Security article
CSRF - where token is not tied to user session
CSRF - where token is not tied to user session: This lab's email change functionality is vulnerable to CSRF. It uses tokens to try to prevent CSRF attacks, but they aren't integrated into the site's session handling system. • Security • CSRF • csrf, security
Lab: CSRF where token is not tied to user sessionThis lab's email change functionality is vulnerable to CSRF. It uses tokens to try to prevent CSRF attacks, but they aren't integrated into the site's session handling system.
To solve the lab, use your exploit server to host an HTML page that uses a CSRF attack to change the viewer's email address.
the purpose of this lab is to update carlos email by use someone else CSRF token example ‘Wiener’csrf.Testcase#1 Verify if you can change HTTP request method 404. Testcase#2
#Verify if you could strip the CSRF-token from characters but no success=(Testcase#3
intercept the request where you update the email for ‘Wiener’ and use the CSRF token from ‘Carlos’.