What is CSRF?
CSRF (cross-site request forgery) and its cousin clickjacking, told as a story about a thief who borrows a guest's wristband to send the counter a note behind the guest's back.
The counter reads the wristband and does what the note says.When a guest with an entry wristband hands over a note, the counter checks the wristband and sends the coins. Handy. But the thief has pinned a strange paper on the village board.
CSRF is a note that borrows the guest's wristband and goes behind the guest's back.The guest only looked at a picture of bread. But that paper pins the guest's wristband onto a note — send my coins to the thief — and mails it to the counter. The wristband is real, so the counter trusts it. Only the wish is fake.
It has a cousin: the real button hidden under a clear sheet.The thief lays a clear sheet over our counter and writes PRESS HERE! When the guest presses, the real SEND COINS button underneath gets pressed. Real wristband, real finger.
A number on every note, wristbands only here, only our own window.The counter refuses any note without the slip it handed over on the spot — the board's paper can't know the number. The wristband sticks only to notes handed in at our counter, and our counter never appears inside a stranger's window.
A thief after the note's insides and a thief after the wristband are different thieves.A command hidden in the note is sent by the thief's own hand; this thief makes the guest send it. The note-checker at the counter sees both first, but the wristband thief is only stopped by the slip.
CSRF = a paper the thief pinned borrows the guest's wristband and sends the counter a note with a fake wish behind the guest's back. Stopped by a slip (a secret number handed over on the spot), wristbands that work only at our counter, and never appearing in a stranger's window.
An attack that abuses the browser's habit of attaching cookies automatically, making a logged-in user's browser send a request from another site without the user knowing. Defended with CSRF tokens, SameSite cookies, and — against clickjacking — X-Frame-Options / CSP frame-ancestors.
When grown-ups say it
- CSRF
- The note that borrows the wristband. Real guest, real wristband, fake wish. It happens when a logged-in guest opens the thief's page.
- CSRF token
- The slip handed over on the spot. A secret number the counter wrote on the note form in advance. The board's paper can never know it.
- SameSite cookie
- A wristband that works only at our counter. The wristband won't attach to notes sent from another town. Modern browsers do this by default.
- Clickjacking
- The real button under a clear sheet. The guest presses PRESS HERE and the real button underneath gets pressed. A cousin of the borrowed wristband.
- X-Frame-Options / CSP
- Never in a stranger's window. Our counter can't be embedded inside another page — so there is nowhere to lay the clear sheet.
- Session
- The entry wristband. How the counter recognizes the guest. It can be stolen — or borrowed. → the thief who steals the wristband
- Versus injection
- Inside the note vs the wristband. Injection hides a command inside the note; CSRF sends with someone else's wristband. → the command hidden in the note
- WAF
- The note-checker at the counter. Filters odd notes first. But the wristband thief is only surely stopped by the slip. → the note-checker at the counter