CSRF - Lab #5 CSRF where token is tied to non-session cookie | Long Version
In this video, we cover Lab #5 in the CSRF module of the Web Security Academy. This lab's email change functionality is vulnerable to CSRF. It uses tokens to try to prevent CSRF attacks, but they aren't fully integrated into the site's session handling system. To solve the lab, we use the exploit server to host an HTML page that uses a CSRF attack to change the viewer's email address. ▬ 🌟 Video Sponsor 🌟 ▬▬▬▬▬▬▬▬▬▬ Sign up to Intigriti: https://go.intigriti.com/ranakhalil (affiliate link) ▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬ Buy my course: https://academy.ranakhalil.com/p/web-... ▬ 📖 Contents of this video 📖 ▬▬▬▬▬▬▬▬▬▬ 00:00 - Introduction 00:14 - Intigriti sponsorship (https://go.intigriti.com/ranakhalil) 01:08 - Navigation to the exercise 01:54 - Understand the exercise and make notes about what is required to solve it 02:48 - Exploit the lab using Burp Suite Pro 20:52 - Script the exploit (without Burp Suite Pro) 27:47 - Summary 28:00 - Thank You ▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬ HTML script: https://github.com/rkhal101/Web-Secur... Notes.txt document: https://github.com/rkhal101/Web-Secur... CSRF theory video: • Cross-Site Request Forgery (CSRF) | Comple... Web Security Academy Youtube Video Series Release Schedule: https://docs.google.com/spreadsheets/... Web Security Academy: https://portswigger.net/web-security/... Rana's Twitter account: / rana__khalil

CSRF - Lab #6 CSRF where token is duplicated in cookie | Long Version

CSRF - CSRF where token is tied to non-session cookie

Cross-Site Request Forgery (CSRF) | Complete Guide

Why Aliens Would NEVER Invade Africa

CSRF - Lab #1 CSRF vulnerability with no defenses | Long Version

CSRF Where Token is Not Tied to User Session

Cross-Site Request Forgery (CSRF) Explained

Lab: CSRF with SameSite Lax BYPASS via method override

CSRF - Lab #4 CSRF where token is not tied to user session | Long Version

We Asked a CIA Officer 24 Tough Questions | Honesty Box

Difference between cookies, session and tokens

Turing Award Winner: Disagreeing with Google, Postgres, Future Problems | Mike Stonebraker

How To Circumvent CSRF Protection!

Attacking AI - Jason Haddix - NDC Security 2026

CSRF where token is tied to non-session cookie (Video solution, Audio)

Passkeys Explained: Are They Actually Better Than Passwords?

Business Logic Vulnerabilities - Lab #5 Low Level Logic Flaw | Long Video

