# CSRF, SOP, SameSite, and CORS checklist

Determine whether a cross-origin attacker can cause or read an authenticated action, then aim that primitive at an administrator objective.

## Recognition

- [ ] State-changing requests rely only on cookies and lack an unpredictable request-bound token.
- [ ] Origin is reflected into Access-Control-Allow-Origin or weakly checked by prefix/suffix.
- [ ] Credentialed cross-origin responses are permitted to an attacker-controlled origin.
- [ ] A privileged user predictably visits attacker-controlled content.

## Manual workflow

- [ ] Record method, content type, cookies, CSRF token, Origin/Referer behavior, redirects, and response requirements.
- [ ] Remove or alter each anti-CSRF control independently and verify whether the state change still succeeds.
- [ ] Determine whether a simple form is sufficient or JavaScript/CORS is required.
- [ ] For CORS, vary Origin using exact attacker origins, null, scheme/port changes, subdomains, prefixes, and suffixes.
- [ ] Confirm both browser acceptance and credential inclusion; permissive response headers alone may not be exploitable.
- [ ] Chain the cross-origin primitive into an administrative read or state change that exposes the exam objective.

## Escalation

- [ ] Use CSRF for blind privileged state changes such as adding an account, changing an email, or modifying content.
- [ ] Use exploitable credentialed CORS when the attacker origin can read sensitive responses.
- [ ] Combine stored XSS or an emulated-user visit with the cross-origin action when direct delivery is required.

## Pitfalls

- [ ] Calling a wildcard ACAO exploitable when credentials are required.
- [ ] Ignoring SameSite behavior and top-level navigation differences.
- [ ] Testing with a request tool instead of confirming actual browser enforcement.
- [ ] Failing to verify the privileged side effect.

## Evidence

- [ ] Original privileged request
- [ ] Removed/bypassed control
- [ ] Browser-deliverable PoC
- [ ] Privileged side effect or readable response
- [ ] Administrator objective

## Tools

- [ ] Burp/ZAP Repeater or Requester
- [ ] Browser console and network panel
- [ ] Local HTML PoC
- [ ] HTTP callback server

## Online references

- [PortSwigger CSRF labs](<https://portswigger.net/web-security/csrf>)
- [PortSwigger CORS labs](<https://portswigger.net/web-security/cors>)

> Do you want to live curiously?
