Ad Widget

Collapse

cannot extract the value of the csrf token in a web scenario

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Amine
    Junior Member
    • Feb 2022
    • 3

    #1

    cannot extract the value of the csrf token in a web scenario

    Hello,

    i want to extract the "csrf token" value in step 1 which is checking the availaibility of the url then use this value in the second step which checks the accessibility of the url (login + password)
    But i'm facing this problem

    Étape "demande. URL PLE" [1 sur 2] échouée : error in step variables "{CSRFTOKEN}=regex:name="OWASP-CSRFTOKEN" value="([0-9A-Za-z-]{39})"": cannot extract the value of "{CSRFTOKEN}" from response

    This is what i did :

    step1:


    Click image for larger version

Name:	1.png
Views:	1237
Size:	41.8 KB
ID:	439347


    step 2:

    Click image for larger version

Name:	2.png
Views:	1117
Size:	49.7 KB
ID:	439348

    ps: this is the regular expression i'm using value="([0-9A-Za-z-]{39})" and this is an example of the OWASP-CSRFTOKEN value:
    4QTS-XIYM-B7L8-KED1-Y406-QJ2H-VZZ6-LWQQ
    nd i tried replacing the word value with content but nothing changed
    is there a fix the official documentation
    2 Real life scenario (zabbix.com) seems outdated for me
  • kirrus
    Junior Member
    • Oct 2022
    • 2

    #2
    Did you find a solution Amine I've got the same issue currently.

    Comment

    • kirrus
      Junior Member
      • Oct 2022
      • 2

      #3
      Solved for me -- the variable appeared to need to be in lowercase, and I needed to use a \\ to select a \ in the CRSF token.

      Comment

      Working...