Cookie Security
Hard · SameSite

Strict Means No Cross-Site Entry

CookieBank changes the session to SameSite=Strict. From the external site, follow an ordinary top-level GET link to a protected report and compare the result with the Lax challenge.

Objective

Confirm that Strict withholds the session even on a cross-site top-level GET.

Target

CookieBank

Launch target

Submit flag