Simple-aa solren
Nee already login panniruka. Browser automatically cookie-ah anupum. Innoru website, unakkku theriyama, bank transfer form-ah submit pannina — cookie poitu work aagum. Adhu dhaan CSRF.
Lab-la enna paaka
- Normal transfer form-la hidden token irukka nu check pannu.
- Token illana, same request-ah vera origin-la try pannu (lab attacker page).
- Session cookie still attached — transfer succeed aagum.
SameSite is not magic
SameSite cookies help, but older browsers, GET-based actions, and mis-set cookies still leak. Labs show the request, not the marketing slide.
Fix
Synchronizer tokens or SameSite=Lax plus checking Origin/Referer on state-changing routes. Idempotent GET should never move money.
curl -i -X POST https://lab.local/transfer -d amount=100