Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

240.CSRF和XSS的区别 #240

Open
webVueBlog opened this issue Jun 29, 2020 · 0 comments
Open

240.CSRF和XSS的区别 #240

webVueBlog opened this issue Jun 29, 2020 · 0 comments

Comments

@webVueBlog
Copy link
Member

  1. CSRF需要登录,获取COOKIE,利用网站本身的漏洞,去请求网站的api
  2. XSS,不需要登录,向网站注入JS代码,执行JS里的代码,篡改网站的内容
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant