b0ySie7e
search
⌘Ctrlk
b0ySie7e
  • Bienvenido
  • Write up
    • DockerLabs
    • Tryhackme
    • Hackthebox
    • PortSwigger
      • SQL Injection
      • Cross-site scripting
      • CSRF
        • CSRF vulnerability with no defenses
        • CSRF where token validation depends on request method
        • CSRF where token validation depends on token being present
        • CSRF where token is not tied to user session
        • CSRF where token is tied to non-session cookie
        • CSRF where token is duplicated in cookie
        • SameSite Lax bypass via method override
        • SameSite Strict bypass via client-side redirect
        • SameSite Strict bypass via sibling domain
        • SameSite Lax bypass via cookie refresh
        • CSRF where Referer validation depends on header being present
        • CSRF with broken Referer validation
      • Path Traversal
      • Autenthentication vulnerabilities
      • SSRF
      • CORS
      • Clickjacking
  • Notas
    • Pentesting
    • Pentesting Web
    • Escalada de Privilegios
    • Red Team
  • Guias y Herramientas
    • MetaSploit
    • Nmap
    • Git
    • Fortinet
  • Articulos
    • Proyectos
    • Laboratorio
  • Vulnerabilidaes
    • Explotacion
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Write upchevron-right
  2. PortSwigger

CSRF

CSRF vulnerability with no defenseschevron-rightCSRF where token validation depends on request methodchevron-rightCSRF where token validation depends on token being presentchevron-rightCSRF where token is not tied to user sessionchevron-rightCSRF where token is tied to non-session cookiechevron-rightCSRF where token is duplicated in cookiechevron-rightSameSite Lax bypass via method overridechevron-rightSameSite Strict bypass via client-side redirectchevron-rightSameSite Strict bypass via sibling domainchevron-rightSameSite Lax bypass via cookie refreshchevron-rightCSRF where Referer validation depends on header being presentchevron-rightCSRF with broken Referer validationchevron-right
PreviousReflected DOM XSSchevron-leftNextCSRF vulnerability with no defenseschevron-right

Last updated 5 months ago