The XSS Rat
CWAP · Module 07 — CSRF

CSRF — Breaking anti-CSRF tokens

Animated, step-by-step: the ladder of token failures — not validated, only-when-present, not session-bound, reusable, POST-only, double-submit and predictable — each with a probe and a verdict.
Module 07CSRFToken bypassHigh

◤ Attacker workstation

🐀
you
idle

◤ On the wire

◤ Server

key material
waiting
attacker
server
hunter@cwap — bash
0:00 / 0:00 step 1 / 1