Broken Access Control - Lab #12 Multi-step process with no access control on one step | Long Version

Опубликовано: 20 Октябрь 2024
на канале: Rana Khalil
2,136
63

In this video, we cover Lab #12 in the Access Control Vulnerabilities module of the Web Security Academy. This lab has an admin panel with a flawed multi-step process for changing a user's role. You can familiarize yourself with the admin panel by logging in using the credentials administrator:admin. To solve the lab, we log in using the credentials wiener:peter and exploit the flawed access controls to promote ourselves to become an administrator.

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://bit.ly/30LWAtE

▬ 📖 Contents of this video 📖 ▬▬▬▬▬▬▬▬▬▬
00:00 - Introduction
00:14 - Web Security Academy Course (https://bit.ly/30LWAtE)
01:25 - Navigation to the exercise
01:58 - Understand the exercise and make notes about what is required to solve it
02:34 - Exploit the lab
17:21 - Summary
17:35 - Thank You!

▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Python script: https://github.com/rkhal101/Web-Secur...
Web Security Academy Exercise Link: https://portswigger.net/web-security/...
Rana's Twitter account:   / rana__khalil