Rich Cannings, Himanshu Dwivedi, Zane Lackey, and Alex Stamos
"Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions"
Upon logging in, the victim??™s browser is redirected to the malicious URL, and the user??™s account is deleted. Craft Your Attack??”Stored CSRF An attacker could also use stored CSRF to perform this attack, which in the case of GoatFriend is quite easy. Stored CSRF requires that the attacker be able to modify the content stored on the targeted web site, much like XSS. Unlike XSS attacks, however, the attacker may not need to be able to inject active content such as JavaScript or