Q and A on cross site request forgeries and breaking into sessions. It's one of the attacks that XSS enables and the attack of the future. For Session, fixations, hijacking, lockout, replay, session riding etc.... 

6 years ago
I apologize if i started thread in wrong section. There is problem with ajax, when is 'ajax' XMLHttpRequest get request made to server which is gzip enabled. Server response gzip-inflated data. But 'XMLHttpRequest' doesn't decompress it at all and silent error happen which responds nothing and status bar in fx just stays loading but doing nothing. But with 'mitm' tool between serv. and brow
Forum: CSRF and Session Info
7 years ago
Also doesn't work to me?
Forum: XSS Info
