Learn Cross-Site Request Forgery (CSRF) From Scratch + FREE Training

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 มิ.ย. 2024
  • This video will teach you the basics of Cross-Site Request Forgery or CSRF vulnerabilities, how to discover them and how to exploit them in a real-life practical example.
    🔴 Snyk's FREE training and CTF signup link👇
    snyk.co/ctf-zsecurity
    🧠 My Hacking Masterclass👇
    zsecurity.org/courses/masterc...
    🧠 My other hacking courses 👇
    zsecurity.org/courses/
    🌟 VIP Membership 👇
    zsecurity.org/vip-membership/
    ---------------------------------------------------------------
    zSecurity Company - zsecurity.com/
    Community - zsecurity.org/
    Facebook - / zsecurity-145325078145...
    Twitter - / _zsecurity_
    Instagram - / zsecurity_org
    Linkedin - / zsecurity-org
    TikTok - / zsecurity_org
    ---------------------------------------------------------------
    Time Stamps:
    00:00 - intro
    00:45 - What is Broken Access Control?
    01:58 - CSRF Explained
    02:27 - How to Discover CSRF
    11:07 - Where to Practice CSRF
    11:24 - More FREE Training
    -------------------------
    🎯 Target Website Link 👇
    portswigger.net/web-security/...

ความคิดเห็น • 71

  • @zSecurity
    @zSecurity  8 หลายเดือนก่อน +7

    FREE training from Snyk & Participate in their CTF to win a Nintendo Switch👇
    snyk.co/ctf-zsecurity

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      First. :3

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      Sweet! :3 One of my favourite ethical hacker teachers. :3

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      Very weird. HamASS has support from Russia, when Russia said it's pro-Jew before, and that's one of the reasons why they invaded Ukraine, to fight anti-Semitism. HamASS said, Putin sympathises with us. Turkey, a moderate Muslim nation, that many Muslims don't find true Muslims for how moderate they are, a NATO member, sympathises with HamASS.
      Even at Harvard, several students with pro-Palestine protests, and saying to gas the Jews. I wonder if they will gas Drake, the rapper, the Harry Potter actor they love, Madonna, the Family Guy and American Dad founder, Einstein, if he was alive, Stephen Spielberg, the founders of most comics, the people that made Starbucks that many love to drink so much, Bruno Mars, the lady that inspired and helped Tupac, etc.
      I wonder if these self-entitled Whites, and other non-Natives, will take their own advice, and leave North America. I wonder if Pakistan will give back that massive amount of land they, Arab Muslims, stole from India. Israel has shared that land for 3,500+ years. Tel Aviv has a photo of itself in 1909, wayyyy before the 1940s. We even have the Palestinian flag with the Jewish Star of David on it beforeeee the 1940s.
      What about the invasions of Arab Muslims into Spain, parts of Africa, etc.? Hmmmm. How convenient.
      While America has predominantly Whites shooting up schools because no one cares to safeguard schools. 300-600+ students a year killed, plus teachers, and others.
      Well, at least there's less racist, self-entitled, fat, drug addicted Americans from these kids getting shot, bright side of it all.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      :3 Persia especially is hurting. They got invaded by Arab Muslims, and became, unfortunately, a Muslim nation, toxicity. They don't allow journalists, and protestors that they don't like. Those people get killed. At least Israel has several Arabs with rights, and jobs in Israel. West Bank doesn't have this radicalism, and has far more people.
      I've been meaning to hack HamASS, but he's gonna thankfully be dead soon since he doesn't want any peace, and wants all Jews dead. Iran, Hezbollah, and others are still targets. Some of the best hackers are Israeli, too. Dark Net Diaries are great podcasts here on TH-cam, and Israel gets plenty of love there for ethical hacking.

  • @ATTIQOP
    @ATTIQOP 8 หลายเดือนก่อน +40

    bro would teach anything and say its for educational purposes only what a humble person ❤️

    • @hawkeye3101
      @hawkeye3101 8 หลายเดือนก่อน +11

      Bro doing the Lord's work. Appreciate and move on sir.

    • @ATTIQOP
      @ATTIQOP 8 หลายเดือนก่อน

      @@hawkeye3101 yeah

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      ​@@hawkeye3101Lord Buddha. Not any toxic, especially Islamic, Abrahamic, unoriginal, very debunked religion. XD
      Spiritual, and anti-religion.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน +2

      Well, it's an ethical hacking channel, and he works in cybersecurity. Plus, you have to say that in order to put hacking videos without worry of your video. Lol. If you don't like it, don't be here.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      :3 Very weird. HamASS has support from Russia, when Russia said it's pro-Jew before, and that's one of the reasons why they invaded Ukraine, to fight anti-Semitism. HamASS said, Putin sympathises with us. Turkey, a moderate Muslim nation, that many Muslims don't find true Muslims for how moderate they are, a NATO member, sympathises with HamASS.
      Even at Harvard, several students with pro-Palestine protests, and saying to gas the Jews. I wonder if they will gas Drake, the rapper, the Harry Potter actor they love, Madonna, the Family Guy and American Dad founder, Einstein, if he was alive, Stephen Spielberg, the founders of most comics, the people that made Starbucks that many love to drink so much, Bruno Mars, the lady that inspired and helped Tupac, etc.
      I wonder if these self-entitled Whites, and other non-Natives, will take their own advice, and leave North America. I wonder if Pakistan will give back that massive amount of land they, Arab Muslims, stole from India. Israel has shared that land for 3,500+ years. Tel Aviv has a photo of itself in 1909, wayyyy before the 1940s. We even have the Palestinian flag with the Jewish Star of David on it beforeeee the 1940s.
      What about the invasions of Arab Muslims into Spain, parts of Africa, etc.? Hmmmm. How convenient.
      While America has predominantly Whites shooting up schools because no one cares to safeguard schools. 300-600+ students a year killed, plus teachers, and others.
      Well, at least there's less racist, self-entitled, fat, drug addicted Americans from these kids getting shot, bright side of it all.

  • @hahaboi
    @hahaboi 8 หลายเดือนก่อน +1

    Hats off for your hardworking.

  • @JLREQ195
    @JLREQ195 4 หลายเดือนก่อน

    Hey I bought u course and I just wanted to say that I’ve definitely learned quite a few things

  • @gilaarts
    @gilaarts 8 หลายเดือนก่อน +4

    I enrolled your paid course the course is very help full for me keep it

  • @flopya
    @flopya 8 หลายเดือนก่อน +1

    😮😮😮😮😮❤❤❤❤❤
    Thanks, been a long timer though 😅

  • @GHOST-hv8ou
    @GHOST-hv8ou 8 หลายเดือนก่อน +1

    actually can you make video explaining us what is osi model because i really treid to understand it well but i can't?

  • @AgborTakorPius
    @AgborTakorPius 8 หลายเดือนก่อน +8

    thanks Mr Zaid. i have like six of your courses i bought from udemy. thank you so much for your effort you put in to teach the world what you know.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      :3 Very weird. HamASS has support from Russia, when Russia said it's pro-Jew before, and that's one of the reasons why they invaded Ukraine, to fight anti-Semitism. HamASS said, Putin sympathises with us. Turkey, a moderate Muslim nation, that many Muslims don't find true Muslims for how moderate they are, a NATO member, sympathises with HamASS.
      Even at Harvard, several students with pro-Palestine protests, and saying to gas the Jews. I wonder if they will gas Drake, the rapper, the Harry Potter actor they love, Madonna, the Family Guy and American Dad founder, Einstein, if he was alive, Stephen Spielberg, the founders of most comics, the people that made Starbucks that many love to drink so much, Bruno Mars, the lady that inspired and helped Tupac, etc.
      I wonder if these self-entitled Whites, and other non-Natives, will take their own advice, and leave North America. I wonder if Pakistan will give back that massive amount of land they, Arab Muslims, stole from India. Israel has shared that land for 3,500+ years. Tel Aviv has a photo of itself in 1909, wayyyy before the 1940s. We even have the Palestinian flag with the Jewish Star of David on it beforeeee the 1940s.
      What about the invasions of Arab Muslims into Spain, parts of Africa, etc.? Hmmmm. How convenient.
      While America has predominantly Whites shooting up schools because no one cares to safeguard schools. 300-600+ students a year killed, plus teachers, and others.
      Well, at least there's less racist, self-entitled, fat, drug addicted Americans from these kids getting shot, bright side of it all.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      Zaid is a badass.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      HamASS says they can hold off 100k Israeli ground troops with only 15k-20k terrorists of HamASS. Well, I don't think they're Sparta, and Sparta were respectable people who kept getting attacked by greedy people, unlike HamASS that doesn't like people who've had shared land there for at least 3,500 years. Lol.
      A GIF even shows Tel Aviv in 1909, and you find the Palestinian flag GIF with the Jewish star in the middle, way before the 1940s ever happened. Lol. So much for the European colonialists in North America, and all the Whites, and other non-Natives still there with their whole talk about Israel never existing. Lolololol. HamASS would destroy most of them for women not covering their faces, anyone who isn't straight, death cult apostasy laws, etc.
      Israel actually employs Arabs, and there are Jews living in Gaza, and in the West Bank, too. Just as Jews live in several Arab nations. HamASS is just racist, and wants all Jews gone from the Earth, but Fatah didn't.
      Even if he can handle ground troops, Israel, among other allies, can just blow up every last building. Gaza will be the world's largest parking lot, as we say.
      Then, we could build back Gaza to look better than it did before. Restore homes to Arabs, and Jews there, and monitor streets tightly for terrorist formations again. That's assuming Netanyahu wants a two-state solution instead of just divide, and war.
      America has billions of dollars, too. They could renovate all of Gaza and West Bank, and make shared land. To put patrol on all streets to fight terrorism, and Muslims hurting non-Muslims (Qur'wrong 2:191, among other verses to take care of non-Muslims).
      HamASS has to go, because he doesn't want a two-state solution. Egypt doesn't even want any Palestinians, any. 🤣🤣🤣🤣🤣Jewish people showing more sympathy than their own Arabs, and own Muslims. XD 🤣🤣🤣🤣🤣🤣🤣🤣💩💩🎪🤡😅💀
      :3

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 8 หลายเดือนก่อน

      Persia especially is hurting. They got invaded by Arab Muslims, and became, unfortunately, a Muslim nation, toxicity. They don't allow journalists, and protestors that they don't like. Those people get killed. At least Israel has several Arabs with rights, and jobs in Israel. West Bank doesn't have this radicalism, and has far more people.
      I've been meaning to hack HamASS, but he's gonna thankfully be dead soon since he doesn't want any peace, and wants all Jews dead. Iran, Hezbollah, and others are still targets. Some of the best hackers are Israeli, too. Dark Net Diaries are great podcasts here on TH-cam, and Israel gets plenty of love there for ethical hacking.

    • @chorkaniitv3386
      @chorkaniitv3386 8 หลายเดือนก่อน

      Bro how do u buy this courses

  • @SumanRoy.official
    @SumanRoy.official 8 หลายเดือนก่อน +5

    please use dark mode while making videos! please use dark reader if you are using browser to demo stuff,

  • @KingLee-ct2kk
    @KingLee-ct2kk 8 หลายเดือนก่อน

    Can you talk about open bullet config tool?

  • @user-nb1me1gq2k
    @user-nb1me1gq2k 8 หลายเดือนก่อน +2

    Zaidh sir please make a course on Android app hacking

  • @nikenhukubhayy
    @nikenhukubhayy 8 หลายเดือนก่อน

    Is there any way to listen live voice recording of other device is there any mobile setting or playstore app ??

  • @OlivierMedor
    @OlivierMedor 8 หลายเดือนก่อน

    How often can someone find CSRF vulnerability in a larger site such as TH-cam?

  • @soTarkyyy
    @soTarkyyy 13 วันที่ผ่านมา

    One question from my site, how the HTML requests recognizes that It should do it for the user Carlos now? I mean there was no Id oder email changed in the HTML. Or is this attack just supposed to work on the same machine? Because I mean then I could directly go to the page where Carlos is logged in and change the email? Or do I have understood here something wrong? Thank you for your answers

  • @AgborTakorPius
    @AgborTakorPius 8 หลายเดือนก่อน

    am here sir

  • @somnathjadhav2869
    @somnathjadhav2869 8 หลายเดือนก่อน

    Sir , make video on installation kali linux on windows 11 step vise please.
    Your videos are vey amazing.
    Please make the video on it...
    Lot of love ....😻💖

    • @Pro-Balak-Senpai
      @Pro-Balak-Senpai 2 หลายเดือนก่อน

      thats the easiest shit to ever exist u need a tutorial for that ? 💀💀

  • @accountfor-yt2rw
    @accountfor-yt2rw 3 หลายเดือนก่อน

    And won't there be a problem with the repositories in Kali 2020 iso
    ?

  • @narutouzmaki2395
    @narutouzmaki2395 7 หลายเดือนก่อน

    Mr Zaid, I have taken your course 'Learn Ethical Hacking From Scratch' but I can't install Veil in my Kali Linux can you please tell me how to install it it

  • @Adil_sheikh
    @Adil_sheikh 8 หลายเดือนก่อน +1

    Brother, you make very good videos but because your video is in English, I am not able to understand it properly and there are many subscribers who have this problem. So can you put an audio track on your video?

    • @Sanatan_khaniya
      @Sanatan_khaniya 8 หลายเดือนก่อน +1

      I am totally satisfied with you.

  • @m1ark2013axiot
    @m1ark2013axiot 2 หลายเดือนก่อน +1

    Can you tell me a free tool who does the same job as Octopus for sms please?

  • @alchamistoh1627
    @alchamistoh1627 4 หลายเดือนก่อน

    So this only works if the token for CSRF is not verified?

  • @sanskar6398
    @sanskar6398 4 หลายเดือนก่อน

    2022 custom Kali on your website is corrupted, please upload new one.

  • @GymMaster_Pro
    @GymMaster_Pro 7 หลายเดือนก่อน

    I want to see hacking mastering class play list but it doesn't work what is wrong i follow your channel program for several time but it ask me for member what is wrong

  • @CloudSec101
    @CloudSec101 8 หลายเดือนก่อน

    need these type of videos for all OWASP top 10.

    • @zSecurity
      @zSecurity  8 หลายเดือนก่อน +1

      It's all in my bug bounty course! This video is actually taken from it.

    • @timecop1983Two
      @timecop1983Two 8 หลายเดือนก่อน

      @@zSecurity wow I am going to do his Udemy course! zSecurity

  • @call-me-potato.
    @call-me-potato. 8 หลายเดือนก่อน

    hi , sorry it doesnot make any sense , which website shows emails of other accounts? so how does concept of email takeover works? could you please explain whats purpose of this CSR?

    • @Hackerjedi
      @Hackerjedi 5 หลายเดือนก่อน

      finding emails of other accounts is not that difficult, you can use tools like maltego or any other social engineering tool, its explained in the zaid's social engineering course.

  • @chmun77
    @chmun77 8 หลายเดือนก่อน

    Hi. This is a very interesting video. However, I'm kind of confused how the CSRF works in the video. You have already logged out from wiener account and then logged in again as carlos. So it seems to me that you are updating carlos email address because you are currently connected as carlos, which I think that's normal since you are using carlos session on the server? I was hoping to see that you are able to change the wiener's email address from carlos session but it doesn't seems so. Will you be able to update either wiener's or carlos email addresses without logging into the system? Am I misunderstanding the objective of this video? Thanks.

    • @zSecurity
      @zSecurity  8 หลายเดือนก่อน

      Yes so Wiener crafter a request (forget a request). This request is being submitted by Carlos, the application is trusting Carlos and letting him change his email even though he did not actually make that request. As a result Wiener can get Carlos to change their email an email that Weiner controls, resulting in an account takeover.

  • @imahsansyed
    @imahsansyed 5 หลายเดือนก่อน

    Hey, I know that its hard to reply for comments but I have a question
    I have my google ID and password but I couldn't sign in into my account
    I have no 2fa enabled, no recovery phone or email in my account
    When I try to login it says, to login from device I logged in earlier (not available),sign in from same network(which isn't also available)
    What to do

  • @mnageh-bo1mm
    @mnageh-bo1mm 8 หลายเดือนก่อน

    darn bro u forget the cookies part

  • @bakasenpaidesu
    @bakasenpaidesu 8 หลายเดือนก่อน +1

    .

  • @ayush_vlogs108
    @ayush_vlogs108 7 หลายเดือนก่อน

    Bro a company had cheated me of money 3000 plz... Help!

  • @alexanderaghukwa3854
    @alexanderaghukwa3854 8 หลายเดือนก่อน

    Zaid’s lord sent

  • @nsricharan1679
    @nsricharan1679 8 หลายเดือนก่อน

    CCTV hack in Android

  • @basilxe9174
    @basilxe9174 8 หลายเดือนก่อน +3

    history of palestine

    • @onlychouaib
      @onlychouaib 8 หลายเดือนก่อน

      yeah why he removed the video?

  • @MidnightSpecter43
    @MidnightSpecter43 8 หลายเดือนก่อน

    confusing

    • @timecop1983Two
      @timecop1983Two 8 หลายเดือนก่อน

      Then you should not become an ethical hacker 😮‍💨

  • @shubham_srt
    @shubham_srt 5 หลายเดือนก่อน

    trash