The XSS Rat
CWAP · Module 07 — CSRF

CSRF — JSON endpoints, Content-Type tricks and SameSite

Animated, step-by-step: why a JSON API looks CSRF-proof and when it isn't — text/plain coercion, the padded-JSON trick, simple-request rules, and the real SameSite=Lax nuances.
Module 07CSRFJSON · SameSiteMedium

◤ Attacker workstation

🐀
you
idle

◤ On the wire

◤ Server

key material
waiting
attacker
server
hunter@cwap — bash
0:00 / 0:00 step 1 / 1