CSRF - Lab #1 CSRF vulnerability with no defenses | Long Version
In this video, we cover Lab #1 in the CSRF module of the Web Security Academy. This lab's email change functionality is vulnerable to CSRF. To solve the lab, we craft some HTML that uses a CSRF attack to change the viewer's email address and upload it to to our exploit server. ▬ 🌟 Video Sponsor 🌟 ▬▬▬▬▬▬▬▬▬▬ Sign up to Intigriti: https://go.intigriti.com/ranakhalil (affiliate link) ▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬ Buy my course: https://academy.ranakhalil.com/p/web-... ▬ 📖 Contents of this video 📖 ▬▬▬▬▬▬▬▬▬▬ 00:00 - Introduction 00:13 - Intigriti sponsorship (https://go.intigriti.com/ranakhalil) 01:07 - Navigation to the exercise 01:51 - Understand the exercise and make notes about what is required to solve it 03:00 - Exploit the lab using Burp Suite Pro 12:58 - Script the exploit (without Burp Suite Pro) 23:00 - Summary 23:16 - Thank You ▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬ CSRF Theory video (previous video): • Cross-Site Request Forgery (CSRF) | Comple... HTML script: https://github.com/rkhal101/Web-Secur... Notes.txt document: https://github.com/rkhal101/Web-Secur... Web Security Academy Youtube Video Series Release Schedule: https://docs.google.com/spreadsheets/... Web Security Academy: https://portswigger.net/web-security/... Rana's Twitter account: / rana__khalil

CSRF - Lab #2 CSRF where token validation depends on request method | Long Version

Cross-Site Request Forgery (CSRF) | Complete Guide

CORS - Lab #3 CORS vulnerability with trusted insecure protocols | Long Video

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

Business Logic Vulnerabilities - Lab #4 Flawed enforcement of business rule | Long Version

CSRF - Lab #3 CSRF where token validation depends on token being present | Long Version

Broken Access Control | Complete Guide

Cross Site Request Forgery - Computerphile

Attacking AI - Jason Haddix - NDC Security 2026

CORS - Lab #1 CORS vulnerability with basic origin reflection | Long Video

CSRF - Lab #5 CSRF where token is tied to non-session cookie | Long Version

I Hacked This Temu Router. What I Found Should Be Illegal.

Flow State Music | No Lyrics Creative Flow Music - Ultimate Work Flow Music For Focus Mode

Practical Help Desk - Learn IT Fundamentals in 9 Hours

SQL Injection | Complete Guide

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

Web App Pentesting - HTTP Cookies & Sessions

