Progress
1 / 5 findings demonstrated this session.
Demonstrate every finding to clear the Module 05 practice pack. Use the PoC Tester to fire the shapes.
✅ NAKED - GET-based CSRF: a state change fired on GET (img-exploitable), no token
⬜ NAKED - POST CSRF: a change-email POST with no anti-CSRF token
⬜ NAKED - Token present but never validated: blank / arbitrary token accepted
⬜ NAKED - SameSite gap: the session cookie rode a cross-site request (no Origin check)
⬜ METHODOLOGY - Enumerate the account, subtract real protection, forge the ONE weak state change
More hands-on practice → labs.hackxpert.com