Skip to content

Latest commit

 

History

History
14 lines (11 loc) · 815 Bytes

CSRF_Post_Swigger_Web_Academy_CTF.md

File metadata and controls

14 lines (11 loc) · 815 Bytes

LAB 0

CSRF Vulnerability with no defense
Hint: Hint: None. Point of the lab is to construct a web page that will launch a CSRF attack and change the users email address.
The credentials are: carlos / montoya.
Capture
Its a POST method and there is a cookie in the request header. Capture

Now we go to the exploit server and craft our response Capture

and voila
Capture