Case 04386E · Web AppSec · L2 Practitioner
Cross-Site Request Forgery
Practise as: Explain it · Interview
Interview questionWhat is CSRF, and why do SameSite cookies change the picture?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- CSRF tricks a logged-in browser into sending a state-changing request because cookies are attached automatically
- Attacker cannot read the response; the harm is the side effect (change email, transfer, add admin)
- Classic fix: synchronizer token or signed double-submit cookie validated on every unsafe method
- Chrome default Lax blocks cross-site POST cookies (2-min grace for new cookies with no SameSite set); top-level GETs still send them
- State-changing GET endpoints, same-site subdomain takeovers, and XSS all defeat SameSite-only defenses
If the interviewer pushes back
- Why is an API that uses a bearer token in the Authorization header generally not CSRF-able?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.