Cross-Site Request Forgery (CSRF)

🔒 Pro Medium Course Online Avg. time 25 min Solved by 0 2 keys · 50 pts Access & Authentication

CSRF turns the browser's own helpfulness against the user. Because the browser sends your cookies with every request to a site, a page you did not write can quietly make your browser perform an action on a site where you are logged in. This exercise explains the mechanism, why it works, and the anti-CSRF token that defeats it.

Skills covered: CSRFAuthentication
Log in or create a free account to submit keys and track your progress.

What you will learn

  • Explain why the browser sends cookies with cross-site requests
  • Understand how a forged request performs an action as the victim
  • Explain why CSRF needs no password and leaves no stolen data
  • Explain the anti-CSRF token and SameSite cookies as defences

Before you start

These exercises cover what this one builds on.

In this exercise

  1. The cookie that goes everywhere
  2. A request you did not mean to send
  3. Why the server cannot tell
  4. The fix: a token the other site can't know
🔒

This is a Pro exercise

Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.

See Pro plans Create a free account

4 sections · 2 keys · 50 points