Q2.3 — CSRF Attack on Elgg Social Network

In this scenario Samy wants to be added to Boby's friend list on the Elgg social network but Boby refuses. Samy creates a malicious page at www.attacker32.com/addfriend.html that automatically sends a forged HTTP GET request to the Elgg server the moment Boby visits the page. Since Boby has an active session with Elgg, the server receives the request with Boby's valid session cookie and processes it as if Boby sent it voluntarily. Key concepts demonstrated: CSRF attack using hidden image tag Forged HTTP GET request to trusted website Session cookie exploitation Modern browser SameSite cookie protection