Lesson 3 ยท 20 min

Bypassing broken CSRF defences

Token not validated when absent, token not tied to the session, double-submit, and Referer checks.

This lesson is locked

Enrol in Cross-Site Request Forgery (CSRF) to unlock this lesson and the rest of the curriculum.

0.0090 BTC
Sign In to Enrol