Jun 2024Cross-Site Request Forgery: Making the Victim's Browser Do ItThe attacker never steals the session. They get the victim's own browser to send an authenticated request, using cookies the browser attaches for them.Security From the Ground Up04