Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Basic clickjacking with CSRF token protection (Apprentice) · 🇬🇧
- PortSwigger — CSRF vulnerability with no defenses (Apprentice) · 🇬🇧
- TryHackMe — Custom Tooling Using Python (Easy · ~60 min) · 🇬🇧
- PortSwigger — Bypassing SameSite cookie restrictions (Practitioner) · 🇬🇧
- PortSwigger — CSRF where Referer validation depends on header being present (Practitioner) · 🇬🇧
- PortSwigger — CSRF where token is duplicated in cookie (Practitioner) · 🇬🇧
Curated resources
HTB machines practicing CSRF (Cross-Site Request Forgery) (2)
PortSwigger labs practicing CSRF (Cross-Site Request Forgery) (15)
TryHackMe rooms practicing CSRF (Cross-Site Request Forgery) (2)
← Back to the full glossary Last updated: 2026-08-24