Demo of SQL injection and CSRF attacks on web applications. Lecture 23 of ITS335 IT Security at Sirindhorn International Institute of Technology, Thammasat University. Given on 20 February 2014 at Bangkadi, Pathumthani, Thailand by Steven Gordon. Course material via: http://sandilands.info/sgordon/teaching