. "CSRF attacks generally target functions that cause a state change on the server but can also be used to access sensitive data. ???For most sites, browsers will automatically include with such requests any credentials associated with the site, such as the user's session cookie, basic auth credentials, IP address, Windows domain credentials, etc." . . . .