Город МОСКОВСКИЙ
00:11:09

Lab: Server-side pause-based request smuggling

Аватар
Автоматизированные умные роботы
Просмотры:
22
Дата загрузки:
02.12.2023 08:56
Длительность:
00:11:09
Категория:
Технологии и интернет

Описание

In-depth solution to PortSwigger's "Server-side pause-based request smuggling" lab.

Turbo Intruder code:
https://pastebin.com/4g3t3xN3

Try it yourself:
https://portswigger.net/web-security/request-smuggling/browser/pause-based-desync/lab-server-side-pause-based-request-smuggling

Timestamps:
00:00 - Intro
01:05 - Find endpoint with server level redirect
01:38 - Send request to Turbo Intruder
01:59 - Detect & Confirm CL.0 vulnerability through Differential Responses
05:01 - Smuggle in a request to the admin panel
06:55 - Add a "Host: localhost" request header
08:14 - Smuggle in a POST request to delete the user carlos

Рекомендуемые видео