Business Logic Vulnerabilities - Lab #7 Weak isolation on dual-use endpoint | Long Version

  Рет қаралды 837

Rana Khalil

Rana Khalil

Күн бұрын

Пікірлер
@RanaKhalil101
@RanaKhalil101 8 ай бұрын
🚀Ready to level up your web security game? Unlock 15 courses and over 50 hours of content with our All-Access Membership for just $1/day: academy.ranakhalil.com/p/all-access-membership 🌟
@MustafaGains
@MustafaGains 8 ай бұрын
Thx! 🙏 excuse me Rana i have a small question , Is it a vulnerability like if we created 2 accounts A and B and swapped only the (sessionsID) of account B to account A and send the request from account A which gonna return 200 OK and let us access account B ? . While keeps every things else as its such CSRF,accountID,middleware without changing them. Lookin patiently for your response.
@RanaKhalil101
@RanaKhalil101 8 ай бұрын
No that's not a vulnerability. The session id is what authenticates and authorizes the user and so if you swap it, it should present you with the user that is tied to that session id.
@nishantdalvi9470
@nishantdalvi9470 7 ай бұрын
@@RanaKhalil101 Can we see scenarios similar to the one which is been portrayed within this lab in real world web applications ? Waiting for your reply patiently
@IcodeCpp
@IcodeCpp 22 күн бұрын
Are Muslims allowed to earn money from KZbin ads? Because they show ads for gambling.
Beat Ronaldo, Win $1,000,000
22:45
MrBeast
Рет қаралды 158 МЛН
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
Business Logic Vulnerabilities | Complete Guide
18:58
Rana Khalil
Рет қаралды 8 М.
Beat Ronaldo, Win $1,000,000
22:45
MrBeast
Рет қаралды 158 МЛН