Brute Forcing User IDS Via CSRF To Delete All Users With CSRF Attack
Brute Forcing User IDS Via CSRF To Delete All Users With CSRF Attack
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
This was very easy CSRF that an attacker can send form to admin and can
delete the user from an application.
But again if you notice that request contains the user id. My challenge was
to gure out that if an application user ids at any end points but i found that
there was no user ID leakage.
From a research i got the blog post in which an attacker has brute forced the
IDs with the help of click jacking.
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Client-side CSRF Token Brute Forcing
While playing around with some CSRF examples the idea of client-
side CSRF token brute forcing came into my head. I'd…
pwndizzle.blogspot.in
In this case I was not able to view the response as response had X-Frame-
Option Header which application was validating.But i was able to send the
request
So I made a CSRF Script which brute forces the USER IDS and deletes all
the existing Users with CSRF from an application
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
And When I sent this PoC to victim (admin) , I was able to delete all Existing
users from an application.
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Thanks guys for reading.
Have a great day ahead.
267 claps
WRITTEN BY
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
See responses (1)
Related reads
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Related reads
Related reads
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD
Discover Medium Make Medium yours Become a member
Welcome to a place where words matter. Follow all the topics you care about, and Get unlimited access to the best stories on
On Medium, smart voices and original we’ll deliver the best stories for you to your Medium — and support writers while
ideas take center stage - with no ads in homepage and inbox. Explore you’re at it. Just $5/month. Upgrade
sight. Watch
Create PDF in your applications with the Pdfcrowd HTML to PDF API PDFCROWD