CVE-2019-5420

Bookmarked!

This exercise details the exploitation of CVE-2019-5420 to forge a session as another user

PRO Medium 2-4 Hrs. 922 Green Badge
Course

This course details the exploitation of a vulnerability in Ruby-on-Rails when it is running in development mode. It demonstrates how attackers can guess the key used to secure sessions by knowing the application's name, enabling them to decrypt, tamper, and re-encrypt session data.

Skills covered
Authentication Authorisation Cryptography
CWE-330
Included with PRO
Full course content 2 videos

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.