Last updated: August 3, 2021
Read time: 3 Minutes
To access this function, select a URL or HTTP request anywhere within Burp, and choose "Generate CSRF PoC" within "Engagement tools" in the context menu.
You can edit the request manually, and click the "Regenerate" button to regenerate the CSRF HTML based on the updated request.
You can test the effectiveness of the generated PoC in your browser, using the "Test in browser" button. When you select this option, Burp gives you a unique URL that you can paste into your browser (configured to use the current instance of Burp as its proxy). The resulting browser request is served by Burp with the currently displayed HTML, and you can then determine whether the PoC is effective by monitoring the resulting request(s) that are made through the Proxy.
Some points should be noted regarding CSRF techniques:
The following options are available: