ArticleCSRF where token is duplicated in cookie
CSRF where token is duplicated in cookie: This lab contains a blind SQL injection vulnerability. The application uses a tracking cookie for analytics…
Practical security research, write-ups, guides, and lessons learned.
ArticleCSRF where token is duplicated in cookie: This lab contains a blind SQL injection vulnerability. The application uses a tracking cookie for analytics…
ArticleCSRF where token validation depends on request method: This lab's email change functionality is vulnerable to CSRF. It attempts to block CSRF attacks…
ArticleCSRF where token is not tied to user session: CSRF Email Change Lab This lab's email change functionality is vulnerable to CSRF. It uses tokens to tr…
ArticleCSRF vulnerability with no defenses: This lab's email change functionality is vulnerable to CSRF. • PortSwigger • CSRF • csrf, lab1
ArticleCSRF where token validation depends on token being present: This lab’s email change functionality is vulnerable to CSRF. • PortSwigger • CSRF • lab3,…
ArticleBasic clickjacking with CSRF token protection: This lab combines CSRF protection with a Clickjacking defense by requiring both a CSRF token and a con…
ArticleExploiting clickjacking vulnerability to trigger DOM based XSS: This lab contains an XSS vulnerability that is triggered by a click. • PortSwigger •…
ArticleLearn how a PostgreSQL UNION based SQL injection can reveal tables, columns, usernames, and passwords in a controlled PortSwigger lab, leading to adm…
ArticleSQL injection attack, querying the database type and version on Oracle: This lab contains a SQL injection vulnerability in the product category filte…
ArticleClickjacking with form input data prefilled from a URL parameter: This lab extends the basic clickjacking example in Lab: Basic clickjacking with CSR…
ArticleBasic clickjacking with CSRF token protection: To solve the lab, craft some HTML that frames the account page and fools the user into deleting their…
ArticleClickjacking with a frame buster script: This lab is protected by a frame buster which prevents the website from being framed. • PortSwigger • Clickj…