Learn Cross-Site Request Forgery (CSRF) From Scratch + FREE Training

Поделиться
HTML-код
  • Опубликовано: 29 июн 2024
  • This video will teach you the basics of Cross-Site Request Forgery or CSRF vulnerabilities, how to discover them and how to exploit them in a real-life practical example.
    🔴 Snyk's FREE training and CTF signup link👇
    snyk.co/ctf-zsecurity
    🧠 My Hacking Masterclass👇
    zsecurity.org/courses/masterc...
    🧠 My other hacking courses 👇
    zsecurity.org/courses/
    🌟 VIP Membership 👇
    zsecurity.org/vip-membership/
    ---------------------------------------------------------------
    zSecurity Company - zsecurity.com/
    Community - zsecurity.org/
    Facebook - / zsecurity-145325078145...
    Twitter - / _zsecurity_
    Instagram - / zsecurity_org
    Linkedin - / zsecurity-org
    TikTok - / zsecurity_org
    ---------------------------------------------------------------
    Time Stamps:
    00:00 - intro
    00:45 - What is Broken Access Control?
    01:58 - CSRF Explained
    02:27 - How to Discover CSRF
    11:07 - Where to Practice CSRF
    11:24 - More FREE Training
    -------------------------
    🎯 Target Website Link 👇
    portswigger.net/web-security/...

Комментарии • 72

  • @zSecurity
    @zSecurity  8 месяцев назад +7

    FREE training from Snyk & Participate in their CTF to win a Nintendo Switch👇
    snyk.co/ctf-zsecurity

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      First. :3

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      Sweet! :3 One of my favourite ethical hacker teachers. :3

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      Very weird. HamASS has support from Russia, when Russia said it's pro-Jew before, and that's one of the reasons why they invaded Ukraine, to fight anti-Semitism. HamASS said, Putin sympathises with us. Turkey, a moderate Muslim nation, that many Muslims don't find true Muslims for how moderate they are, a NATO member, sympathises with HamASS.
      Even at Harvard, several students with pro-Palestine protests, and saying to gas the Jews. I wonder if they will gas Drake, the rapper, the Harry Potter actor they love, Madonna, the Family Guy and American Dad founder, Einstein, if he was alive, Stephen Spielberg, the founders of most comics, the people that made Starbucks that many love to drink so much, Bruno Mars, the lady that inspired and helped Tupac, etc.
      I wonder if these self-entitled Whites, and other non-Natives, will take their own advice, and leave North America. I wonder if Pakistan will give back that massive amount of land they, Arab Muslims, stole from India. Israel has shared that land for 3,500+ years. Tel Aviv has a photo of itself in 1909, wayyyy before the 1940s. We even have the Palestinian flag with the Jewish Star of David on it beforeeee the 1940s.
      What about the invasions of Arab Muslims into Spain, parts of Africa, etc.? Hmmmm. How convenient.
      While America has predominantly Whites shooting up schools because no one cares to safeguard schools. 300-600+ students a year killed, plus teachers, and others.
      Well, at least there's less racist, self-entitled, fat, drug addicted Americans from these kids getting shot, bright side of it all.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      :3 Persia especially is hurting. They got invaded by Arab Muslims, and became, unfortunately, a Muslim nation, toxicity. They don't allow journalists, and protestors that they don't like. Those people get killed. At least Israel has several Arabs with rights, and jobs in Israel. West Bank doesn't have this radicalism, and has far more people.
      I've been meaning to hack HamASS, but he's gonna thankfully be dead soon since he doesn't want any peace, and wants all Jews dead. Iran, Hezbollah, and others are still targets. Some of the best hackers are Israeli, too. Dark Net Diaries are great podcasts here on RUclips, and Israel gets plenty of love there for ethical hacking.

  • @ATTIQOP
    @ATTIQOP 8 месяцев назад +40

    bro would teach anything and say its for educational purposes only what a humble person ❤️

    • @hawkeye3101
      @hawkeye3101 8 месяцев назад +11

      Bro doing the Lord's work. Appreciate and move on sir.

    • @ATTIQOP
      @ATTIQOP 8 месяцев назад

      @@hawkeye3101 yeah

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      ​@@hawkeye3101Lord Buddha. Not any toxic, especially Islamic, Abrahamic, unoriginal, very debunked religion. XD
      Spiritual, and anti-religion.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад +2

      Well, it's an ethical hacking channel, and he works in cybersecurity. Plus, you have to say that in order to put hacking videos without worry of your video. Lol. If you don't like it, don't be here.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      :3 Very weird. HamASS has support from Russia, when Russia said it's pro-Jew before, and that's one of the reasons why they invaded Ukraine, to fight anti-Semitism. HamASS said, Putin sympathises with us. Turkey, a moderate Muslim nation, that many Muslims don't find true Muslims for how moderate they are, a NATO member, sympathises with HamASS.
      Even at Harvard, several students with pro-Palestine protests, and saying to gas the Jews. I wonder if they will gas Drake, the rapper, the Harry Potter actor they love, Madonna, the Family Guy and American Dad founder, Einstein, if he was alive, Stephen Spielberg, the founders of most comics, the people that made Starbucks that many love to drink so much, Bruno Mars, the lady that inspired and helped Tupac, etc.
      I wonder if these self-entitled Whites, and other non-Natives, will take their own advice, and leave North America. I wonder if Pakistan will give back that massive amount of land they, Arab Muslims, stole from India. Israel has shared that land for 3,500+ years. Tel Aviv has a photo of itself in 1909, wayyyy before the 1940s. We even have the Palestinian flag with the Jewish Star of David on it beforeeee the 1940s.
      What about the invasions of Arab Muslims into Spain, parts of Africa, etc.? Hmmmm. How convenient.
      While America has predominantly Whites shooting up schools because no one cares to safeguard schools. 300-600+ students a year killed, plus teachers, and others.
      Well, at least there's less racist, self-entitled, fat, drug addicted Americans from these kids getting shot, bright side of it all.

  • @hahaboi
    @hahaboi 8 месяцев назад +1

    Hats off for your hardworking.

  • @GilaArts
    @GilaArts 8 месяцев назад +4

    I enrolled your paid course the course is very help full for me keep it

  • @JLREQ195
    @JLREQ195 4 месяца назад

    Hey I bought u course and I just wanted to say that I’ve definitely learned quite a few things

  • @flopya
    @flopya 8 месяцев назад +1

    😮😮😮😮😮❤❤❤❤❤
    Thanks, been a long timer though 😅

  • @SumanRoy.official
    @SumanRoy.official 8 месяцев назад +5

    please use dark mode while making videos! please use dark reader if you are using browser to demo stuff,

  • @GHOST-hv8ou
    @GHOST-hv8ou 8 месяцев назад +1

    actually can you make video explaining us what is osi model because i really treid to understand it well but i can't?

  • @AgborTakorPius
    @AgborTakorPius 8 месяцев назад +8

    thanks Mr Zaid. i have like six of your courses i bought from udemy. thank you so much for your effort you put in to teach the world what you know.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      :3 Very weird. HamASS has support from Russia, when Russia said it's pro-Jew before, and that's one of the reasons why they invaded Ukraine, to fight anti-Semitism. HamASS said, Putin sympathises with us. Turkey, a moderate Muslim nation, that many Muslims don't find true Muslims for how moderate they are, a NATO member, sympathises with HamASS.
      Even at Harvard, several students with pro-Palestine protests, and saying to gas the Jews. I wonder if they will gas Drake, the rapper, the Harry Potter actor they love, Madonna, the Family Guy and American Dad founder, Einstein, if he was alive, Stephen Spielberg, the founders of most comics, the people that made Starbucks that many love to drink so much, Bruno Mars, the lady that inspired and helped Tupac, etc.
      I wonder if these self-entitled Whites, and other non-Natives, will take their own advice, and leave North America. I wonder if Pakistan will give back that massive amount of land they, Arab Muslims, stole from India. Israel has shared that land for 3,500+ years. Tel Aviv has a photo of itself in 1909, wayyyy before the 1940s. We even have the Palestinian flag with the Jewish Star of David on it beforeeee the 1940s.
      What about the invasions of Arab Muslims into Spain, parts of Africa, etc.? Hmmmm. How convenient.
      While America has predominantly Whites shooting up schools because no one cares to safeguard schools. 300-600+ students a year killed, plus teachers, and others.
      Well, at least there's less racist, self-entitled, fat, drug addicted Americans from these kids getting shot, bright side of it all.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      Zaid is a badass.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      HamASS says they can hold off 100k Israeli ground troops with only 15k-20k terrorists of HamASS. Well, I don't think they're Sparta, and Sparta were respectable people who kept getting attacked by greedy people, unlike HamASS that doesn't like people who've had shared land there for at least 3,500 years. Lol.
      A GIF even shows Tel Aviv in 1909, and you find the Palestinian flag GIF with the Jewish star in the middle, way before the 1940s ever happened. Lol. So much for the European colonialists in North America, and all the Whites, and other non-Natives still there with their whole talk about Israel never existing. Lolololol. HamASS would destroy most of them for women not covering their faces, anyone who isn't straight, death cult apostasy laws, etc.
      Israel actually employs Arabs, and there are Jews living in Gaza, and in the West Bank, too. Just as Jews live in several Arab nations. HamASS is just racist, and wants all Jews gone from the Earth, but Fatah didn't.
      Even if he can handle ground troops, Israel, among other allies, can just blow up every last building. Gaza will be the world's largest parking lot, as we say.
      Then, we could build back Gaza to look better than it did before. Restore homes to Arabs, and Jews there, and monitor streets tightly for terrorist formations again. That's assuming Netanyahu wants a two-state solution instead of just divide, and war.
      America has billions of dollars, too. They could renovate all of Gaza and West Bank, and make shared land. To put patrol on all streets to fight terrorism, and Muslims hurting non-Muslims (Qur'wrong 2:191, among other verses to take care of non-Muslims).
      HamASS has to go, because he doesn't want a two-state solution. Egypt doesn't even want any Palestinians, any. 🤣🤣🤣🤣🤣Jewish people showing more sympathy than their own Arabs, and own Muslims. XD 🤣🤣🤣🤣🤣🤣🤣🤣💩💩🎪🤡😅💀
      :3

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 месяцев назад

      Persia especially is hurting. They got invaded by Arab Muslims, and became, unfortunately, a Muslim nation, toxicity. They don't allow journalists, and protestors that they don't like. Those people get killed. At least Israel has several Arabs with rights, and jobs in Israel. West Bank doesn't have this radicalism, and has far more people.
      I've been meaning to hack HamASS, but he's gonna thankfully be dead soon since he doesn't want any peace, and wants all Jews dead. Iran, Hezbollah, and others are still targets. Some of the best hackers are Israeli, too. Dark Net Diaries are great podcasts here on RUclips, and Israel gets plenty of love there for ethical hacking.

    • @chorkaniitv3386
      @chorkaniitv3386 8 месяцев назад

      Bro how do u buy this courses

  • @user-nb1me1gq2k
    @user-nb1me1gq2k 8 месяцев назад +2

    Zaidh sir please make a course on Android app hacking

  • @KingLee-ct2kk
    @KingLee-ct2kk 8 месяцев назад

    Can you talk about open bullet config tool?

  • @AgborTakorPius
    @AgborTakorPius 8 месяцев назад

    am here sir

  • @nikenhukubhayy
    @nikenhukubhayy 8 месяцев назад

    Is there any way to listen live voice recording of other device is there any mobile setting or playstore app ??

  • @OlivierMedor
    @OlivierMedor 8 месяцев назад

    How often can someone find CSRF vulnerability in a larger site such as RUclips?

  • @soTarkyyy
    @soTarkyyy 23 дня назад

    One question from my site, how the HTML requests recognizes that It should do it for the user Carlos now? I mean there was no Id oder email changed in the HTML. Or is this attack just supposed to work on the same machine? Because I mean then I could directly go to the page where Carlos is logged in and change the email? Or do I have understood here something wrong? Thank you for your answers

  • @m1ark2013axiot
    @m1ark2013axiot 2 месяца назад +1

    Can you tell me a free tool who does the same job as Octopus for sms please?

  • @somnathjadhav2869
    @somnathjadhav2869 8 месяцев назад

    Sir , make video on installation kali linux on windows 11 step vise please.
    Your videos are vey amazing.
    Please make the video on it...
    Lot of love ....😻💖

    • @Pro-Balak-Senpai
      @Pro-Balak-Senpai 3 месяца назад

      thats the easiest shit to ever exist u need a tutorial for that ? 💀💀

  • @Adil_sheikh
    @Adil_sheikh 8 месяцев назад +1

    Brother, you make very good videos but because your video is in English, I am not able to understand it properly and there are many subscribers who have this problem. So can you put an audio track on your video?

    • @Sanatan_khaniya
      @Sanatan_khaniya 8 месяцев назад +1

      I am totally satisfied with you.

  • @accountfor-yt2rw
    @accountfor-yt2rw 4 месяца назад

    And won't there be a problem with the repositories in Kali 2020 iso
    ?

  • @narutouzmaki2395
    @narutouzmaki2395 7 месяцев назад

    Mr Zaid, I have taken your course 'Learn Ethical Hacking From Scratch' but I can't install Veil in my Kali Linux can you please tell me how to install it it

  • @sanskar6398
    @sanskar6398 4 месяца назад

    2022 custom Kali on your website is corrupted, please upload new one.

  • @alchamistoh1627
    @alchamistoh1627 4 месяца назад

    So this only works if the token for CSRF is not verified?

  • @GymMaster_Pro
    @GymMaster_Pro 7 месяцев назад

    I want to see hacking mastering class play list but it doesn't work what is wrong i follow your channel program for several time but it ask me for member what is wrong

  • @CloudSec101
    @CloudSec101 8 месяцев назад

    need these type of videos for all OWASP top 10.

    • @zSecurity
      @zSecurity  8 месяцев назад +1

      It's all in my bug bounty course! This video is actually taken from it.

    • @timecop1983Two
      @timecop1983Two 8 месяцев назад

      @@zSecurity wow I am going to do his Udemy course! zSecurity

  • @imahsansyed
    @imahsansyed 6 месяцев назад

    Hey, I know that its hard to reply for comments but I have a question
    I have my google ID and password but I couldn't sign in into my account
    I have no 2fa enabled, no recovery phone or email in my account
    When I try to login it says, to login from device I logged in earlier (not available),sign in from same network(which isn't also available)
    What to do

  • @call-me-potato.
    @call-me-potato. 8 месяцев назад

    hi , sorry it doesnot make any sense , which website shows emails of other accounts? so how does concept of email takeover works? could you please explain whats purpose of this CSR?

    • @Hackerjedi
      @Hackerjedi 6 месяцев назад

      finding emails of other accounts is not that difficult, you can use tools like maltego or any other social engineering tool, its explained in the zaid's social engineering course.

  • @mnageh-bo1mm
    @mnageh-bo1mm 8 месяцев назад

    darn bro u forget the cookies part

  • @chmun77
    @chmun77 8 месяцев назад

    Hi. This is a very interesting video. However, I'm kind of confused how the CSRF works in the video. You have already logged out from wiener account and then logged in again as carlos. So it seems to me that you are updating carlos email address because you are currently connected as carlos, which I think that's normal since you are using carlos session on the server? I was hoping to see that you are able to change the wiener's email address from carlos session but it doesn't seems so. Will you be able to update either wiener's or carlos email addresses without logging into the system? Am I misunderstanding the objective of this video? Thanks.

    • @zSecurity
      @zSecurity  8 месяцев назад

      Yes so Wiener crafter a request (forget a request). This request is being submitted by Carlos, the application is trusting Carlos and letting him change his email even though he did not actually make that request. As a result Wiener can get Carlos to change their email an email that Weiner controls, resulting in an account takeover.

  • @alexanderaghukwa3854
    @alexanderaghukwa3854 8 месяцев назад

    Zaid’s lord sent

  • @ayush_vlogs108
    @ayush_vlogs108 7 месяцев назад

    Bro a company had cheated me of money 3000 plz... Help!

  • @bakasenpaidesu
    @bakasenpaidesu 8 месяцев назад +1

    .

  • @nsricharan1679
    @nsricharan1679 8 месяцев назад

    CCTV hack in Android

  • @basilxe9174
    @basilxe9174 8 месяцев назад +3

    history of palestine

    • @onlychouaib
      @onlychouaib 8 месяцев назад

      yeah why he removed the video?

  • @MidnightSpecter43
    @MidnightSpecter43 8 месяцев назад

    confusing

    • @timecop1983Two
      @timecop1983Two 8 месяцев назад

      Then you should not become an ethical hacker 😮‍💨

  • @shubham_srt
    @shubham_srt 5 месяцев назад

    trash