Hi all,
I’ve been taking a peek into how the EE engineers have been ensuring form submissions are ‘secure’ in the sense of anti brute force attacks, replay attacks and the like. With that said, it is typical of EE of embed a hidden field named ‘XID’ to help take preventive measures against these verticals.
I suppose my question is, is there any public documentation describing the thought process in the purpose of the hidden XID field—and what exactly it does to help make the life of a perpetrator slightly more difficult?
If not, I’ll stop being lazy and continue reading the source code. 😊
Thanks all!