Ott3rly
Ott3rly
  • Видео 57
  • Просмотров 65 847
SSRF Vulnerability
Brief coverage of Server-Side Request Forgery Vulnerability.
Cool Defcon presentation by Nahamsec: ruclips.net/video/o-tL9ULF0KI/видео.html
and it's slides:
docs.google.com/presentation/d/1JdIjHHPsFSgLbaJcHmMkE904jmwPM4xdhEuwhy2ebvo/htmlpresent
---
Twitch: ott3rly.com/twitch
Patreon: ott3rly.com/patreon
Twitter: ott3rly.com/X
Discord: ott3rly.com/discord
Get a $200, 60-day credit for DigitalOcean: ott3rly.com/do
NordVPN: ott3rly.com/NordVPN
Domain: ott3rly.com/123-reg-co-uk
Disclaimer: This channel is strictly educational for learning about ethical hacking and penetration testing so that we can protect ourselves against real hackers. Hacking without permission is illegal so always ensure you have pro...
Просмотров: 206

Видео

CSRF Vulnerability
Просмотров 149Месяц назад
The Cross-Site Request Forgery vulnerability overview. Twitch: ott3rly.com/twitch Patreon: ott3rly.com/patreon Twitter: ott3rly.com/X Discord: ott3rly.com/discord Get a $200, 60-day credit for DigitalOcean: ott3rly.com/do NordVPN: ott3rly.com/NordVPN Domain: ott3rly.com/123-reg-co-uk Disclaimer: This channel is strictly educational for learning about ethical hacking and penetration testing so t...
XSS Overview
Просмотров 240Месяц назад
This is the highlight of Cross-Site Scripting Vulnerability and its capabilities. Twitch: ott3rly.com/twitch Patreon: ott3rly.com/patreon Twitter: ott3rly.com/X Discord: ott3rly.com/discord Get a $200, 60-day credit for DigitalOcean: ott3rly.com/do NordVPN: ott3rly.com/NordVPN Domain: ott3rly.com/123-reg-co-uk Timestamps: 0:00 - Intro 0:30 - What Is XSS? 1:15 - Types Of XSS 2:53 - Place In OWAS...
HTML Injection Vulnerability
Просмотров 206Месяц назад
Welcome back to the Web Hacking Vulnerabilities series. This time we will be exploring HTML injection vulnerability - the door to broader set of issues. Twitch: ott3rly.com/twitch Patreon: ott3rly.com/patreon Twitter: ott3rly.com/X Discord: ott3rly.com/discord Get a $200, 60-day credit for DigitalOcean: ott3rly.com/do NordVPN: ott3rly.com/NordVPN Domain: ott3rly.com/123-reg-co-uk Timestamps: 0:...
Open Redirect Vulnerability
Просмотров 1982 месяца назад
This is the second video of the Hacking Web Vulnerabilities series about Open Redirect. For more payloads, you could check the PayloadAllTheThings page: github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Open Redirect Also, there are pretty good examples mentioned on the HackTricks: book.hacktricks.xyz/pentesting-web/open-redirect Twitch: ott3rly.com/twitch Patreon: ott3rly.com/patreon Twi...
IDOR and BAC Vulnerabilities
Просмотров 3222 месяца назад
Start of Web Hacking Vulnerabilities series. This episode is about Broken Access Control and Insecure Direct Object Reference issues. Twitch: ott3rly.com/twitch Patreon: ott3rly.com/patreon Twitter: ott3rly.com/X Discord: ott3rly.com/discord Get a $200, 60-day credit for DigitalOcean: ott3rly.com/do NordVPN: ott3rly.com/NordVPN Domain: ott3rly.com/123-reg-co-uk Timestamps: 0:00 - Intro 0:18 - W...
Browser Extensions for Bug Bounty
Просмотров 3412 месяца назад
Let's explore my favorite browser extensions. Here are the list for firefox: FoxyProxy - addons.mozilla.org/en-US/firefox/addon/foxyproxy-standard/ Wappalyzer - addons.mozilla.org/en-US/firefox/addon/wappalyzer/ Firefox Multi-Account Containers - addons.mozilla.org/en-US/firefox/addon/multi-account-containers/ Cookie-Editor - addons.mozilla.org/en-US/firefox/addon/cookie-editor/ DotGit - addons...
Own Blind XSS Server Setup
Просмотров 5683 месяца назад
The article to follow the setup: ott3rly.com/hunting-blind-xss-on-the-large-scale-part-1/ In case you want to go hunting after the setup, there is also good follow up article: ott3rly.com/hunting-blind-xss-on-the-large-scale-part-2/ My BXSS Hunting Methodology (Paid): www.patreon.com/posts/hunting-for-xss-112351849 Twitch: ott3rly.com/twitch Patreon: ott3rly.com/patreon Twitter: ott3rly.com/X D...
AXIOM vs ShadowClone
Просмотров 6235 месяцев назад
AXIOM vs ShadowClone
Common 403 Bypa$$es Part 2
Просмотров 9676 месяцев назад
Common 403 Bypa$$es Part 2
Andvanced SQLMap Customization
Просмотров 1,1 тыс.6 месяцев назад
Andvanced SQLMap Customization
Common 403 Bypasses Part 1
Просмотров 1,2 тыс.7 месяцев назад
Common 403 Bypasses Part 1
SQLi WAF Bypass Techniques Part 2 - Other Attacks
Просмотров 1,6 тыс.7 месяцев назад
SQLi WAF Bypass Techniques Part 2 - Other Attacks
SQLi WAF Bypass Techniques Part 1 - Time-Based Attacks
Просмотров 4,1 тыс.8 месяцев назад
SQLi WAF Bypass Techniques Part 1 - Time-Based Attacks
Find Sensitive Files with FFUF
Просмотров 2,9 тыс.8 месяцев назад
Find Sensitive Files with FFUF
Your Own Search Engines For Bug Bounty
Просмотров 1,1 тыс.9 месяцев назад
Your Own Search Engines For Bug Bounty
Active DNS Recon using AXIOM
Просмотров 7769 месяцев назад
Active DNS Recon using AXIOM
Building Own Nuclei Templates
Просмотров 1,5 тыс.9 месяцев назад
Building Own Nuclei Templates
Using Nuclei The Right Way
Просмотров 3,2 тыс.9 месяцев назад
Using Nuclei The Right Way
XSS WAF Bypass Techniques
Просмотров 6 тыс.10 месяцев назад
XSS WAF Bypass Techniques
Jump Over Firewall Finding Origin IPs
Просмотров 4 тыс.10 месяцев назад
Jump Over Firewall Finding Origin IPs
Recon on Steroids - Discover EVEN MORE Subdomains
Просмотров 2,7 тыс.10 месяцев назад
Recon on Steroids - Discover EVEN MORE Subdomains
Level Up Your Port Scanning Skills
Просмотров 1,8 тыс.10 месяцев назад
Level Up Your Port Scanning Skills
Master The Elite Hacker Search Engine
Просмотров 1,9 тыс.10 месяцев назад
Master The Elite Hacker Search Engine
Make Money 💸 Using Google Hacking
Просмотров 4,9 тыс.10 месяцев назад
Make Money 💸 Using Google Hacking
Skyrocket Your Bug Bounty Success Using These Crawlers 🚀
Просмотров 1,5 тыс.10 месяцев назад
Skyrocket Your Bug Bounty Success Using These Crawlers 🚀
Turning Wayback Machine Into GOLD MINING MACHINE 💰
Просмотров 1,8 тыс.11 месяцев назад
Turning Wayback Machine Into GOLD MINING MACHINE 💰
Headstart Your Bug Bounty Recon With AXIOM
Просмотров 2,8 тыс.11 месяцев назад
Headstart Your Bug Bounty Recon With AXIOM

Комментарии

  • @tomsong7595
    @tomsong7595 20 часов назад

    Kindly give more tips on Bug hunting

  • @tahsinhossain4413
    @tahsinhossain4413 День назад

    big fan of you bro🖤 your sqlmap customization is impressive 🔥🔥

  • @marios4275
    @marios4275 16 дней назад

  • @testchanel9992
    @testchanel9992 16 дней назад

    Thanks a lot for the comprehensive video, I looked for this information for a while

  • @lavirusec
    @lavirusec 17 дней назад

  • @Taidenz
    @Taidenz 24 дня назад

    You deserve my sub 🎉

  • @LeiYiren
    @LeiYiren 26 дней назад

    nice , juice

  • @warnawarni5227
    @warnawarni5227 Месяц назад

    Is CSRF stilll alive?

    • @Ott3rly
      @Ott3rly Месяц назад

      I do still see some writeups popping, so yes. Got to remember that there are some outdated websites still being used across the web.

  • @closevote
    @closevote Месяц назад

    thank you

  • @nishantdalvi9470
    @nishantdalvi9470 Месяц назад

    🧨🔥

  • @fazaareza3374
    @fazaareza3374 Месяц назад

    so if i can't find origin IP im done?

  • @Shintowel
    @Shintowel Месяц назад

    amazing

  • @bhaitechwala
    @bhaitechwala Месяц назад

    Hi @Ott3rly Thank you this amazing content. I have a question to be solved, How can we setup Axiom server on a physical Machine at my location Instead of a VPS. Please help, I will be grateful.

    • @Ott3rly
      @Ott3rly Месяц назад

      It would be the same process for your computer. Check out my blog, I have a lot of info about it.

    • @bhaitechwala
      @bhaitechwala Месяц назад

      @@Ott3rly while installing it always ask for cloud company name and its key. I wan't to install it on my physical ubuntu machine. can you share the link of that blog of yours, please?

  • @TheFunGunn
    @TheFunGunn Месяц назад

    Thankyou sir it was informative😊😊

  • @GilterLong
    @GilterLong Месяц назад

    make a video tutorial about axioms again, please...

  • @ehimuanfrancis3225
    @ehimuanfrancis3225 Месяц назад

    What tool is used to decete vulnerability?

  • @MFoster392
    @MFoster392 Месяц назад

    Thank you :)

  • @0xanupam
    @0xanupam Месяц назад

    thanks ott3rly :)

  • @Free.Education786
    @Free.Education786 2 месяца назад

    Excellent, bro 🎉❤. I have a TBSQLi XOR payload list with thousands of payloads in a text file. How do I add them to my SQLMAP? Thanks 🎉❤

  • @success_ambitionx377
    @success_ambitionx377 2 месяца назад

    Want to contact you ❤ ?

  • @MFoster392
    @MFoster392 2 месяца назад

    Thanks again :)

  • @ShermaMahdi
    @ShermaMahdi 2 месяца назад

    Amazing. i was following You Since day 1 Your always amazing Brother❤❤🎉

  • @Rev.Eng.-ru7hw
    @Rev.Eng.-ru7hw 2 месяца назад

    Brother keep it up, please add these videos in a playlist this will be amazing ❤️

  • @Lurd-q7s
    @Lurd-q7s 2 месяца назад

    Bro, can you share how to find any site that potential to find sqli but have waf also?

  • @bughunter9766
    @bughunter9766 2 месяца назад

    Hello Hero nice to see you bro

  • @GhtsGameplay
    @GhtsGameplay 2 месяца назад

    We finally see bro in real life!

  • @nishantdalvi9470
    @nishantdalvi9470 2 месяца назад

    Please cover all CWEs mapped with each Owasp top 10 category if possible, It will be very helpful

    • @Ott3rly
      @Ott3rly 2 месяца назад

      I will necessarily cover those, but I will cover most of that plus some advanced vuln types of bug bounty.

    • @nishantdalvi9470
      @nishantdalvi9470 2 месяца назад

      @Ott3rly Yaya 😁😊 eagerly waiting for upcoming videos

  • @razmjumehdi9069
    @razmjumehdi9069 2 месяца назад

    Please make a more video like it for BAC and special race condition🙏

    • @Ott3rly
      @Ott3rly 2 месяца назад

      I want to cover top issues first. Then I will see which videos are the most interesting for the public ;)

  • @razmjumehdi9069
    @razmjumehdi9069 2 месяца назад

    That's amazing bro 👏👏👏👏

  • @p0k3r1st
    @p0k3r1st 2 месяца назад

    perfect content

  • @jsmith85151
    @jsmith85151 2 месяца назад

    Nice!

  • @Ott3rly
    @Ott3rly 2 месяца назад

    VPN destroyed my steam, jeez.