How To Search For CSRF!

  Рет қаралды 36,177

Intigriti

Intigriti

Күн бұрын

Пікірлер: 28
@igbinosuneric
@igbinosuneric 2 жыл бұрын
they say you learn by doing. did not understand CSRF still I did this tutorial, plus I don't have burp bro so I modify the HTML template to look like yours. keep it up, guys
@intigriti
@intigriti 2 жыл бұрын
We are glad to hear that you are learning from our videos 😇 Good luck on your journey!
@bertrandfossung1216
@bertrandfossung1216 3 жыл бұрын
I love intigriti. We'll start hunting on that platform soon. Thank you for all you do to make us better Security reserchers. Great video. My best bug class. CSRF 🔥🔥🔥🔥
@intigriti
@intigriti 3 жыл бұрын
Niiiice, we are looking forward to welcoming you on our platform 🥳.
@dennismunyaka6537
@dennismunyaka6537 3 жыл бұрын
intigiriti not a bad platform. only problem for me is the language barrier haha
@fahadfaisal2383
@fahadfaisal2383 3 жыл бұрын
Nice man . Keep it going
@intigriti
@intigriti 3 жыл бұрын
Thanks, will do!
@KarolPosiewała
@KarolPosiewała 9 ай бұрын
You are great! Keep good work. I hope you now you are helping lots of ppl to turn around their lives :)
@intigriti
@intigriti 9 ай бұрын
🙏🥰
@Sana123236
@Sana123236 7 ай бұрын
do you know which software is this?
@MCTorse
@MCTorse Жыл бұрын
Hey! The video is very useful, thank you! I have a question, how do we know which request headers to remove?
@intigriti
@intigriti Жыл бұрын
Generally speaking you will have to learn what the different request headers are used for. You can always send the request to Burp's repeater and start by removing individual headers to see what happens, playing around with them.
@dustinjoosen5901
@dustinjoosen5901 6 ай бұрын
Thanks. I had a lot of issues with this lab
@intigriti
@intigriti 6 ай бұрын
Glad it helped!
@HerbertEduardoFernandezTamayo
@HerbertEduardoFernandezTamayo 2 жыл бұрын
great walkthrough, thanks a lot. Question: if the webapp use JWT instead of session's cookies, this means the application is totally immune to CSRF attack?
@intigriti
@intigriti 2 жыл бұрын
Pretty much yes. If your application uses an authorization header which is not automatically set by the browser (such as cookies and basic auth), there is chance for CSRF.
@Sana123236
@Sana123236 7 ай бұрын
@0.33 Which application is this? newbie here
@intigriti
@intigriti 7 ай бұрын
Hey! You wanting to know which portswigger lab it is? If so, it's portswigger.net/web-security/csrf/lab-no-defenses but if you are wondering what tool is shown there, it's burp suite (also by portswigger) 🙂
@Sana123236
@Sana123236 7 ай бұрын
@@intigriti Thank you so much for your quick response!
@AnthonyMcqueen1987
@AnthonyMcqueen1987 2 жыл бұрын
Pure gold
@intigriti
@intigriti 2 жыл бұрын
⭐️
@paulojr1384
@paulojr1384 2 жыл бұрын
many tnx
@intigriti
@intigriti 2 жыл бұрын
You are very welcome ❤️
@mehrankurd
@mehrankurd 19 күн бұрын
great
@lethalleet
@lethalleet 3 жыл бұрын
First again
@intigriti
@intigriti 3 жыл бұрын
🏎
@落珰
@落珰 Жыл бұрын
Thank you. intigriti
@intigriti
@intigriti Жыл бұрын
Of course 💪
How To Circumvent CSRF Protection!
8:01
Intigriti
Рет қаралды 12 М.
How To Search For DOM-Based XSS!
9:37
Intigriti
Рет қаралды 51 М.
Smart Sigma Kid #funny #sigma
00:33
CRAZY GREAPA
Рет қаралды 36 МЛН
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 10 МЛН
99.9% IMPOSSIBLE
00:24
STORROR
Рет қаралды 25 МЛН
Creative Justice at the Checkout: Bananas and Eggs Showdown #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 35 МЛН
Cross Site Request Forgery - Computerphile
9:20
Computerphile
Рет қаралды 771 М.
How To Circumvent SSRF Protection!
9:15
Intigriti
Рет қаралды 10 М.
CSRF - how to find it in 2024? CSRF bug bounty case study
15:29
Bug Bounty Reports Explained
Рет қаралды 8 М.
How to exploit a blind SSRF?
9:36
Intigriti
Рет қаралды 24 М.
BUG BOUNTY HUNTING: FINDING CROSS SITE REQUEST FORGERY LIVE
12:01
What is Clickjacking?
8:06
Intigriti
Рет қаралды 53 М.
CSRF Introduction and what is the Same-Origin Policy? - web 0x04
10:25
Smart Sigma Kid #funny #sigma
00:33
CRAZY GREAPA
Рет қаралды 36 МЛН