Город МОСКОВСКИЙ
00:06:04

Lab: CSRF with SameSite Lax BYPASS via method override

Аватар
JavaScript для всех
Просмотры:
28
Дата загрузки:
29.11.2023 15:58
Длительность:
00:06:04
Категория:
Технологии и интернет

Описание

In this lab I show you how you can perform a CSRF attack with a SameSite Lax bypass by overriding the Request Method with a hidden input parameter.

TRY IT YOURSELF
https://portswigger.net/web-security/csrf/bypassing-samesite-restrictions/lab-samesite-lax-bypass-via-method-override

FINAL PAYLOAD
https://pastebin.com/mM3GxtdP

TIMESTAMPS
00:00 - Intro
00:55 - Analyze the session cookie and change email request in Burp
01:38 - Look at the SameSite attribute within the developer console
02:06 - POST request CSRF payload
02:31 - Deliver POST request CSRF payload
03:39 - Try a GET request instead
04:05 - Try Request Method Spoofing
05:23 - Deliver the spoofed request method CSRF payload

REFERENCES
https://chromestatus.com/feature/5088147346030592
https://laravel.com/docs/5.0/routin #method-spoofing

COOKIE EDITOR EXTENSION
https://chrome.google.com/webstore/detail/cookie-editor/hlkenndednhfkekhgcdicdfddnkalmdm
https://addons.mozilla.org/en-US/firefox/addon/cookie-editor/

Рекомендуемые видео