EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium
During a penetration test, an ethical hacker discovers that a web application is vulnerable to Cross-Site Request Forgery (CSRF). Which of the following conditions is NOT typically required for a successful CSRF attack?
- AThe target website must process state-changing requests using HTTP GET or POST without sufficient anti-CSRF protection.
- BThe attacker must be able to inject malicious script into the target website.
- CThe victim must be authenticated to the target website.
- DThe attacker must craft a malicious request that the victim's browser will automatically send.
Show answer & explanationAnswer & explanation
Correct answer: B. The attacker must be able to inject malicious script into the target website.
CSRF attacks do not typically require the attacker to inject malicious scripts into the target website. Instead, the attacker crafts a malicious request and tricks the authenticated victim's browser into sending it to the vulnerable site. The key is that the victim is already authenticated and the site lacks anti-CSRF tokens.
Why the other options are wrong
- A. This is fundamental; the website must have a state-changing action vulnerable to being triggered by a forged request without proper validation.
- C. This is a critical condition; without an authenticated session, the request would not be authorized.
- D. This is how the attack is executed, by tricking the victim's browser into making the unintended request.
Cross-Site Request Forgery (CSRF)
An attack that forces an end user to execute unwanted actions on a web application in which they are currently authenticated.
- Exploits trust in a user's browser, not the user directly.
- Often uses social engineering to trick victims.
- Anti-CSRF tokens are a common defense mechanism.
Memory trick: CSRF doesn't need to 'script' anything, just 'trick' with a link.