← Client-Side Attacks
ReadingLesson 4 of 5 · 10 min

Understanding CSRF

What it is

Cross-site request forgery abuses the fact that a browser attaches a victim's cookies to a request no matter who caused it. If a state-changing action is protected by nothing but the session cookie, a page the victim merely visits can fire that action as them.

How you approach it

  1. Which request changes something and carries no token the attacker could not guess — just the cookie the browser sends automatically?
  2. Build a form or an image on your own page that reproduces that request. The victim's browser will attach their cookie for you.
  3. When the forged request lands as the victim, the action's own confirmation carries the flag.

How it gets fixed

The action authenticated with the session cookie alone, so a request originating from another site was indistinguishable from a real one. A crafted auto-submitting form fired it as the victim. The fix is an anti-CSRF token the attacker's page cannot read, and SameSite cookies.

Practise it

Every lab in the CSRF category drills exactly this. Start at Apprentice and work up.

← Lab: stored in a display name
Sign in to track thisLab: the form with no token →