Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8171245
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 6, 20262026-06-06T21:24:16+00:00 2026-06-06T21:24:16+00:00

I read this post Understanding CSRF – Simple Question But I still do not

  • 0

I read this post Understanding CSRF – Simple Question
But I still do not understanding how the CSRF token can prevent a CSRF token.

The main problem which confused me is that why the attacker can make any http request to my site, but he cannot read back the response?

1、If I post a http request to get token before every post request, attacker also can make an “get token” request to get token.

2、If I set token to the hidden input while the .html page is loading, attacker also can make a “get html” request to get the this .html page and read the value of hidden page.

I just don’t understand why the attacker can make request but can not read the response?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-06T21:24:17+00:00Added an answer on June 6, 2026 at 9:24 pm

    The attacker cannot make the request himself at all. What he can do is trick his victim (or the victim’s browser) to make that request. So any response would go back to the victim’s browser, too.

    The problem here is that the attacker can choose the URL, and even without seeing any response, accessing that URL may have harmful consequences for the victim.

    The reason why the attacker needs to trick the victim into making the request (as opposed to just accessing the URL himself) is that if the victim does it, the victim’s session cookies will also be sent along, so it looks like an authenticated action for the server.

    If I set token to the hidden input while the .html page is loading, attacker also can make a “get html” request to get the this .html page and read the value of hidden page.

    The attacker can only get a hidden input for his own session, not for the victim’s session. This hidden input will be different from session to session (otherwise there is not point).

    The CSRF token makes sure that every (critical) request includes a random piece of data that must match the user’s session. This way, an attacker cannot just guess what the complete URL would be, and trick someone into clicking on it.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I read this post, but I do not think it really answered my question.
I read this post but I can't get it working: Change Background Color... I
I've read a similar question and Raymond Chan's blog post , but still have
I've read every post about this issue, but nothing solved the problem. I'll be
After reading more and more about IoC containers, I read this post about not
I read this post and I really like this solution to templating but I
I have read this post and it doesn't answer my question. Stateless session bean
Using the fantastic (yet cruelly not accepted) post on this question: List all javascript
I have read another post/question regarding jquery variables and it was useful but I'm
I have read this post and I wanted to use ControllerExtensions.RedirectToAction method. But I

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.