Skip to main content
This page aggregates cross-platform resources to practice CSRF (Cross-Site Request Forgery): retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 19 challenges across 3 platforms β€” 2 HackTheBox Β· 15 PortSwigger Β· 2 TryHackMe. 2 with a Spanish writeup, 2 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwigger β€” Basic clickjacking with CSRF token protection (Apprentice) Β· πŸ‡¬πŸ‡§
  2. PortSwigger β€” CSRF vulnerability with no defenses (Apprentice) Β· πŸ‡¬πŸ‡§
  3. TryHackMe β€” Custom Tooling Using Python (Easy Β· ~60 min) Β· πŸ‡¬πŸ‡§
  4. PortSwigger β€” Bypassing SameSite cookie restrictions (Practitioner) Β· πŸ‡¬πŸ‡§
  5. PortSwigger β€” CSRF where Referer validation depends on header being present (Practitioner) Β· πŸ‡¬πŸ‡§
  6. PortSwigger β€” CSRF where token is duplicated in cookie (Practitioner) Β· πŸ‡¬πŸ‡§

Curated resources

HTB machines practicing CSRF (Cross-Site Request Forgery) (2)

PortSwigger labs practicing CSRF (Cross-Site Request Forgery) (15)

TryHackMe rooms practicing CSRF (Cross-Site Request Forgery) (2)


← Back to the full glossary Last updated: 2026-08-24