Overview
CSRF relies on the browser automatically attaching cookies to cross-origin requests.\nIf an endpoint trusts "the session cookie equals intent", an attacker's page can change a password, transfer funds or alter settings while the victim is logged in.\nDefence is an unpredictable per-session token bound into every state-changing request.
Indicators of Compromise
Signals that suggest this is present on a system.
- State-changing GET endpoints
- Missing or static CSRF tokens
- No SameSite cookie attribute
Controls that stop it
-
Harden TLS and Security Headers
Serve everything over TLS with HSTS so downgrades are impossible, set a modern Content-Security-Policy, enable HSTS preload, deny framing with frame-ancestors, and switch on Referrer-Policy and Permissions-Policy. Disable unused legacy protocols and cipher suites rather than leaving them configured for compatibility.