CSRF where token is tied to non-session cookie (Video solution, Audio)

  Рет қаралды 22,158

Michael Sommer

Michael Sommer

Күн бұрын

Пікірлер: 25
@ali-wz6nz
@ali-wz6nz Ай бұрын
00:08 - Understanding session cookies and their impact on web security. 01:08 - Understanding CSRF with Non-Session Cookies and Parameters 02:26 - Updating email addresses in application settings 03:36 - Demonstrating CSRF token validation with non-session cookies in a browser environment. 04:54 - Exploration of browser interactions and CSRF prevention strategies. 06:03 - Overview of CSRF token security challenges with non-session cookies. 07:22 - Using proxy tools for CSRF token generation. 09:23 - Discussion on how cookies impact CSRF security.
@fannah24
@fannah24 3 жыл бұрын
For those who are struggling to understand the payload, search 'CRLF Injection Attack', or visit CRLF on geeksforgeeks
@venomhacks1322
@venomhacks1322 3 жыл бұрын
0 explanation
@2os5
@2os5 3 жыл бұрын
true
@alonsocorrea1256
@alonsocorrea1256 3 жыл бұрын
i think that you could explain the impact of this way to exploit CSRF
@mamunurrashid9022
@mamunurrashid9022 3 жыл бұрын
I didn't understand why you copied session & csrfkey and save it on notepad, you didn't do anything with it later.!
@some_user6929
@some_user6929 3 жыл бұрын
I'm glad you also spotted that. At 9:50 in csrfKey he should paste csrfKey from dropped in Burp's Repeater request and also from that request should copy csrf value and paste it to form .html.
@zipp5022
@zipp5022 3 жыл бұрын
my email address gets changed but still the lab isnt solved....
@rud8716
@rud8716 2 жыл бұрын
us bro us
@zipp5022
@zipp5022 2 жыл бұрын
@@rud8716 the struggle is real bro, but it got solved eventually :)
@rud8716
@rud8716 2 жыл бұрын
@@zipp5022 bro what did you do, because I am also facing same problem
@zipp5022
@zipp5022 2 жыл бұрын
@@rud8716 i wish i could help, but i solved it over a month ago, i dont exactly remember what happened, but it got solved, this lab is a big pain in the ass 😮‍💨😮‍💨
@JollyRogers-vp5yn
@JollyRogers-vp5yn Жыл бұрын
About the end of the video, in POC, you should put your csrf token on line 8 (name="csrf" value="your csrf token" This will resolve lab😊
@axeldelgadillo9838
@axeldelgadillo9838 Жыл бұрын
you and rana khalil are the best
@hexbrokers9115
@hexbrokers9115 3 жыл бұрын
my firefox private icognito not load foxyproxy add on for proxying
@mamunurrashid9022
@mamunurrashid9022 3 жыл бұрын
you need to give permission
@mushtaqueahmed6949
@mushtaqueahmed6949 10 ай бұрын
Why you copied and paste csrfKey in PoC from same request. you should copy scrf from attacker request and paste in PoC
@EmilyAnn
@EmilyAnn Жыл бұрын
goddamit! this is not that difficult so why isn't this working for me??
@lie-be4277
@lie-be4277 5 ай бұрын
same problem. i inspected packets and realized cookie is not changing.
@Fth.44
@Fth.44 8 ай бұрын
Bu videodaki her şeyi defalarca yapmama rağmen bir türlü çözemedim tek tek not ediyorum nafile
@sayeu1444
@sayeu1444 10 ай бұрын
confusing af
@Mr.Hoque.
@Mr.Hoque. Жыл бұрын
Very confusion video
Ozoda - Alamlar (Official Video 2023)
6:22
Ozoda Official
Рет қаралды 10 МЛН
She wanted to set me up #shorts by Tsuriki Show
0:56
Tsuriki Show
Рет қаралды 8 МЛН
Dear Engineers: NOW is the time to lead.
14:23
David Malawey
Рет қаралды 2,2 М.
CSRF where token is not tied to user session (Video solution, Audio)
6:42
CSRF where token is duplicated in cookie (Audio, Comments)
8:11
Michael Sommer
Рет қаралды 2,7 М.
This free Chinese AI just crushed OpenAI's $200 o1 model...
4:41
Fireship
Рет қаралды 1,1 МЛН
Session Vs JWT: The Differences You May Not Know!
7:00
ByteByteGo
Рет қаралды 328 М.
Session vs Token Authentication in 100 Seconds
2:18
Fireship
Рет қаралды 1,1 МЛН