CSRF - Lab #8 CSRF with broken Referer validation | Long Version
In this video, we cover Lab #8 in the CSRF module of the Web Security Academy. This lab's email change functionality is vulnerable to CSRF. It attempts to detect and block cross domain requests, but the detection mechanism can be bypassed. To solve the lab, we use the exploit server to host an HTML page that uses a CSRF attack to change the viewer's email address. ▬ 🌟 Video Sponsor 🌟 ▬▬▬▬▬▬▬▬▬▬ Sign up to Intigriti: https://go.intigriti.com/ranakhalil (affiliate link) ▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬ Buy my course: https://academy.ranakhalil.com/p/web-... ▬ 📖 Contents of this video 📖 ▬▬▬▬▬▬▬▬▬▬ 00:00 - Introduction 00:14 - Intigriti sponsorship (https://go.intigriti.com/ranakhalil) 01:09 - Navigation to the exercise 01:44 - Understand the exercise and make notes about what is required to solve it 02:43 - Exploit the lab using Burp Suite Pro 13:17 - Script the exploit (without Burp Suite Pro) 18:40 - Summary 18:53 - Thank You ▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬ HTML script: https://github.com/rkhal101/Web-Secur... Notes.txt document: https://github.com/rkhal101/Web-Secur... CSRF theory video: • Cross-Site Request Forgery (CSRF) | Comple... Web Security Academy Youtube Video Series Release Schedule: https://docs.google.com/spreadsheets/... Web Security Academy: https://portswigger.net/web-security/... Rana's Twitter account: / rana__khalil

CSRF - Lab #1 CSRF vulnerability with no defenses | Long Version

Cross-Site Request Forgery (CSRF) | Complete Guide

CSRF - Lab #5 CSRF where token is tied to non-session cookie | Long Version

CSRF - Lab #7 CSRF where Referer validation depends on header being present | Long Version

Passkeys Explained: Are They Actually Better Than Passwords?

7 Authentication Concepts Every Developer Should Know

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

CSRF - Lab #6 CSRF where token is duplicated in cookie | Long Version

DOM Vulnerabilities - DOM XSS Using Web Messages

CORS - Lab #3 CORS vulnerability with trusted insecure protocols | Long Video

CSRF - Lab #2 CSRF where token validation depends on request method | Long Version

SUMMER DEEP HOUSE Musics Mix 2026 ♫ Bruno Mars, Lady Gaga,Dua Lipa, Adele,Ed Sheeran, The Weeknd #02

How Hackers Use Burp Suite to Get Into Websites

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Attacking AI - Jason Haddix - NDC Security 2026

CSRF - Lab #4 CSRF where token is not tied to user session | Long Version

SUMMER DEEP HOUSE Musics Mix 2026 ♫ Bruno Mars, Lady Gaga,Dua Lipa, Adele,Ed Sheeran, The Weeknd #29

Lab: CSRF with SameSite Lax BYPASS via method override

