Web Apps Beginner

CSRF with no defences: forced email change

The change-email endpoint has no CSRF token and relies only on the session cookie. Build an auto-submitting form that changes a victim's email.

Scenario

POST /my-account/change-email takes a single email parameter, authenticates via the session cookie only, and includes no anti-CSRF token.

Your objective

Host a page that, when the logged-in victim opens it, changes their account email to one you control. Solved when the victim's email is updated.

Capture 1 flag(s) and record the exact technique for each step.

Getting started

  1. Change your own email in the proxy and capture the exact request.
  2. Confirm removing the Referer and any token still succeeds.
  3. Write an HTML <form> targeting the endpoint with a hidden email field and document.forms[0].submit().
  4. Host it on the exploit server and deliver it to the victim.
  5. Submit the email address you set as the flag.

Connecting

Press Launch Lab to build your own instance, then use the How to connect panel — it shows the browser link as soon as the app is running. Hit Stop when you are done, or Relaunch / Reset for a clean copy.

Credentials: wiener:peter

Hints

Tip

Use method="POST" and enctype="application/x-www-form-urlencoded" so the body matches the real form.

How to connect

Connect to the lab VPN first

Lab machines sit on an isolated network with no public address. Connect to the VPN once — the same config works for every lab.

1 · Get your config

Download rooted-labs.ovpn

2 · Connect

Linux / macOS — from a terminal:

Windows / mobile — import the file into OpenVPN Connect, Tunnelblick, or the OpenVPN GUI.

3 · Reach the machine

Once connected, the address shown below (SSH command / lab link / RDP command) is reachable. Only lab traffic is routed through the VPN — your normal internet is untouched.

Step 2 — reach the machine

Challenge questions

0 / 2 correct
  1. Submit the initial flag you recovered while solving this lab.
  2. Which vulnerability class does this lab cover? (a few words)
Sign in to attempt
On this page

At a glance

Operating system
Web application
Connection
Browser / HTTP
Questions
0 / 2 solved
Launched by
0 hackers
Maintained by
Porter Mohr

Your machine

Status

Booting your machine — this takes about a minute. Connection details appear in the brief below when it's ready.

Ready — see How to connect below.

Provisioning failed. Hit Relaunch to try again.