---
title: Preventing Cross Site Request Forgery
description: Cross Site Request Forgery (CSRF) is an attack against web applications that forces users to execute unwanted actions within authenticated web applications
image: https://www.teamscs.com/hubfs/Imported_Blog_Media/LockedLaptop.jpg
---

[Skip to main content](https://www.teamscs.com/superior-spotlight-blogs/2014/02/preventing-cross-site-request-forgery#main-content)

- [Power BI Consulting](https://www.teamscs.com/power-bi-enterprise)
- [Request a Quote](https://www.teamscs.com/discovery)

[![Superior Consulting Services logo](https://www.teamscs.com/hubfs/SCS_2015_LOGO.svg) ![Superior Consulting Services logo](https://www.teamscs.com/hubfs/SCS_2015_LOGO.svg)](https://www.teamscs.com/old-homepage)

- Show submenu for Data Services Data Services 
  
    - [Data Unification](https://www.teamscs.com/data-unification)
    - [Data Modeling](https://www.teamscs.com/data-modeling)
    - [Data Visualization](https://www.teamscs.com/reporting-and-analytics)
    - [Spatial Analytics](https://www.teamscs.com/gis-spatial-analytics)
    - [Business Automation](https://www.teamscs.com/business-automation)
    - [AI & Machine Learning](https://www.teamscs.com/ai-machine-learning)
- Show submenu for Technologies Technologies 
  
    - [Power BI & Analytics](https://www.teamscs.com/power-bi-enterprise)
    - [Microsoft Fabric](https://www.teamscs.com/microsoft-fabric-consulting)
    - [Microsoft Azure](https://www.teamscs.com/azure-services)
    - [Power Apps & Power Automate](https://www.teamscs.com/power-apps-power-automate)
- Show submenu for Industries Served Industries Served 
  
    - [Community Corrections](https://www.teamscs.com/community-corrections)
    - [Financial Institutions](https://www.teamscs.com/financial-institutions)
    - [Government Contracting](https://www.teamscs.com/government-contracting)
    - [HHS Departments](https://www.teamscs.com/county-hss-departments)
    - [Insurance Companies](https://www.teamscs.com/insurance-industry)
    - [Manufacturing](https://www.teamscs.com/manufacturing)
    - [Nonprofits](https://www.teamscs.com/nonprofits)
    - [SaaS Companies](https://www.teamscs.com/software-as-a-service)
    - [Service Providers](https://www.teamscs.com/service-providers)
- Show submenu for About Us About Us 
  
    - [Meet the Team](https://www.teamscs.com/about)
    - [The Superior Way](https://www.teamscs.com/superior-way)
    - [Case Studies](https://www.teamscs.com/superior-spotlight-blogs/tag/case-studies)
    - [Testimonials](https://www.teamscs.com/insights/testimonials)
- Show submenu for Training Training 
  
    - [Power BI & Fabric Training](https://www.teamscs.com/custom-training)
    - [Online Courses](https://www.teamscs.com/learn-power-bi)
    - [User Groups and Events](https://www.teamscs.com/user-groups-and-events)
- Show submenu for Resources Resources 
  
    - [Superior Blog](https://www.teamscs.com/superior-spotlight-blogs)
    - [Published Books](https://www.teamscs.com/insights/resources)
- [Contact](https://www.teamscs.com/contact)

Open main navigation

Close main navigation

- Show submenu for Data Services Data Services 
  
    - Data Services
    - [Data Unification](https://www.teamscs.com/data-unification)
    - [Data Modeling](https://www.teamscs.com/data-modeling)
    - [Data Visualization](https://www.teamscs.com/reporting-and-analytics)
    - [Spatial Analytics](https://www.teamscs.com/gis-spatial-analytics)
    - [Business Automation](https://www.teamscs.com/business-automation)
    - [AI & Machine Learning](https://www.teamscs.com/ai-machine-learning)
- Show submenu for Technologies Technologies 
  
    - Technologies
    - [Power BI & Analytics](https://www.teamscs.com/power-bi-enterprise)
    - [Microsoft Fabric](https://www.teamscs.com/microsoft-fabric-consulting)
    - [Microsoft Azure](https://www.teamscs.com/azure-services)
    - [Power Apps & Power Automate](https://www.teamscs.com/power-apps-power-automate)
- Show submenu for Industries Served Industries Served 
  
    - Industries Served
    - [Community Corrections](https://www.teamscs.com/community-corrections)
    - [Financial Institutions](https://www.teamscs.com/financial-institutions)
    - [Government Contracting](https://www.teamscs.com/government-contracting)
    - [HHS Departments](https://www.teamscs.com/county-hss-departments)
    - [Insurance Companies](https://www.teamscs.com/insurance-industry)
    - [Manufacturing](https://www.teamscs.com/manufacturing)
    - [Nonprofits](https://www.teamscs.com/nonprofits)
    - [SaaS Companies](https://www.teamscs.com/software-as-a-service)
    - [Service Providers](https://www.teamscs.com/service-providers)
- Show submenu for About Us About Us 
  
    - About Us
    - [Meet the Team](https://www.teamscs.com/about)
    - [The Superior Way](https://www.teamscs.com/superior-way)
    - [Case Studies](https://www.teamscs.com/superior-spotlight-blogs/tag/case-studies)
    - [Testimonials](https://www.teamscs.com/insights/testimonials)
- Show submenu for Training Training 
  
    - Training
    - [Power BI & Fabric Training](https://www.teamscs.com/custom-training)
    - [Online Courses](https://www.teamscs.com/learn-power-bi)
    - [User Groups and Events](https://www.teamscs.com/user-groups-and-events)
- Show submenu for Resources Resources 
  
    - Resources
    - [Superior Blog](https://www.teamscs.com/superior-spotlight-blogs)
    - [Published Books](https://www.teamscs.com/insights/resources)
- [Contact](https://www.teamscs.com/contact)

- [Power BI Consulting](https://www.teamscs.com/power-bi-enterprise)
- [Request a Quote](https://www.teamscs.com/discovery)

# Preventing Cross Site Request Forgery

###### February 27, 2014

![](https://www.teamscs.com/hubfs/Imported_Blog_Media/LockedLaptop.jpg)

Cross Site Request Forgery (CSRF) is an attack against web applications that forces users to execute unwanted actions within the web applications that they are currently authenticated. By sending a malicious link via email, social network post or chat, an attacker may trick users of web applications into executing actions of the attacker’s choosing. A successful CSRF exploit can compromise end user data, allow unwanted transactions to occur, redirect purchase goods to fraudulent shipping addresses and other unwanted and unexpected actions.

Microsoft ASP.Net provides a mechanism to prevent CSRF attacks in MVC architected web applications.

**![LockedLaptop](https://www.teamscs.com/hs-fs/hubfs/Imported_Blog_Media/LockedLaptop-300x250-1.jpg?width=300&height=250&name=LockedLaptop-300x250-1.jpg)CSRF Prevention**  
 To prevent CSRF attacks in Microsoft ASP.net MVC applications, code must be added to the View and Controller classes. The following two (2) sections detail the specifics of adding code to prevent CSRF attacks at the View and Controller level.

**View**  
 The View class is instantiated on the server and generates HTML to render the form to the client in the client’s browser.

To prevent a CSRF attack, a helper method, specifically ***@Html.AntiForgeryToken***, is added to the view class.

This will add a hidden field to the form sent to the browser.

The following code is a View page written in C# and uses the Razor View Engine. This code demonstrates the insertion of the ***@Html.AntiForgeryToken*** method within the code that will generate a hidden field to the form being posted.

Upon clicking the submit button within this form from the browser, a HTTP Post request is sent to the Login Method within the Account Controller on the Server.

![PreventingCrossSite1](https://www.teamscs.com/hs-fs/hubfs/Imported_Blog_Media/PreventingCrossSite1-1.jpg?width=452&height=172&name=PreventingCrossSite1-1.jpg)

The hacker will not be able to generate a token that will be accepted by the controller on the server.

**Controller**  
 The Controller is run on the server and responds to events including the posting of forms from a browser.

To eliminate CSRF threats, a ***ValidateAntiForgeryToken*** attribute is added to the controller Method. This will cause the method to interpret the antiForgery token generated from the view and to generate an error if the token is missing or does not match the specific token generated by the view.

The following code shows the insertion of the ***ValidateAntiForgeryToken*** attribute in front of the Login controller method.

![PreventingCrossSite2](https://www.teamscs.com/hs-fs/hubfs/Imported_Blog_Media/PreventingCrossSite2-1.jpg?width=467&height=172&name=PreventingCrossSite2-1.jpg)

**Impact of implementing CSFT prevention code**  
 If the ***@Html.AntiForgeryToken*** method is added to the view, and if the method on the controller called by the view has the ValidateAntiForgeryToken attribute, the controller will process the data within the posted form, appropriately.

If the form posted to the controller does not include a token, or if the token is invalid, the controller will throw an exception and the form will not be processed, and no harm will come to the application or data.

*Image courtesy of FreeDigitalPhotos.net/Stuart Miles*

###### Tags:

[Application Development,](https://www.teamscs.com/superior-spotlight-blogs/tag/application-development) [CSRF,](https://www.teamscs.com/superior-spotlight-blogs/tag/csrf) [Forgery,](https://www.teamscs.com/superior-spotlight-blogs/tag/forgery) [c#,](https://www.teamscs.com/superior-spotlight-blogs/tag/c) [ASP.net](https://www.teamscs.com/superior-spotlight-blogs/tag/asp-net)

[![SCS_2015_LOGO](https://www.teamscs.com/hubfs/SCS_2015_LOGO.svg)](https://www.teamscs.com/old-homepage)

350 West Burnsville Parkway, Suite 550  
Burnsville, MN 55337

[scs@teamscs.com](mailto:scs@teamscs.com)

[952.890.0606](tel:9528900606)

- <https://www.facebook.com/TeamSCSers/>
- <https://www.linkedin.com/company/122280?trk=tyah>
- <https://www.youtube.com/channel/UCO2e_BbdPC3mYluONFHH02g>

- [Careers](https://www.teamscs.com/superior-consulting-careers)

- [Power BI Consulting and Support](https://www.teamscs.com/power-bi-enterprise)
- [Fabric Consulting](https://www.teamscs.com/microsoft-fabric-consulting)
- [Azure Services](https://www.teamscs.com/azure-services)
- [Power Apps & Power Automate Services](https://www.teamscs.com/power-apps-power-automate)
- [Data Unification & Modernization](https://www.teamscs.com/data-unification)
- [Data Modeling](https://www.teamscs.com/data-modeling)
- [Reporting & Analytics](https://www.teamscs.com/reporting-and-analytics)
- [GIS & Spatial Analytics](https://www.teamscs.com/gis-spatial-analytics)
- [Business Automation & Workflow](https://www.teamscs.com/business-automation)

- [Government Contracting](https://www.teamscs.com/government-contracting)
- [HHS Departments](https://www.teamscs.com/county-hss-departments)
- [Community Corrections](https://www.teamscs.com/community-corrections)
- [Manufacturing](https://www.teamscs.com/manufacturing)
- [Insurance Companies](https://www.teamscs.com/insurance-industry)
- [Financial Institutions](https://www.teamscs.com/financial-institutions)
- [Nonprofits](https://www.teamscs.com/nonprofits)
- [Service Providers](https://www.teamscs.com/service-providers)
- [SaaS Companies](https://www.teamscs.com/software-as-a-service)

Copyright © 2026 Superior Consulting Services | All Rights Reserved | [Privacy Policy](http://23673295.hs-sites.com/privacy-policy) | [Terms of Use](https://www.teamscs.com/terms-of-use) | Minneapolis Web Design by Bizzyweb

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Team SCS",
    "url" : "https://www.teamscs.com/superior-spotlight-blogs/author/clearedge"
  },
  "dateModified" : "2024-02-06T15:19:36.608Z",
  "datePublished" : "2014-02-28T01:47:40.000Z",
  "headline" : "Preventing Cross Site Request Forgery",
  "image" : [ "https://www.teamscs.com/hubfs/Imported_Blog_Media/LockedLaptop.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.teamscs.com/superior-spotlight-blogs/2014/02/preventing-cross-site-request-forgery",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.teamscs.com/hubfs/SCS_2015_LOGO.svg"
    },
    "name" : "Superior Consulting Services"
  }
}
```