Open cardosec

Case 04386E · Web AppSec · L2 Practitioner

Cross-Site Request Forgery

Practise as: Explain it · Interview

Interview questionWhat is CSRF, and why do SameSite cookies change the picture?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. CSRF tricks a logged-in browser into sending a state-changing request because cookies are attached automatically
  2. Attacker cannot read the response; the harm is the side effect (change email, transfer, add admin)
  3. Classic fix: synchronizer token or signed double-submit cookie validated on every unsafe method
  4. Chrome default Lax blocks cross-site POST cookies (2-min grace for new cookies with no SameSite set); top-level GETs still send them
  5. State-changing GET endpoints, same-site subdomain takeovers, and XSS all defeat SameSite-only defenses

If the interviewer pushes back

  • Why is an API that uses a bearer token in the Authorization header generally not CSRF-able?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.