CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A user who is authenticated to an online banking portal unknowingly visits a malicious website that contains a hidden form auto-submitting a funds transfer request to the bank's server using the user's active session cookie. Which attack does this describe?
- ACross-site request forgery
- BSession replay attack
- CSQL injection
- DCross-site scripting
Show answer & explanationAnswer & explanation
Correct answer: A. Cross-site request forgery
Cross-site request forgery (CSRF) tricks an authenticated user's browser into submitting an unwanted, state-changing request to a trusted site using the victim's existing session, without the victim's knowledge. Because the browser automatically includes the session cookie, the bank server processes the forged request as legitimate.
Why the other options are wrong
- B. Session replay reuses a captured session token rather than forging a new request via the browser.
- C. SQL injection manipulates database queries, not browser session cookies.
- D. XSS injects malicious script into a trusted site, not a forged request from another site.
Cross-Site Request Forgery (CSRF)
An attack that forces an authenticated user's browser to send unwanted requests to a web application in which the user is currently logged in.
- Exploits trust a site has in the user's browser
- Mitigated with anti-CSRF tokens and SameSite cookies
- Requires the victim to be actively authenticated
Memory trick: CSRF = 'Con the Session, Request Forged' using your own cookie against you.