Defeating a predictable token
50 points · about 90 minutes · flag formatDC{...}Brief
Cross-site request forgery abuses the fact that a browser attaches a victim's cookies to a request no matter who caused it. If a state-changing action is protected by nothing but the session cookie, a page the victim merely visits can fire that action as them.
This lab: Defeating a predictable token. Make a logged-in victim's browser send a state-changing request.
Work it against your own copy of the target. When you have the flag, submit it below.
Objective
Find a state-changing request that relies only on the session cookie, and build a page that fires it from another origin. Capture the flag the successful forged action reveals.
Sign in and join the Academy to submit a flag, take hints and track your progress.
Sign inWalkthrough
Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.