SEC-2282: Polish CSRF doc

This commit is contained in:
Rob Winch 2013-08-27 17:16:32 -05:00
parent aca2e4ff3a
commit 9483226d02
1 changed files with 1 additions and 1 deletions

View File

@ -31,7 +31,7 @@ amount=100.00&routingNumber=1234&account=9876
name="account"
value="evilsAccountNumber"/>
<input type="submit"
value="Win Money!'/>
value="Win Money!"/>
</form>]]></programlisting>
<para>You like to win money, so you click on the submit button. In the process, you have unintentionally transferred $100 to
a malicious user. This happens because, while the evil website cannot see your cookies, the cookies associated with your