Это видео недоступно.
Сожалеем об этом.

Account Take Over via Forgot Password Function

Поделиться
HTML-код
  • Опубликовано: 22 июн 2022
  • Forgot Password function allows the application users to reset their password if they forgot their account password. If a web application doesn’t implement a secure forgot password function this would allow an attacker to reset the application users password and take over their account. During this video we look at this scenario in action.
    NOTE: This video is made ONLY for educational purposes and to help developers and security researchers to enhance their security knowledge. Therefore, allowing them remediate potential vulnerabilities in their OWN applications.
    Web Security Academy | Lab: Password reset broken logic:
    portswigger.ne...
    Twitter: / tracethecode

Комментарии • 16

  • @DoctorWEED-
    @DoctorWEED- 2 месяца назад

    its a perfect metod to learn

  • @SohagAfsar
    @SohagAfsar Год назад +1

    You are the best brother.
    Take Love😍😍💞💞💞

  • @tigreonice2339
    @tigreonice2339 2 года назад +1

    Gracias por compartir tus conocimientos

  • @GameWithSNAKE
    @GameWithSNAKE 2 года назад +2

    Thanks for knowledge ❤️

  • @tiwister8773
    @tiwister8773 10 месяцев назад +1

    thanks

  • @tigreonice2339
    @tigreonice2339 2 года назад +1

    If my pc has malware and I reset or format the pc, will the malware be deleted?
    I Deleted the file and from the trash.
    Will I be able to format the pc and be calm?

    • @freedom4all931
      @freedom4all931 2 года назад

      No

    • @tigreonice2339
      @tigreonice2339 2 года назад

      @@freedom4all931 what can I do? No I cant see the file and none antivirus detected it

    • @youtubee4817
      @youtubee4817 Год назад

      @@tigreonice2339 destroy it and change hd.

  • @Lacunna
    @Lacunna 2 года назад

    When I send it, It says bad request how to fix that

    • @Lacunna
      @Lacunna 2 года назад

      It say in the response tab “invalid csrf token (session does not contain a csrf token)” but when I remove it it says missing parameter

    • @TraceTheCode
      @TraceTheCode  2 года назад +1

      If that's the case for you, I suggest to follow these steps 1)request a new password reset link 2) Click on the PW reset link in the email inbox 3) turn on burp intercept 4) choose the new password in the forgot password page 5) submit the request 6) go to the captured request in Burp and change the username parameter value to carlos and forward the request.

  • @Ashton.Rblx-
    @Ashton.Rblx- 9 месяцев назад

    How do i get burp suite for free?