Web - Client

Saturday 26 May 2018, 09:05  #1
csrf- 0 protection
yalda
  • 5 posts

Hi everybody,
I have some problem with this challenge. I copied below html code to text area in contact page and check my access to private section some times after that but my account is not validated yet.
Suppose my username is "test"

Is my payload correct? Please give me some hint!

Saturday 26 May 2018, 13:20  #2
csrf- 0 protection
Th1b4ud
  • 1636 posts

Hi. I think you forget something. Look at this doc : https://www.w3schools.com/jsref/met_form_submit.asp

Saturday 26 May 2018, 15:39  #3
csrf- 0 protection
yalda
  • 5 posts

The source code of my payload is like below, only I replaced bracket tags with double quotation here (since with brackets the code is rendered):

Saturday 26 May 2018, 18:49  #4
csrf- 0 protection
Th1b4ud
  • 1636 posts
Sunday 27 May 2018, 12:04  #5
csrf- 0 protection
yalda
  • 5 posts

Thanks. I change the automation submitting the form but I can not enter private section in my profile yet and this show that my payload is not successful.
I try both way to automate submitting form and both of them work but this payload doesn’t run completely in admin session.
Can I ask to give me some hint to solve this challenge?

Sunday 27 May 2018, 12:37  #6
csrf- 0 protection
Th1b4ud
  • 1636 posts

You have all you need to resolve this challenge. Try harder ;)

Sunday 27 May 2018, 14:08  #7
csrf- 0 protection
yalda
  • 5 posts

Ok, Thanks :)

Wednesday 27 June 2018, 11:07  #8
csrf- 0 protection
j4rv!c3
  • 2 posts

Tried all the suggestions guided above , till unable to enter the private section of this challange.Can you provide some hint regarding this??

Saturday 16 February 2019, 21:35  #9
csrf- 0 protection
Weberling2
  • 1 posts

can sb pls explain me csrf in a simple way?

send me a message on rootme

greeding Weberling2