У нас вы можете посмотреть бесплатно Portswigger - Access Control - Lab #12 Multi step process with no access control on one step или скачать в максимальном доступном качестве, видео которое было загружено на ютуб. Для загрузки выберите вариант из формы ниже:
Если кнопки скачивания не
загрузились
НАЖМИТЕ ЗДЕСЬ или обновите страницу
Если возникают проблемы со скачиванием видео, пожалуйста напишите в поддержку по адресу внизу
страницы.
Спасибо за использование сервиса ClipSaver.ru
Hello Hackers, in this video of Multi step process with no access control on one step. You will see how to exploit, discover and find senstive information based on application logic flow to leak for potential attacks from Burp Suite in a lab from Web Security Academy powered by Portswigger ⚠️ Subscribe to my channel ➡️ @popo_hack ⚠️ 0:00 - About the Lab 1:32 - Discover Admin account 2:15 - Test upgrade and downgrade function 4:28 - Upgrade user Wiener 🔍 About the Lab Lab: URL-based access control can be circumvented Level: Practitioner This lab has an admin panel with a flawed multi-step process for changing a user's role. You can familiarize yourself with the admin panel by logging in using the credentials administrator:admin. To solve the lab, log in using the credentials wiener:peter and exploit the flawed access controls to promote yourself to become an administrator. ✅ What to do ? 1. Log in using the admin credentials. 2. Browse to the admin panel, promote carlos, and send the confirmation HTTP request to Burp Repeater. 3. Open a private/incognito browser window, and log in with the non-admin credentials. 4. Copy the non-admin user's session cookie into the existing Repeater request, change the username to yours, and replay it. Thank you for watching my video, if you have any questions or any topics recommendation feel free to write them on the comment below 🙋 #WebSecurityAcademy #portswigger #vulnerability