Broken Access Control - Lab #3 User role controlled by request parameter | Long Version

Опубликовано: 05 Октябрь 2024
на канале: Rana Khalil
4,624
131

In this video, we cover Lab #3 in the Access Control Vulnerabilities module of the Web Security Academy. This lab has an admin panel at /admin, which identifies administrators using a forgeable cookie. To solve the lab, we access the admin panel and use it to delete the user carlos.

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://bit.ly/30LWAtE

▬ 📖 Contents of this video 📖 ▬▬▬▬▬▬▬▬▬▬
00:00 - Introduction
00:13 - Web Security Academy Course (https://bit.ly/30LWAtE)
01:23 - Navigation to the exercise
01:54 - Understand the exercise and make notes about what is required to solve it
01:54 - Exploit the lab
24:36 - Summary
24:49 - Thank You

▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Python script: https://github.com/rkhal101/Web-Secur...
Web Security Academy Exercise Link: https://portswigger.net/web-security/...
Rana's Twitter account:   / rana__khalil