2731327 comment Comment Re:Does this actually say anything? (Score 1) 143 by sk89q on Tuesday September 30, 2008 @12:57AM (#25201597) Attached to: CSRF Flaws Found On Major Websites, Including a Bank XSS is done on the target site. CSRF is done on a different site.