Q and A on cross site request forgeries and breaking into sessions. It's one of the attacks that XSS enables and the attack of the future. For Session, fixations, hijacking, lockout, replay, session riding etc.... 

7 years ago
I want to implement a function to help users who forgot to log off to send a logoff request before accessing third-party sites. This obviously wont be foolproof as its run on the client side, but is there a recommended secure way to implement this functionality? What limitations are there (besides for having javascript disabled)?
Forum: CSRF and Session Info
