O'Reilly logo

Mastering Kali Linux for Web Penetration Testing by Michael McPhee

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Don't you know who I am? Account creation

Taking over an account might work short-term, but often we want a persistent presence on the application that does not have a very angry or upset victim trying to wrest back control. In the event we are able to obtain access to an admin's account or fool an admin user into clicking on a link, we can sometimes have them help us create an account on our own!

The trick is to have located or accurately guessed the URL for the new user or account creation page. Once we've done this, we can use a similar attack to our first CSRF to automate the account creation and pass it the appropriate seed credentials we'd like to use on it. To walk through this, we can see how this works by using bWAPP again, and select ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required