EXERCISE 1 — Name the vulnerability (the "who acts?" test) ========================================================== THE TEST: ask "whose code/action causes the harm?" - Attacker's script runs ON the target page -> XSS - The victim's BROWSER sends an unwanted request -> CSRF - The SERVER is made to send a request -> SSRF (a) A forum signature containing