Conducting DoS attacks on other sites, using external server servers.Hiding your own IP, which, in addition to concealing the source of the attack, can also be used to circumvent IP restrictions.Hide the referee (compared to CSRF attacks through site users).This method, which uses external sites to attack other sites, has the following advantages (compared to using your own computer): For example, on-line voting, for scrolling on meter clicks and impressions on the site, as well as for click fraud.Īttack occurs when one site (http: // site) hits another (http: // another_site) when using the appropriate site functionality (http: // site / script). This attack method may be needed when it is necessary to conduct a covert CSRF attack on another site (not to be lit), for DoS and DDoS attacks, and for other attacks, in particular to perform various actions that must be performed from different IPs. CSRF attacks can only be done on pages that do not require authorization.įor these attacks, you can use both Abuse of Functionality vulnerabilities (similar to those in this article) and Remote File Include vulnerabilities (as in PHP applications) – this is Abuse of Functionality via RFI.
Including DoS attacks via Abuse of Functionality, as noted above. Sites that allow requests to other web sites (to arbitrary web pages) have Abuse of Functionality vulnerability and can be used to carry out CSRF attacks on other sites. Davoset is command line tool for conducting DDoS attacks on the sites via Abuse of Functionality and XML External Entities vulnerabilities at other sites.