Pin It

How To Find CSRF Vulnerabilites? - Twilio CSRF Attack [Demonstration]




Recently, i wrote an article on the "ifixit Stored XSS vulnerability". I received a good response from my readers, therefore i thought to write about my recent CSRF vulnerability i found inside twilio. Typically, when hunting for a CSRF vulnerability, we look for forms that are without CSRF tokens, I have created a small screencast, where i will walk you through the process of finding CSRF vulnerabilities. I would be using two different tools for this purpose namely "Tamper Data" and "Burp Suite", I hope you enjoy the video and i am looking forward to have a feedback.





My name would be listed inside there responsible disclosure page, the name text page would be updated:
https://www.twilio.com/docs/security/disclosure

Subscribe to our Newsletter and receive updates directly via email - Get Ethical hacking and security tips directly to your inbox. Alternatively you can Join our Hackers Community on Facebook, Google+ and Twitter.
Subscribe to RHA


Enjoyed this article?
Subscribe to "Rafay Hacking Articles" and get daily updates in your inbox for free!




Kindly Bookmark it and Share it with Friends:

9 comments:

Anonymous said...

Bro...u r name is missing in https://www.twilio.com/docs/security/disclosure

Tel them 2 fix :)

Rafay Baloch on January 10, 2013 at 2:13 AM said...

It will be there, the next time the page would be updated.

Cyber-boss on January 11, 2013 at 2:49 AM said...

Nyc Wrk bRo:)

Rynaldo on January 11, 2013 at 7:30 AM said...

Seems to be a great video tutorial to learn from, but it requires password to watch, but i can't find it from the article.

"If you have permission to watch this video, please type in your password."

Rynaldo. :)

Rafay Baloch on January 11, 2013 at 11:33 AM said...

@Rynaldo

Send an email to rafayhackingarticles@gmail.com, i'll send you the password.

Facebook Covers on January 14, 2013 at 4:55 AM said...

Rafay your site is really awesome . good work bro.

Mehul Mohan on January 16, 2013 at 4:47 AM said...

pass please... :(

Parv Jain on February 11, 2013 at 3:23 AM said...

Gone Through your Video! That's Awesome Dude! and i will just say that you have got skills!
Well Thanks for Password! :D

Anonymous said...

Pass please

Dare to ask? :)

Blog Archive

 

Popular Posts

Recent Comments

Stats

Receive all updates via Facebook. Just Click the Like Button Below

You can also receive Free Email Updates:

Followers

RHA © 2013. All Rights Reserved.

Design By My Blogger Tricks | Home | RSS

Click Here To Subscribe Now To Our RSS FEED.