Writeups
-
Easy
CSRF with broken Referer validation
csrf where the Referer must contain the site's domain but the check is a naive substring match
Cross-site request forgery (CSRF) 3 min -
Easy
CSRF where Referer validation depends on header being present
csrf where the site validates the Referer header only when it is present
Cross-site request forgery (CSRF) 2 min -
Medium
SameSite Strict bypass via sibling domain
cross site websocket hijacking blocked by a SameSite=Strict session cookie, bypassed by running the cswsh script on a sibling subdomain through its reflected login xss so the connection counts as same site
Cross-site request forgery (CSRF) 7 min -
Easy
SameSite Strict bypass via client-side redirect
csrf where the session cookie is SameSite=Strict, bypassed by abusing the site's own client side redirect and a path traversal on postId
Cross-site request forgery (CSRF) 4 min -
Easy
SameSite Lax bypass via method override
csrf with no token, protected only by chrome's default Lax SameSite cookie, bypassed with a top level get navigation that carries the session cookie plus a _method=POST override so the post only email change endpoint accepts it
Cross-site request forgery (CSRF) 4 min -
Easy
CSRF where token is duplicated in cookie
csrf using the insecure double submit technique where the server only checks the form token equals the csrf cookie
Cross-site request forgery (CSRF) 2 min -
Easy
CSRF where token is tied to non-session cookie
csrf where the token is tied to a separate csrfKey cookie rather than the session
Cross-site request forgery (CSRF) 5 min
Nothing matched that.
No writeups here yet. Try a broader tag, or clear the filter to see everything.
Clear filters