Загрузка...

Authentication Vulnerabilities - Lab #9 Brute-forcing a stay-logged-in cookie | Long Version

In this video, we cover Lab #9 in the Authentication module of the Web Security Academy. This lab allows users to stay logged in even after they close their browser session. The cookie used to provide this functionality is vulnerable to brute-forcing.

To solve the lab, we brute-force Carlos's cookie to gain access to his "My account" page.

Your credentials: wiener:peter
Victim's username: carlos
Candidate passwords

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://academy.ranakhalil.com/p/web-security-academy-video-series

▬ 📚 Contents of this video 📚 ▬▬▬▬▬▬▬▬▬▬
00:00​​​ - Introduction
00:11 - Web Security Academy Course (https://bit.ly/30LWAtE)
01:22 - Navigation to the exercise
01:50 - Understand the exercise and make notes about what is required to solve it
02:25 - Exploit the lab using Burp Suite Professional
08:37 - Script the Exploit in Python
18:12 - Summary
18:24 - Thank You

▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Python script: https://github.com/rkhal101/Web-Security-Academy-Series/blob/main/broken-authentication/lab-09/authentication-lab-09.py
Notes.txt document: https://github.com/rkhal101/Web-Security-Academy-Series/blob/main/broken-authentication/lab-09/notes.txt
Web Security Academy Lab Exercise: https://portswigger.net/web-security/authentication/other-mechanisms/lab-brute-forcing-a-stay-logged-in-cookie
Rana's Twitter account: https://twitter.com/rana__khalil

Видео Authentication Vulnerabilities - Lab #9 Brute-forcing a stay-logged-in cookie | Long Version канала Rana Khalil
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять