Hello! Little confuse........For this vulnerability we need victim account for capturing csrf token??????????
@intigriti Жыл бұрын
CSRF tokens are used to prevent CSRF attacks. If a site implements CSRF tokens, an attacker would need to get around that..
@vishaalkumaranandan2894 Жыл бұрын
can this be done without burpsuite pro as I am not having it, if yes how to get the csrf html alone
@intigriti Жыл бұрын
Unfortunately not 😑 In real-world scenario, you would use your own server (or ngrok, requestbin etc) *but* portswigger only allow the use of burp collaborator for the WebSecAcademy labs, so you need burp pro. You can sign up for a free trial, if you haven't used it already..
@alan.m.rebeira3 жыл бұрын
Can you guys make an video about sql injection with the help of portswigger sql injection cheat sheet
@intigriti3 жыл бұрын
The SQL injection module will come in the future! Look out for further videos!