Cookie Security
Medium · SameSite

Lax Versus Cross-Site POST

The rewards site submits a normal HTML form to CookieBank. This is a top-level cross-site navigation, but the method is POST. Determine whether the Lax session authenticates it.

Objective

Submit the cross-site POST and prove from the request evidence that the Lax cookie was not sent.

Target

CookieBank

Launch target

Submit flag