Authentication Vulnerabilities - Lab #9 Brute-forcing a stay-logged-in cookie | Long Version

In this video, we cover Lab #9 in the Authentication module of the Web Security Academy. This lab allows users to stay logged in even after they close their browser session. The cookie used to provide this functionality is vulnerable to brute-forcing. To solve the lab, we brute-force Carlos's cookie to gain access to his "My account" page. Your credentials: wiener:peter Victim's username: carlos Candidate passwords ▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬ Buy my course: https://academy.ranakhalil.com/p/web-... ▬ 📚 Contents of this video 📚 ▬▬▬▬▬▬▬▬▬▬ 00:00​​​ - Introduction 00:11 - Web Security Academy Course (https://bit.ly/30LWAtE) 01:22 - Navigation to the exercise 01:50 - Understand the exercise and make notes about what is required to solve it 02:25 - Exploit the lab using Burp Suite Professional 08:37 - Script the Exploit in Python 18:12 - Summary 18:24 - Thank You ▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬ Python script: https://github.com/rkhal101/Web-Secur... Notes.txt document: https://github.com/rkhal101/Web-Secur... Web Security Academy Lab Exercise: https://portswigger.net/web-security/... Rana's Twitter account:   / rana__khalil  

Authentication Vulnerabilities - Lab #10 Offline password cracking | Long Version
▶︎

Authentication Vulnerabilities - Lab #10 Offline password cracking | Long Version

Authentication Vulnerabilities | Complete Guide
▶︎

Authentication Vulnerabilities | Complete Guide

Broken Authentication - Brute Forcing a Stay Logged In Cookie
▶︎

Broken Authentication - Brute Forcing a Stay Logged In Cookie

Business Logic Vulnerabilities - Lab #4 Flawed enforcement of business rule | Long Version
▶︎

Business Logic Vulnerabilities - Lab #4 Flawed enforcement of business rule | Long Version

SSRF Lab 3 - Blind SSRF with out-of-band detection (2 Solution Methods)
▶︎

SSRF Lab 3 - Blind SSRF with out-of-band detection (2 Solution Methods)

Authentication Vulnerabilities - Lab #6 Broken brute-force protection, IP block | Long Version
▶︎

Authentication Vulnerabilities - Lab #6 Broken brute-force protection, IP block | Long Version

SUMMER DEEP HOUSE Musics Mix 2026 ♫ Bruno Mars, Lady Gaga,Dua Lipa, Adele,Ed Sheeran, The Weeknd #02
▶︎

SUMMER DEEP HOUSE Musics Mix 2026 ♫ Bruno Mars, Lady Gaga,Dua Lipa, Adele,Ed Sheeran, The Weeknd #02

Authentication Vulnerabilities - Lab #5 Username enumeration via response timing | Long Version
▶︎

Authentication Vulnerabilities - Lab #5 Username enumeration via response timing | Long Version

Passkeys Explained: Are They Actually Better Than Passwords?
▶︎

Passkeys Explained: Are They Actually Better Than Passwords?

THESE Apps Are SPYING on You — Shut Them Off NOW!
▶︎

THESE Apps Are SPYING on You — Shut Them Off NOW!

Bypassing Brute-Force Protection with Burpsuite
▶︎

Bypassing Brute-Force Protection with Burpsuite

Passkeys SUCK (here’s why + how I use them)
▶︎

Passkeys SUCK (here’s why + how I use them)

Broken Access Control | Complete Guide
▶︎

Broken Access Control | Complete Guide

تلاوة القرآن للدراسة والتركيز 📚🕛 | راحة وطمأنينة | Peaceful Focus Quran | محمد هشام
▶︎

تلاوة القرآن للدراسة والتركيز 📚🕛 | راحة وطمأنينة | Peaceful Focus Quran | محمد هشام

Business Logic Vulnerabilities - Lab #2 High-level logic vulnerability | Long Version
▶︎

Business Logic Vulnerabilities - Lab #2 High-level logic vulnerability | Long Version

Broken Access Control - Lab #2 Unprotected admin functionality with unpredictable URL | Long Version
▶︎

Broken Access Control - Lab #2 Unprotected admin functionality with unpredictable URL | Long Version

Top 10 Real World Wireshark Filters you need to know
▶︎

Top 10 Real World Wireshark Filters you need to know

Broken Access Control - Lab #1 Unprotected admin functionality | Long Version
▶︎

Broken Access Control - Lab #1 Unprotected admin functionality | Long Version

Avicii, Dua Lipa, Coldplay, Martin Garrix & Kygo, The Chainsmokers Style - Summer Vibes #21
▶︎

Avicii, Dua Lipa, Coldplay, Martin Garrix & Kygo, The Chainsmokers Style - Summer Vibes #21