📙
AppSec
Ctrlk
  • Overview
  • Write Ups Compilations/Resources
  • Main Resources
  • Labs
  • Cross Site Request Forgery
    • Cross Site Request Forgery (CSRF)
      • Write-ups
      • Source Code Examples
      • Labs
  • Missing Access Controls
    • Missing Access Controls
  • LFI / Directory Traversal
    • Local File Inclusion
  • XXE
    • XML External Entity (XXE)
  • Injection
    • Command Injection
    • Server-Side Template Injection
    • SQL Injection
  • SSRF
    • Server-Side Request Forgery (SSRF)
  • Unvalidated Redirects and Forwards
    • Unvalidated Redirects and Forwards
  • Verbose Error Messages and Stack Traces
    • Verbose Error Messages and Stack Traces
Powered by GitBook
On this page

Was this helpful?

  1. Cross Site Request Forgery
  2. Cross Site Request Forgery (CSRF)

Labs

LogoLab: CSRF vulnerability with no defenses | Web Security AcademyWebSecAcademy
LogoLab: CSRF where token validation depends on request method | Web Security AcademyWebSecAcademy
LogoLab: CSRF where token validation depends on token being present | Web Security AcademyWebSecAcademy
LogoLab: CSRF where token is not tied to user session | Web Security AcademyWebSecAcademy
LogoLab: CSRF where token is tied to non-session cookie | Web Security AcademyWebSecAcademy
LogoLab: CSRF where token is duplicated in cookie | Web Security AcademyWebSecAcademy
LogoLab: CSRF where Referer validation depends on header being present | Web Security AcademyWebSecAcademy
LogoLab: CSRF with broken Referer validation | Web Security AcademyWebSecAcademy

PreviousSource Code ExamplesNextMissing Access Controls

Last updated 4 years ago

Was this helpful?