CSRF - Lab #4 CSRF where token is not tied to user session | Short Version

Поделиться
HTML-код
  • Опубликовано: 27 сен 2024
  • In this video, we cover Lab #4 in the CSRF module of the Web Security Academy. This lab's email change functionality is vulnerable to CSRF. It uses tokens to try to prevent CSRF attacks, but they aren't integrated into the site's session handling system. To solve the lab, use your exploit server to host an HTML page that uses a CSRF attack to change the viewer's email address.
    ▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
    Buy my course: academy.ranakh...
    ▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
    CSRF Lab #4 long video: • CSRF - Lab #4 CSRF whe...
    Notes.txt document: github.com/rkh...
    CSRF theory video: • Cross-Site Request For...
    Web Security Academy RUclips Video Series Release Schedule: docs.google.co...
    Web Security Academy: portswigger.ne...
    Rana's Twitter account: / rana__khalil

Комментарии • 14

  • @AJ_23510
    @AJ_23510 4 месяца назад

    I love how detailed you do these tutorials and the way you use a check list when examining these vulnerabilities! You definitely got my subscription

  • @youtubevideostorage3381
    @youtubevideostorage3381 3 года назад +1

    I'm a big big fan of our work. I can't thank you enough for this series. May god bless you with great health and fortune.

  • @jaywandery9269
    @jaywandery9269 11 месяцев назад +1

    good work

  • @jackhack1234
    @jackhack1234 2 года назад

    Very good explanation. Thank you.

  • @exploitplays3835
    @exploitplays3835 2 года назад

    amazing explanation

  • @FahadAli-ot5kn
    @FahadAli-ot5kn Год назад

    awasome tutorial

  • @落珰
    @落珰 Год назад

    Thank you

  • @bradsen
    @bradsen 6 месяцев назад

    Hi Rana, thanks for the explanation. May I know why the CSRF Token in Forms or Requests is different from the CSRF Token in chrome browser's Network Tab?

    • @bradsen
      @bradsen 6 месяцев назад

      I know the answer. The CSRF token in the form is to be used for subsequent requests. Which is reflected in the browser network tab 😂

  • @ashiqhussainkumar1391
    @ashiqhussainkumar1391 3 года назад

    Asa lamu elykum Mam,
    Do u have any course on security in DJANGO

  • @jwd42
    @jwd42 Год назад

    For that we need victim account in real world

  • @cybersecurity7577
    @cybersecurity7577 3 года назад

    انتي فلسطينية ليش كورساتك بل انجليزي 🙂💔

  • @cair0_
    @cair0_ 2 года назад

    6:36 that's a wrong assumption dear since it's refered in the lab that both accounts is yours + why would u make a csrf attack on carlos if u have his credintials ! 😆😆

  • @TRASH_Z403
    @TRASH_Z403 6 месяцев назад

    Thankyou so much ❤