← All concepts
CSRF

Understanding CSRF

What it is

Cross-site request forgery abuses the fact that a browser attaches a victim's cookies to a request no matter who caused it. If a state-changing action is protected by nothing but the session cookie, a page the victim merely visits can fire that action as them.

How you approach it

  1. Which request changes something and carries no token the attacker could not guess — just the cookie the browser sends automatically?
  2. Build a form or an image on your own page that reproduces that request. The victim's browser will attach their cookie for you.
  3. When the forged request lands as the victim, the action's own confirmation carries the flag.

How it gets fixed

The action authenticated with the session cookie alone, so a request originating from another site was indistinguishable from a real one. A crafted auto-submitting form fired it as the victim. The fix is an anti-CSRF token the attacker's page cannot read, and SameSite cookies.

Practise it

Every lab in the CSRF category drills exactly this. Start at Apprentice and work up.

Practise it

ApprenticeCSRF

Changing an email with a single GET

Make a logged-in victim's browser send a state-changing request.

10 pts · 20 minStart →
PractitionerCSRF

The form with no anti-forgery token

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
PractitionerCSRF

A JSON endpoint that accepts form content-type

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
ExpertCSRF

Defeating a predictable token

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
ExpertCSRF

SameSite is not set, and it matters

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
MasterCSRF

Login CSRF into an attacker's account

Make a logged-in victim's browser send a state-changing request.

100 pts · 180 minStart →