← All labs
MasterCSRF

Login CSRF into an attacker's account

100 points · about 180 minutes · flag format DC{...}
Client-SideWeb Fundamentals

Brief

Cross-site request forgery abuses the fact that a browser attaches a victim's cookies to a request no matter who caused it. If a state-changing action is protected by nothing but the session cookie, a page the victim merely visits can fire that action as them.

This lab: Login CSRF into an attacker's account. Make a logged-in victim's browser send a state-changing request.

Work it against your own copy of the target. When you have the flag, submit it below.

Objective

Find a state-changing request that relies only on the session cookie, and build a page that fires it from another origin. Capture the flag the successful forged action reveals.

Sign in and join the Academy to submit a flag, take hints and track your progress.

Sign in

Walkthrough

Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.