CSRF - Lab #2 CSRF where token validation depends on request method | Short Version

  Рет қаралды 22,640

Rana Khalil

Rana Khalil

Күн бұрын

Пікірлер: 21
@RanaKhalil101
@RanaKhalil101 3 жыл бұрын
Interested in supporting me and gaining early access to the Web Security Academy videos when they're recorded? Consider buying my course: academy.ranakhalil.com/p/web-security-academy-video-series! ✨ ✨
@frolicfox5432
@frolicfox5432 3 жыл бұрын
First things first!! Hats off Mrs. Rana Khalil for this swashbuckling video series!! Ur elucidation of this concept is amazing which made my brain store it so easily! Can't wait for ur other lectures on various portswigger labs as am madly waiting for clickjacking series!! This channel is definitely the next big thing and truly a pentester's delight!! May Allah serve you the best always and bless you! Happy if I receive a reply from you madam!
@Gurumoorthi-u2c
@Gurumoorthi-u2c 2 ай бұрын
well Explained 👍
@hellohi5814
@hellohi5814 25 күн бұрын
You already changed the email at “2:30” and it was updated, so what’s the point I didn’t get it ?
@落珰
@落珰 Жыл бұрын
thank. I will follow your course
@S2eedGH
@S2eedGH 2 жыл бұрын
thanks a lot, Can you please explain more about the third condition (no unpredictable request parameters) ? at 03:34
@elinamk12
@elinamk12 3 ай бұрын
big thanks to community
@deadeye821
@deadeye821 3 жыл бұрын
which cookie editor do u use and how to install it?
@brucebane7401
@brucebane7401 2 жыл бұрын
amazing!!!!!
@_____pd____5919
@_____pd____5919 3 жыл бұрын
🔥🔥🔥
@etc.4792
@etc.4792 Жыл бұрын
i'm followed all of your process but my lab is not solving and not congratulated me. please give me solution
@heyybigdaddy6988
@heyybigdaddy6988 5 ай бұрын
did it work for you?
@naveenrawat1549
@naveenrawat1549 5 ай бұрын
First store then view and then deliver
@heyybigdaddy6988
@heyybigdaddy6988 5 ай бұрын
​@@naveenrawat1549 nah. It was due to LAX being implemented in all the browsers. This video is old and doesn't tell you to add %3b%20SAMESITE=NONE after your csrf key.
@naveenrawat1549
@naveenrawat1549 5 ай бұрын
@@heyybigdaddy6988 ohh I got it but have you done same session csrf key I got stuck there
@naveenrawat1549
@naveenrawat1549 4 ай бұрын
@@heyybigdaddy6988 brother help me how do I put this I am just after csrf key or somewhere else ? I mean if csrf= abcd12 then where do I put this
@落珰
@落珰 Жыл бұрын
thank
@rafinrahmanchy
@rafinrahmanchy 3 жыл бұрын
Use the term "Exploitability" besides of "Analysis". It suites better
@saikrishnapuli6591
@saikrishnapuli6591 2 жыл бұрын
without deleting csrf token in the post method i have changed mail id and it worked
@bishalshrestha3880
@bishalshrestha3880 3 жыл бұрын
First 😳
@thesecuritypoint
@thesecuritypoint 3 жыл бұрын
Second
Creative Justice at the Checkout: Bananas and Eggs Showdown #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 34 МЛН
How To Choose Mac N Cheese Date Night.. 🧀
00:58
Jojo Sim
Рет қаралды 115 МЛН
When Cucumbers Meet PVC Pipe The Results Are Wild! 🤭
00:44
Crafty Buddy
Рет қаралды 63 МЛН
I thought one thing and the truth is something else 😂
00:34
عائلة ابو رعد Abo Raad family
Рет қаралды 16 МЛН
CSRF where token is not tied to user session (Video solution, Audio)
6:42
CSRF - Lab #1 CSRF vulnerability with no defenses | Short Version
11:41
Lab: CSRF with SameSite Lax BYPASS via method override
6:05
Jarno Timmermans
Рет қаралды 4,4 М.
Creative Justice at the Checkout: Bananas and Eggs Showdown #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 34 МЛН