← Back to Attack / Defense Lab
OSI LAYER 7 // Application Layer

Cross-Site Request Forgery (CSRF)

CSRF tricks an authenticated browser into sending an unwanted state-changing request to a site where the victim is already signed in.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

The browser automatically supplies authentication material such as cookies while the application fails to verify that the request originated from an intended interaction.

02 // DETECTION

Indicators to watch

Unexpected state changes, requests lacking valid CSRF tokens, unusual Origin/Referer values, and state-changing endpoints that accept cross-site requests are useful signals.

03 // ATTACK FLOW

Concept diagram

01Authenticated browser↓
02Cross-site request↓
03State-changing endpoint↓
04Unwanted action↓
05CSRF token + SameSite
04 // PREVENTION

Defensive controls

Use anti-CSRF tokens, SameSite cookies, Origin/Referer validation where appropriate, re-authentication for sensitive actions, and avoid unsafe state changes through GET.

05 // SECURITY TOOL

Recommended security control

CSRF middleware + SameSite cookies

Validate defenses in an application test environment.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.