Q and A on cross site request forgeries and breaking into sessions. It's one of the attacks that XSS enables and the attack of the future. For Session, fixations, hijacking, lockout, replay, session riding etc....
I found a csrf vuln on famous board trough a "hacker" can add a admin user with admin privilege on site.
But i have a problem, when i try it (like admin user, click on csrf code) the site respond me: WARNING: yuor broswer don't send the HTTP_referrer header. I don't understand why the site don't accept my POST request, how can i bypass this, or how can i send it?
thnaks in advance, for more info contact me with PM or at xados@hotmail.it