The XSS Rat
CWAP · Module 07 — CSRF

CSRF — Classic POST, from candidate to working PoC

Animated, step-by-step: find a state-changing POST with no token, confirm the cookie rides cross-site, build the auto-submitting form, and prove the change happened as the victim.
Module 07CSRFPOSTHigh

◤ Attacker workstation

🐀
you
idle

◤ On the wire

◤ Server

key material
waiting
attacker
server
hunter@cwap — bash
0:00 / 0:00 step 1 / 1