Cross-Site Request Forgery (CSRF)
CSRF turns the browser's own helpfulness against the user. Because the browser sends your cookies with every request to a site, a page you did not write can quietly make your browser perform an action on a site where you are logged in. This exercise explains the mechanism, why it works, and the anti-CSRF token that defeats it.
Log in or create a free account to submit keys and track your progress.
What you will learn
- Explain why the browser sends cookies with cross-site requests
- Understand how a forged request performs an action as the victim
- Explain why CSRF needs no password and leaves no stolen data
- Explain the anti-CSRF token and SameSite cookies as defences
Before you start
These exercises cover what this one builds on.
- How HTTP Works Easy
In this exercise
- The cookie that goes everywhere
- A request you did not mean to send
- Why the server cannot tell
- The fix: a token the other site can't know
🔒
This is a Pro exercise
Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.
See Pro plans Create a free account4 sections · 2 keys · 50 points