Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger β Basic clickjacking with CSRF token protection (Apprentice) Β· π¬π§
- PortSwigger β CSRF vulnerability with no defenses (Apprentice) Β· π¬π§
- TryHackMe β Custom Tooling Using Python (Easy Β· ~60 min) Β· π¬π§
- PortSwigger β Bypassing SameSite cookie restrictions (Practitioner) Β· π¬π§
- PortSwigger β CSRF where Referer validation depends on header being present (Practitioner) Β· π¬π§
- PortSwigger β CSRF where token is duplicated in cookie (Practitioner) Β· π¬π§
Curated resources
HTB machines practicing CSRF (Cross-Site Request Forgery) (2)
PortSwigger labs practicing CSRF (Cross-Site Request Forgery) (15)
TryHackMe rooms practicing CSRF (Cross-Site Request Forgery) (2)
β Back to the full glossary Last updated: 2026-08-24