3 ms·
CSRF attacks are weak. You'd have to know my website's phpMyAdmin location (if I used phpMyAdmin) and my table names in order to do this. CSRF attacks are onl
by thenotself 18y ago
CSRF attacks are weak. You'd have to know my website's phpMyAdmin location (if I used phpMyAdmin) and my table names in order to do this. CSRF attacks are only scary when they effect major websites.
- simonw 18y agoCSRF attacks are strong. I can write an attack that tries dozens of different potential combinations of URL and table names just as easily as I can attack one. Not to mention that many people use their web host's one-click install tool which always puts scripts like phpMyAdmin in the same place.
- jonknee 18y agoBut you still need to know the address of the site. You'd need to create a new attack site for every victim. And then lure the victim there after they had just been in PHPMyAdmin. Not exactly like a CSRF in Facebook or something. It should definitely be fixed, but it really is a weak attack.
- olefoo 18y agoWhat if you're using a common application like WordPress or Movable Type where the database and table names are known?