Cross-Site Request Forgery (CSRF)
CSRF tricks an authenticated browser into sending an unwanted state-changing request to a site where the victim is already signed in.
Mechanism
The browser automatically supplies authentication material such as cookies while the application fails to verify that the request originated from an intended interaction.
Indicators to watch
Unexpected state changes, requests lacking valid CSRF tokens, unusual Origin/Referer values, and state-changing endpoints that accept cross-site requests are useful signals.
Concept diagram
Defensive controls
Use anti-CSRF tokens, SameSite cookies, Origin/Referer validation where appropriate, re-authentication for sensitive actions, and avoid unsafe state changes through GET.
Recommended security control
CSRF middleware + SameSite cookies
Validate defenses in an application test environment.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.