЛрдВ рдХрд╛ рд╕рд╣реА рд╣рд┐рдВрджреА рдЕрдиреБрд╡рд╛рдж рд╡рд┐рдХрд▓реНрдкреЛрдВ рд╕реЗ рдЪрдпрди рдХрд░я┐╜...
рдирд┐рдореНрдирд▓рд┐рдЦрд┐рдд рд╡рд╛рдХреНрдп рдХрд╛ рд╕рд╣реА рдЕрдиреБрд╡рд╛рдж рдХреМрди рд╕рд╛ рд╡рд┐рдХрд▓реНрдк рд╣реЛрдЧрд╛ред┬а
The gu...
GIC
рджреЗрд╡рдирд╛рдЧрд░реА рд▓рд┐рдкрд┐ рдХреЗ рд╡рд┐рд╖рдп рдореЗ рдХреНрдпрд╛ рд╕рддреНрдп рдирд╣реА рд╣реИ ?
рдЗрдирдореЗрдВ рд╕реЗ рдХреНрдпрд╛ тАШNon-Performing Asset тАЩ рдХрд╛ рд╕рд╣реА рдЕрд░реНрде рд╣реИ?┬а
рд╡рд┐рддреНрддреАрдп рд░реВрдк рд╕реЗ рдордЬрдмреВрдд рд░рд╛рдЬреНрдп рд╡рд╛рд╕реНрддрд╡ рдореЗрдВ рд╕рд╛рд░реНрд╡рдЬрдирд┐рдХ рдмреБрдирд┐рдпрд╛рджреА...