Hello Friends,

I’m Rem01x And I’m Currently Preparing For The eWPTX Exam So I Will Be Walking Through All PortSwigger Labs And Make Sure To Make Writeups For All Of Them.

Let’s Start Now.

Assume that we have this website.

Untitled

Now, let’s login to our account

Untitled

Now, let’s go to the burp and check the requests,

Untitled

Please notice the CORS Header in the response

Now, let’s try to add the Origin Header and see if it reflects

Untitled

It’s seems that the Origin Header not reflected back to us

Now, let’s try the Origin Header null value

Untitled

Nope that didn’t work too.