Cross-site request forgery (CSRF)
Methodology
Case 1: Testing CSRF Tokens
Case 2: When CSRF Cookies Are Present
Case 3: When Referer Header Is Used
Case 4: SameSite Cookies
PoC Examples
CSRF via GET
CSRF via POST
Cookie header injection Technique


Cookie header injection POC
Referer techniques
CSRF + Removing referer Header
Bypassing Mandatory Referer (Old & Modern Techniques)

SameSite Protection Bypasses
Bypass SameSite=Lax via _method=POST
Bypass SameSite=Strict Using Gadgets
POC for CSRF
Bypass SameSite=Lax Using Newly Issued Cookies (120s Window)
Cross-Site WebSocket Hijacking
CSRF + XSS + Cross-Site WebSocket Hijacking (CSWSH)
Last updated