AcmeBank — secure online banking

Login

This is a lab. Any username/password is accepted (we're not the auth boundary today).

Dashboard

Welcome . Balance: $50,000

Quick transfer

Note for the developer: hidden CSRF token still TODO.

Simulate the attacker

In a real CSRF, the victim clicks a malicious link/page. Click below to simulate it.