Instead of hijacking the victim, plant them inside an account you control. Forge the sign-in.
Sign in
The victim is browsing while logged in. This login form has no CSRF protection.
Force the victim's browser to log in as your account, so their activity lands in it.
Victim is currently signed in as
victim
Your attacker account credentials (yours to give away):
This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you.
The rest of CSPSHIVAM Playground is not part of the target.
Category complete
You earned a badge
Enter a name to put on your badge, then download it.
Caption copied. Post your badge on LinkedIn or Instagram with #CSPSHIVAMPlayground.
If the download is blocked, a screenshot works just as well.