Web Apps
Beginner
Cross-Site Request Forgery (CSRF)
Make a victim's browser send a state-changing request they never intended — and learn every way token, SameSite, and Referer defences are gotten wrong.
Beaulah Marks
4 lessons
About this class
What you'll learn
CSRF forces an authenticated user's browser to perform an action chosen by the attacker. This class covers the three conditions that make it possible, building a proof-of-concept, bypassing weak defences, and the correct fix.
Practice
Pair with CSRF with no defences and CSRF with broken token validation.
Curriculum
On this page
Price
0.0090 BTC≈ $585.00
At a glance
- Category
- Web Apps
- Difficulty
- Beginner
- Lessons
- 4 · 2 free
- Total time
- 59m
- Students
- 0 enrolled
- Tutor
- Beaulah Marks
- Published
- Sep 2026