DEV Community

Discussion on: Port Swigger Academy CTF - CSRF vulnerability with no defenses

Collapse
 
mostafareconn profile image
Mostafa Khajevand

Thanks buddy for your post.
I think you missed one thing. when performing the attack in the exploit server, you should be logged out, because as a real attacker you would not be logged in the account carlos/montoya.

Collapse
 
caffiendkitten profile image
DaNeil C

Thanks for info. Maybe this was why I had struggled to get it to work for so long. I'll have to try this again and log out.