Skip to main content


xsrfprobe-logo

XSRFProbe

The Prime Cross Site Request Forgery Audit & Exploitation Toolkit.

About

XSRFProbe is an advanced Cross Site Request Forgery (CSRF/XSRF) Audit and Exploitation Toolkit. Equipped with a powerful crawling engine and numerous systematic checks, it is able to detect most cases of CSRF vulnerabilities, their related bypasses and futher generate exploitable proof of concepts with each found vulnerability. For more info on how XSRFProbe works, see XSRFProbe Internals on wiki.

banner-image

XSRFProbe WikiGetting StartedGeneral UsageAdvanced UsageXSRFProbe InternalsGallery

Some Features

  • Runs a full battery of systematic checks — backed by a response diffing/benchmark engine — before declaring an endpoint vulnerable.
  • Detects and actively tampers with many Anti-CSRF token implementations: request-method switch, token removal, empty/duplicated values, non-session-bound tokens, double-submit cookies and custom-header tokens.
  • Probes Referer and Origin validation with real-world bypasses (header removal, regex/subdomain tricks, Origin: null) as well as method-override and Content-Type bypasses.
  • Analyses SameSite cookie protections, with optional subdomain enumeration (via crt.sh) for sibling-domain bypass testing.
  • Works with a powerful crawler featuring deterministic, bounded crawling and scanning (configurable via --max-urls, --max-depth and --crawl-timeout).
  • Optional headless Firefox (Selenium) integration for browser-dependent tests and auto-validation of generated PoCs.
  • Accurate Token-Strength Detection and Analysis using entropy and encoding checks.
  • Can generate both normal as well as maliciously exploitable CSRF proof of concepts.
  • Out of the box support for custom cookie values, generic headers and a JSON report — each finding carries a severity rating and an exploitability precondition.
  • The user is in control of everything whatever the scanner does.
  • User-friendly interaction environment with full verbose support and detailed logging of errors, vulnerabilities and tokens.

Vulnerability Tests Performed:

Every check XSRFProbe runs has a unique identifier. The ID is shown in the console output (e.g. [T6] VULNERABLE: ...) and stored as the test_id field of each finding in the JSON report (alongside its severity and, where relevant, an exploitability note under details), so each finding maps back to the exact test that produced it.

ID Category Check
D1 Token presence No anti-CSRF token present (generic request forgery)
D2 Token presence Login form lacks CSRF token (login CSRF)
T2 Token tampering Validation tied to request method (GET ↔ POST switch)
T3 Token tampering Token can be omitted entirely
T4 Token tampering Token not tied to the user session (cross-session replay)
T5 Token tampering Token tied to a non-session cookie (e.g. csrfKey)
T6 Token tampering Naive double-submit cookie (cookie == body, no binding)
T7 Token tampering Empty token value accepted
T8 Token tampering Custom-header token can be omitted or forged
M1 Method / Content-Type HTTP method override via _method parameter
M2 Method / Content-Type HTTP method override via X-HTTP-Method-Override header
M4 Method / Content-Type Validation bypass via alternate Content-Type
R0 Referer Referer header not validated on form submission
R1 Referer Referer validation bypassed by omitting the header
R2a Referer Referer regex bypass — target as attacker subdomain
R2b Referer Referer regex bypass — target in query string
R2c Referer Referer regex bypass — target in path
O1 Origin Origin validation bypassed with Origin: null
O2 Origin Origin validation bypassed with a subdomain trick
O3 Origin Origin validation bypassed by omitting the header
S2 SameSite (browser) SameSite=Strict bypass via client-side redirect gadget
S3 SameSite (browser) SameSite=Strict bypass via XSS on a sibling subdomain
S4 SameSite (browser) SameSite=Lax bypass via cookie-refresh / OAuth flow
C1 Cookie posture Cookie SameSite attribute analysis (None/Lax/Strict)
C2 Cookie posture No SameSite attribute set on cookies
E1 Token strength Token uses a weak/structured hash encoding
A1 Token strength Post-scan token predictability / forgeability analysis

S* checks require the optional headless-browser integration (--browser). T*/M*/R*/O* are HTTP-level checks gated by the response diffing/benchmark engine.

Gallery

Lets see some real-world scenarios of XSRFProbe in action:

Installation & Usage

For the full usage info, please take a look at the wiki's — General Usage and Advanced Usage.

Installing via Pypi:

XSRFProbe can be easily installed via a single command:

pip install xsrfprobe

Installing manually:

  • For the basics, the first step is to install the tool:
pip install .
  • Now, the tool can be fired up via:
xsrfprobe --help
  • The browser-dependent tests (--browser, --auto-validate-poc) additionally require geckodriver to be available in your PATH (or pointed to via --geckodriver-path).
  • After testing XSRFProbe on a site, an output folder is created in your present working directory as xsrfprobe-output. Under this folder you can view the detailed logs and information collected during the scans (pass --json for a machine-readable report).

Version and License

XSRFProbe is currently v3.0.0 and the work is licensed under the GNU General Public License (GPLv3).

Warnings

Do not use this tool on a live site!

It is because this tool is designed to perform all kinds of form submissions automatically which can sabotage the site. Sometimes you may screw up the database and most probably perform a DoS on the site as well.

Test on a disposable/dummy setup/site!

Disclaimer

Usage of XSRFProbe for testing websites without prior mutual consistency can be considered as an illegal activity. It is the final user's responsibility to obey all applicable local, state and federal laws. The author assumes no liability and is not responsible for any misuse or damage caused by this program.

Author's Words

This project is based entirely upon my own research and my own experience with web applications on Cross-Site Request Forgery attacks. You can try going through the source code to help you understand how this toolkit was built. Useful pull requests, ideas and issues are highly welcome. If you wish to see what how XSRFProbe is being developed, check out the Development Board.

Crafted with ♡ by @0xInfection

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

xsrfprobe-3.0.0.tar.gz (78.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

xsrfprobe-3.0.0-py3-none-any.whl (89.1 kB view details)

Uploaded Python 3

File details

Details for the file xsrfprobe-3.0.0.tar.gz.

File metadata

  • Download URL: xsrfprobe-3.0.0.tar.gz
  • Upload date:
  • Size: 78.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.3

File hashes

Hashes for xsrfprobe-3.0.0.tar.gz
Algorithm Hash digest
SHA256 d1a86d7375f038f83835f2f325f28503b535ad4efa43b3fec4ff42fe4aef8582
MD5 fe882abeb55ea406e40bbd17c5612307
BLAKE2b-256 0a8edba008b5d36da565d5cf7dedcb7e55a8f4a75db1136274ca182e8b20b12d

See more details on using hashes here.

File details

Details for the file xsrfprobe-3.0.0-py3-none-any.whl.

File metadata

  • Download URL: xsrfprobe-3.0.0-py3-none-any.whl
  • Upload date:
  • Size: 89.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.3

File hashes

Hashes for xsrfprobe-3.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f97f09585b1f00a199d52d04e05fe334e4406add34b1e8757c77d2a70ed6557c
MD5 6a24c32b055bee50927054cb86cc74a8
BLAKE2b-256 9cc4860779fd5a4eabd2d3dabd493901f9850cf1ccdd1e50705385e3b5b24f8f

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

3.0.0 This release

2 files

2.3.1

2 files

2.3.0

2 files

2.2.0

1 file

2.1.1

2 files

2.1.0

1 file

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page