Lab: CSRF with SameSite Lax BYPASS via method override
Описание
In this lab I show you how you can perform a CSRF attack with a SameSite Lax bypass by overriding the Request Method with a hidden input parameter.
TRY IT YOURSELF
https://portswigger.net/web-security/csrf/bypassing-samesite-restrictions/lab-samesite-lax-bypass-via-method-override
FINAL PAYLOAD
https://pastebin.com/mM3GxtdP
TIMESTAMPS
00:00 - Intro
00:55 - Analyze the session cookie and change email request in Burp
01:38 - Look at the SameSite attribute within the developer console
02:06 - POST request CSRF payload
02:31 - Deliver POST request CSRF payload
03:39 - Try a GET request instead
04:05 - Try Request Method Spoofing
05:23 - Deliver the spoofed request method CSRF payload
REFERENCES
https://chromestatus.com/feature/5088147346030592
https://laravel.com/docs/5.0/routin #method-spoofing
COOKIE EDITOR EXTENSION
https://chrome.google.com/webstore/detail/cookie-editor/hlkenndednhfkekhgcdicdfddnkalmdm
https://addons.mozilla.org/en-US/firefox/addon/cookie-editor/
Рекомендуемые видео


















