# API Reference: Performing CSRF Attack Simulation ## HTTP Headers for CSRF Protection | Header | Description | |--------|-------------| | `Set-Cookie: SameSite=Strict` | Prevents cookie from being sent in cross-site requests | | `Set-Cookie: SameSite=Lax` | Allows cookies on top-level GET navigations only | | `X-CSRF-Token` | Custom header carrying CSRF token | | `Origin` | Sent by browsers on cross-origin POST requests | | `Referer` | Indicates the source page of the request | ## CSRF Token Patterns (HTML) | Pattern | Framework | |---------|-----------| | `` | Generic | | `` | Django | | `` | Ruby on Rails | | `` | ASP.NET | | `` | Rails/Laravel meta tag | ## requests Library | Method | Description | |--------|-------------| | `session.get(url)` | Fetch page to extract CSRF tokens | | `session.post(url, data)` | Submit form with/without CSRF token | | `session.cookies` | Access session cookies for SameSite analysis | ## Key Libraries - **requests** (`pip install requests`): HTTP client with session cookie management - **beautifulsoup4** (`pip install beautifulsoup4`): Parse HTML forms and extract tokens - **selenium** (optional): Browser-based CSRF testing with full JS execution ## PoC Generation | Element | Purpose | |---------|---------| | `