Understanding CSRF
What it is
Cross-site request forgery abuses the fact that a browser attaches a victim's cookies to a request no matter who caused it. If a state-changing action is protected by nothing but the session cookie, a page the victim merely visits can fire that action as them.
How you approach it
- Which request changes something and carries no token the attacker could not guess — just the cookie the browser sends automatically?
- Build a form or an image on your own page that reproduces that request. The victim's browser will attach their cookie for you.
- When the forged request lands as the victim, the action's own confirmation carries the flag.
How it gets fixed
The action authenticated with the session cookie alone, so a request originating from another site was indistinguishable from a real one. A crafted auto-submitting form fired it as the victim. The fix is an anti-CSRF token the attacker's page cannot read, and SameSite cookies.
Practise it
Every lab in the CSRF category drills exactly this. Start at Apprentice and work up.