Cross-site request forgery, also known as one-click attack or session riding and abbreviated as CSRF (sometimes pronounced sea-surf) or XSRF, is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the website trusts. Unlike cross-site scripting (XSS), which exploits the trust a user has for a particular site, CSRF exploits the trust that a site has in a user's browser.
CSRF vulnerabilities have been known and in some cases exploited since 2001. Because it is carried out from the user's IP address, some website logs might not have evidence of CSRF. Exploits are under-reported, at least publicly, and as of 2007 there are few well-documented examples. The online banking webapplication of ING Direct was vulnerable for a CSRF attack that allowed illicit money transfers. Popular video website YouTube was also vulnerable to CSRF in 2008 and this allowed any attacker to perform nearly all actions of any user. Customers of a bank in Mexico were attacked in early 2008 with an image tag in email. The link in the image tag changed the DNS entry for the bank in their ADSL router to point to a malicious website impersonating the bank.McAfee was also vulnerable to CSRF and it allowed attackers to change their company system.
Wind blown
A semi capsized in the storm
Stranded
The rains of June have cleansed it
A baptism of sufferage
Take two
One man beneath a waning moon
Still birth
The abortive child of entropy
Careening for identity
Tempt him
Break him in slowly
His heart is quick to judge
But his hands are too lonely
Break him in slowly...
Red dawn
Another storm opens her arms
She's whispering
"Surrender all your loyalties"
Hand over your idle hands of false idols
Let the rains embrace you
Now...
Break them in slowly
Young hearts are quick to judge
But their hands are so lonely
Break them in slowly...
Break them in slowly...