CSRF - Lab #2 CSRF where token validation depends on request method | Long Version
In this video, we cover Lab #2 in the CSRF module of the Web Security Academy. This lab's email change functionality is vulnerable to CSRF. It attempts to block CSRF attacks, but only applies defenses to certain types of requests. To solve the lab, we craft some HTML that uses a CSRF attack to change the viewer's email address and upload it to to our exploit server. ▬ 🌟 Video Sponsor 🌟 ▬▬▬▬▬▬▬▬▬▬ Sign up to Intigriti: https://go.intigriti.com/ranakhalil (affiliate link) ▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬ Buy my course: https://academy.ranakhalil.com/p/web-... ▬ 📖 Contents of this video 📖 ▬▬▬▬▬▬▬▬▬▬ 00:00 - Introduction 00:15 - Intigriti sponsorship (https://go.intigriti.com/ranakhalil) 01:09 - Navigation to the exercise 01:49 - Understand the exercise and make notes about what is required to solve it 02:39 - Exploit the lab using Burp Suite Pro 12:42 - Script the exploit (without Burp Suite Pro) 21:07 - Summary 21:27 - Thank You ▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬ HTML script: https://github.com/rkhal101/Web-Secur... Notes.txt document:https://github.com/rkhal101/Web-Secur... CSRF Lab #1 (previous video): • CSRF - Lab #1 CSRF vulnerability with no d... CSRF theory video: • Cross-Site Request Forgery (CSRF) | Comple... Web Security Academy Youtube Video Series Release Schedule: https://docs.google.com/spreadsheets/... Web Security Academy: https://portswigger.net/web-security/... Rana's Twitter account: / rana__khalil

CSRF - Lab #3 CSRF where token validation depends on token being present | Long Version

CSRF - Lab #1 CSRF vulnerability with no defenses | Long Version

Why Aliens Would NEVER Invade Africa

Cross-Site Request Forgery (CSRF) | Complete Guide

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

CSRF - Lab #5 CSRF where token is tied to non-session cookie | Long Version

CSRF - Lab #4 CSRF where token is not tied to user session | Long Version

Lab: CSRF where token validation depends on request method | Burp Suite | Portswigger

Attacking AI - Jason Haddix - NDC Security 2026

Passkeys Explained: Are They Actually Better Than Passwords?

CSRF - how to find it in 2024? CSRF bug bounty case study

She Asks if I Know Coldplay and This Singer Shocks The Street

Server-Side Request Forgery (SSRF) | Complete Guide

Turing Award Winner: Disagreeing with Google, Postgres, Future Problems | Mike Stonebraker

CSRF where token is tied to non-session cookie (Video solution, Audio)

The AI Coding Revolution Has a Huge Problem?

We Asked a CIA Officer 24 Tough Questions | Honesty Box

