3 ms·
Sure enough, that's a real problem when the attacker is on the local network, but what if the attacker is not on the local network? Because I think that this at
by Kayou 12y ago
Sure enough, that's a real problem when the attacker is on the local network, but what if the attacker is not on the local network? Because I think that this attack is supposed to work from an external network, or the Internet.
- meowface 12y agoA CSRF attack is essentially a local attack. All an attacker needs to do is have an array of [192.168.0.1, 192.168.1.1, 192.168.2.1, ...] and attempt the CSRF against all of them. 5 different local IPs will probably cover 90% or more of consumer routers, since nearly all of them are on 192.168 RFC 1918 networks and will generally always be a .1 host. If they were going after a small or large business, it'd be a different story. But even then there'd be a lot of opportunity for likely guesses.