3 ms·
The CSRF attacker cannot set a cookie for the domain of the target site, it can only set the token on the request itself, which will most likely be not equivale
by relix 13y ago
The CSRF attacker cannot set a cookie for the domain of the target site, it can only set the token on the request itself, which will most likely be not equivalent to the cookie token.