Hacksplained
Hacksplained
  • Видео 126
  • Просмотров 783 895
Intigriti Out-Of-Scope Days 2022 - Mallorca 🇪🇸
When an entire company goes out-of-scope, it's the Intigriti OOS DAYS 🇪🇸
After our successful Series-B funding round, it was time to pack up the entire team an go ... to SPAIN! Together with 80 colleagues we flew over to the beautiful island of Mallorca and landed in a nice hotel in Magaluf. Our days were packed with good food, workshops, crazy team events and even bigger parties!
Come and join Intigriti if you also wanna be part of our OOS days in the future 😇
📃 This video is part of the HACKING ESCAPES playlist (ruclips.net/video/1-Gl5yTrXKo/видео.html).
🧘 Take this journey together with me. Calm down, stop hacking for just a bit and recharge yourself.
💡 If you have any questions or want t...
Просмотров: 1 569

Видео

Hacking Escape #6 - Island, Volcano & Lighthouse 🇪🇸
Просмотров 4932 года назад
Island, Volcano & Lighthouse - Viva la España 🇪🇸 Having studied together in 2016 in Malaga, we have not had the chance since to go on a boys trip. Haroun, Dino and I set out to explore the volcanic island of Gran Canaria (back to the roots travelling to Spain). Timeline: 00:00 Las Palmas de Gran Canaria 02:05 Dunas de Maspalomas 03:10 Puerto Morgan 04:05 El Roque Nublo 05:33 Arucas 05:51 Gáldar...
Bug Bounty Live Recon - Linked / JS Discovery!
Просмотров 3,8 тыс.2 года назад
Bug Bounty Live Hunting Part 2 - In episode 2, we are going to extract further subdomains from links and from discovering JS files🔥 Timeline: 00:00 Intro & Disclaimer 01:02 Burp Suite Crawling 02:57 Hakrawler 04:22 Privado VPN 05:15 Gospider 06:36 Subdomainizer 07:44 Outro Big thanks to the sponsor of this video: Privado VPN Get 69% off their regular prize with my link: privadovpn.com/limitedof...
Bug Bounty Live Recon - Grabbing Domains!
Просмотров 5 тыс.2 года назад
Bug Bounty Live Hunting Part 1 - In this first episode, we are going to look into grabbing root domains of a bug bounty target🔥 Timeline: 00:00 Intro & Disclaimer 01:09 ipinfo.io sponsoring 02:05 Study BB Program 02:20 Crunchbase.com 03:15 BGP Toolkit 04:24 Metabigor 05:11 Amass 06:03 Whoxy.com 07:04 Domlink.py 07:48 Builtwith.com 08:53 Shodan.io 09:50 Outro Big thanks to the sponsor of this vi...
2nd German Live Hacking Event (#KAEFERJAEGER)!
Просмотров 7892 года назад
2nd German Live Hacking Event (#KAEFERJAEGER)!
Hacking Escape #5 - Cliff Walks, Pubs & Guinness 🇮🇪
Просмотров 5042 года назад
Hacking Escape #5 - Cliff Walks, Pubs & Guinness 🇮🇪
OWASP TOP 10 - 2021 Edition
Просмотров 28 тыс.2 года назад
OWASP TOP 10 - 2021 Edition
Staying Up-To-Date In CYBERSECURITY!
Просмотров 2,4 тыс.3 года назад
Staying Up-To-Date In CYBERSECURITY!
I QUIT MY JOB 🤯 (And you will benefit!)
Просмотров 1,7 тыс.3 года назад
I QUIT MY JOB 🤯 (And you will benefit!)
Finding Secrets in Public Github Repositories (the SAST way)
Просмотров 9163 года назад
Finding Secrets in Public Github Repositories (the SAST way)
Finding Vulns in Public Github Repositories (the SAST way)
Просмотров 1,1 тыс.3 года назад
Finding Vulns in Public Github Repositories (the SAST way)
Finding vulnerabilities with automation (the SAST way)
Просмотров 6 тыс.3 года назад
Finding vulnerabilities with automation (the SAST way)
Burp Suite Professional Features For Free (Pimp your Community Edition)
Просмотров 13 тыс.3 года назад
Burp Suite Professional Features For Free (Pimp your Community Edition)
Python Dependency Confusion (Demystified)
Просмотров 1,5 тыс.3 года назад
Python Dependency Confusion (Demystified)
★★★★★ Extra Language (Broken Anti Automation)
Просмотров 4,3 тыс.3 года назад
★★★★★ Extra Language (Broken Anti Automation)
★★★★★ Change Benders Password (Broken Authentication)
Просмотров 8 тыс.3 года назад
★★★★★ Change Benders Password (Broken Authentication)
@VickieLiDev and I chat about Bug Bounties, Infosec, Jobs and More
Просмотров 1,3 тыс.3 года назад
@VickieLiDev and I chat about Bug Bounties, Infosec, Jobs and More
Pentest Interview Questions (Junior / Senior / Principal)
Просмотров 24 тыс.3 года назад
Pentest Interview Questions (Junior / Senior / Principal)
★★★★ NoSql Manipulation (Injection)
Просмотров 7 тыс.3 года назад
★★★★ NoSql Manipulation (Injection)
★★★★ Nested Easter Egg (Cryptographic Issues)
Просмотров 5 тыс.3 года назад
★★★★ Nested Easter Egg (Cryptographic Issues)
OSWE Review - Tips & Tricks (Offensive Security Web Expert)
Просмотров 19 тыс.3 года назад
OSWE Review - Tips & Tricks (Offensive Security Web Expert)
2020: A Year in Review (Hacksplained Edition)
Просмотров 2133 года назад
2020: A Year in Review (Hacksplained Edition)
Merry Christmas (Give-Away)
Просмотров 4863 года назад
Merry Christmas (Give-Away)
The Motivational Advice You Never Asked For (Bug Bounty Style)
Просмотров 2,5 тыс.3 года назад
The Motivational Advice You Never Asked For (Bug Bounty Style)
Faster Bounty Rewards With 5 Easy Tips
Просмотров 1,7 тыс.3 года назад
Faster Bounty Rewards With 5 Easy Tips
★★★★ Misplaced Signature File (Sensitive Data Exposure)
Просмотров 3 тыс.3 года назад
★★★★ Misplaced Signature File (Sensitive Data Exposure)
★★★★ Login Bjoern (Broken Authentication)
Просмотров 6 тыс.3 года назад
★★★★ Login Bjoern (Broken Authentication)
★★★★ Legacy Typosquatting (Vulnerable Components)
Просмотров 4,1 тыс.3 года назад
★★★★ Legacy Typosquatting (Vulnerable Components)
First German Live Hacking Event (Kaeferjaeger Style)
Просмотров 1,1 тыс.3 года назад
First German Live Hacking Event (Kaeferjaeger Style)
★★★★ GDPR Data Theft (Sensitive Data Exposure)
Просмотров 4,4 тыс.3 года назад
★★★★ GDPR Data Theft (Sensitive Data Exposure)

Комментарии

  • @hichemsavastano4430
    @hichemsavastano4430 5 дней назад

    Hello 🙂 i have long time and i was searching for tool or something like i give it the source code and she find the mistakes inside and vulnerability's i think that help me on my journey and im new in bug hunting 😅

  • @user-go3zu4nf5c
    @user-go3zu4nf5c 29 дней назад

    Lol i can see your basket with an apple juice

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    Thanks for all juice-shop run👍 greetings from Türkiye 😁

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    eyw

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    ilqinç

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    eyw

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    😮

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    vayqw

  • @TheMilesPrower
    @TheMilesPrower Месяц назад

    You can figure out it use a base64 crypto because when you intercept a login callback we can see a bunch of SHA-1 and base64 encrypted tokens in the session loggin. Don't know why they do not accept SHA-1 as an excuse though.

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    eyw

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    ha

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    eyw

  • @aliuzun8885
    @aliuzun8885 Месяц назад

    6:10 inş knk

  • @kalendra.ethicalhacker
    @kalendra.ethicalhacker 2 месяца назад

    I applied for a job as penetration testing , for my online interview , I want to show by bug bounty hunting skills , my hall of fames , how I do testing by screen sharing , is that helpful

  • @JoudNovember
    @JoudNovember 2 месяца назад

    I dont have add to basket button

  • @user-vg3jh7lg6o
    @user-vg3jh7lg6o 2 месяца назад

    I Waited for this video

  • @mangwibenita3138
    @mangwibenita3138 2 месяца назад

    How do I link juice box to burp?

  • @MistaYo9221
    @MistaYo9221 3 месяца назад

    Hi @Hacksplained. How do you reset the challenges? Every time i open a new juiceshop page it says i have completed 57% of the challenges

  • @AbdulHannanEngg
    @AbdulHannanEngg 3 месяца назад

    how to get jpeg file/code u hve pasted

  • @joesiu4972
    @joesiu4972 4 месяца назад

    very good bro

  • @legio-nyc
    @legio-nyc 4 месяца назад

    Hacksplained is the best teacher! Thanks for helping us noobs get through a lot of complicated stuff.

  • @user-jn3vf8zg4k
    @user-jn3vf8zg4k 4 месяца назад

    Big love from Pakistan 🇵🇰✅❤

  • @mvs9549
    @mvs9549 5 месяцев назад

    how do u know which cipher encryption to use??

  • @dudetime3720
    @dudetime3720 5 месяцев назад

    I came here because I’m on OWASP Juice Shop for the first time. I was scrolling down my HTTP History on Burp and I got the “solved challenge” banner for “Manipulate Basket” and all I did was scroll down burp. I didn’t even make an account on Juice shop. I know hacks, exploits, and vulnerabilities can be found by accident, but like what did I do? 💀

  • @tauseef3270
    @tauseef3270 5 месяцев назад

    thanks man! really helped a lot

  • @LordAikay
    @LordAikay 6 месяцев назад

    All right I’m thanks for your video I really loved it so am I was wondering can I get your email address I really want to talk to you about something

  • @flookergames
    @flookergames 6 месяцев назад

    i cant find the bid

  • @edclam
    @edclam 6 месяцев назад

    Alas, it's free no more, a payment method must be added. Here's what I was shown just now: 'Basic dynos ~$0.010/hour'. Personally I don't mind making reasonable payments. It's the cancellation or forget to cancel and using the services inadvertently that can be concerning. So if that's fine with you do enjoy it! Plus, I already have a few deployments made on Kali Linux so don't really need the Heroku vesion. Anyway, happy hacking (legally)!

  • @guriktala3508
    @guriktala3508 6 месяцев назад

    🫡

  • @anonyone8834
    @anonyone8834 6 месяцев назад

    I DID IT in browser only, just use the endpoint of feedbacks

  • @rajendr7235
    @rajendr7235 6 месяцев назад

    Hii

  • @rajendr7235
    @rajendr7235 6 месяцев назад

    ❤❤❤

  • @ritubanerjee5061
    @ritubanerjee5061 7 месяцев назад

    This is truly a brilliant solution! I haven't downloaded the script, but you can display a suitable message and terminate the loop as soon as you get a 200 response (instead of 401) from the server.

  • @h0udini420
    @h0udini420 7 месяцев назад

    Great stuff! could you please make demos for maven and rubygems as well?

  • @sethwikle8927
    @sethwikle8927 8 месяцев назад

    why is this video age restricted lmao

  • @vardanverma1585
    @vardanverma1585 8 месяцев назад

    why cant i edit in burp raw req part

  • @gschitz
    @gschitz 8 месяцев назад

    ⥊ 15: 13 0: Good (if not good, then not zero) 0001: Uniqueness 001: Identity 002: Individuality 003: Variability 004: Diversity 005: Tolerance / Inclusion 006: Acceptance 007: Consonance / Harmony 008: Innocence 009: Transcendence 01: Awareness 02: Diversion 03: Sensing 04: Love 05: Grace 06: Reasoning 07: Ingenuity 08: Decency / Honesty 09: Truth Seeking 1: Ethical 2: Problem-Solution 3: Situation 4: Abstraction 5: Expression 6: Why/Who/When/How/Where/What 7: Information/Code 8: Stability 9: Sanity 10: Network (Good Network, because zero) 11: Justice 12: Time/Spread/Dissipation/Easter 13: Death / Fact 14: Cognition 15: Agent 16: Reason 17: Discourse 18: State 19: Discipline / Control 20: Judgement 21: To Solve Problems with Ethics 22: Resistance / Differentiate 23: Consideration 24: Humor / Mental State 25: Behavior 26: Motivation 27: Cohesion 28: Dependability 29: Diagnostic 30: Liberty 31: Consent 32: Discernment 33: Response 34: Ideas 35: Showing 36: Option 37: Opinion 38: Decision 39: Prognostic 40: Wellness 41: Attention 42: Critical Thinking 43: Acknowledgment 44: Free Love 45: Plan / Task Force 46: Purpose 47: Perspective 48: Character 49: Ambition 50: Good Expression 51: Manifestation 52: Support 53: Respect 54: Care 55: War 56: Pointing / Profiling 57: Tell / Counter-Terrorism 58: Invoking / Building 59: Proficiency / To Excel 60: Certainty 61: Identification 62: Qualification / Characterization 63: Inquiring 64: Conjecturing 65: Function / Role 66: Investigation 67: Arguing 68: Indicator 69: Scrutinity 70: Validation 71: Illustration / Knowledge 72: Construct 73: Explanation / Informing 74: Data 75: Materialization 76: Delineation / Instruction 77: Flow / Cadency 78: Share 79: Accountability 80: Personal Soverenity 81: Independency Constancy 82: Resilience 83: Established 84: Autonomy 85: Executing 86: Authority 87: Stream 88: Consistency 89: Boldness 90: Wisdom 91: Assertiveness 92: Optimism 93: Scrupulousness 94: Integrality 95: Composure 96: Blockchain: ⥊ (TRACE MARKER) 97: Anarchy 98: Veganism 99: Revolution 100: Liberation 101: Peer-2-Peer 102: Partnership 103: Proposal 104: Design 105: Collaboration 106: Necessities 107: Vocabulary 108: Clarity 109: Regulation 110: Virtue 111: Honor Righteousness Principle 112: Distributed Ledger 113: Privacy / Assistance 114: Abolitionism 115: Pride 116: Justifiable 117: Equitable 118: Liberation State Formation 119: Mission / Objective 120: Harvest 121: Deliverance 122: To Sort Out / Separate 123: Inclusion 124: 125: Differentiate 126: Distinguish 127: 128: Frankness / 129: 130: Realization 131: Fulfillment 132: Regard 133: Responsability 134: Address 135: Execute 136: Obtain 137: 138: To Mark / Formation 140: Serenity 141: Idea 144: To Notice 148: Mindfulness 150: Good Character 151: Virtue 153: Declaring 155: Perform 158: Rising 160: Technology 161: Communication Systems 166: Causality 167: To Label 170: Knowledge 185: System Accessibility 181: Structure 199: Commitment Conviction 200: Sanctuary 209: Enlist 210: Resolution 211: To Engage 212: Secure 215: Mobilize 219: Annihilation 220: Contemplation / Meditation 221: Either Way / Alignment 222: Cooperation 230: Resilience 250: To Thrive 255: To Emerge 266: Correlation 299: Elevate 300: Crusade / Jihad 301: Confront 309: Consensus 310: Self 311: Bodily Autonomy 320: Deliberation 322: Oportunity 330: Win-Win 331: Self-Determination 333: Abundance 340: Conceive 353: Energy Management 360: Technology 373: Remote Killing 370: Efficiency 390: Economicity 399: Revolution Gear 400: Earth Population 410: Permaculture 430: Ecosystem 440: Fellowship 444: Direct Digital Democracy 500: Assumption / Honor 501: Leadership 502: Credit 503: Esteem 509: Prestige 510: Admiration 511: Heroism 512: Altruism 520: Proficiency 530: Acceptance 535: Denoucing 540: Appreciation 550: Diplomacy 555: Gathering 556: To Pick Up Someone/Something 590: Excellency 600: Organizator 620: Diagnose 660: Operation 661: Operator 665: Role 666: Method 676: Deduce 700: Honor 702: Credit 710: Intelligence 717: Desing 720: Quantum Mechanics 733: Argorithm Explaining 747: Artificial Intelligence 750: Consolidation 751: Enlightment 756: Inspire 757: Prompt 766: Plan 770: The Gear 771: File 773: Algorithm Recoginzing 775: Output 777: Pattern / Rhetoric 778: Development 780: Systematization 799: Revolution Algorithm 800: Providence / Heroism 801: Production 802: Necessities 803: Resorces 804: Energy 808: Renewable Cycle 810: Permaculture 820: Management 830: Logistics 831: Scheme 832: Reach 833: Demand 834: Stock 835: Distribution 840: Consumption 850: Labor 860: Human Resources 863: Assignments 870: Structure 880: Peace 888: Globalization 890: Needs 899: Conception 900: Transparency 910: Institutions 911: Emergency Call 930: Energy Distribution 931: Only One Global Currency 960: Blockchain 962: Traceability 970: Optimization 990: Inspection 995: Accountancy 998: Regulation 999: Implementation 1000: Militancy 1001: Nova Era 1030: 1042: Drug Liberation 1100: Liberation Army 1160: Pacifism 1312: Boycott 1400: Unity 1500: Benevolence 1550: Charity 1807: Black & Yellow 2222: Paradox 3000: Freedom 3100: Triumph 3311: To Revolt 3330: We All Can Live In Abundance 4000: Coexist 4411: Riders of Justice 5000: Glory 5500: Greatness 6999: Mystery 7220: Unified Field Theory 8000: Sustainability 8999: Finitude 9997: Discovery 9998: Unknown 9999: Universe 10000: Existence . This is a Numeric Matrix for Communications Purposes. . This Can Be Used to Convey Meaning. Ex.: 2034: To Judge the Idea. . Mathematical Operators Can Be Used to Calculate Meaning. Ex.: To Judge the Expression: 25 20 + 5 = 25 (Behavior) . Logical Operators to Create statements. Ex.: ¬11: 13. If not Just then Death. . Colors can also be used as information. - You can help build it.

    • @gschitz
      @gschitz 8 месяцев назад

      5513: 713

  • @trustedsecurity6039
    @trustedsecurity6039 8 месяцев назад

    It isnt a dom XSS it is a reflected

  • @andreadistasi8842
    @andreadistasi8842 8 месяцев назад

    You are not giving answers... 😅😅

  • @jaywandery9269
    @jaywandery9269 9 месяцев назад

    Whats your take on skipping the OSWA & straight to the OSWE

  • @NoONE-bk7ud
    @NoONE-bk7ud 9 месяцев назад

    or you can search on the md5 hash on amy's password on google

  • @call-me-potato.
    @call-me-potato. 10 месяцев назад

    poor explanation.

  • @mosk53
    @mosk53 10 месяцев назад

    dude don't giving the answers was a great idea, it helps learning a lot

  • @nathanharmatys
    @nathanharmatys 10 месяцев назад

    Dude stop saying that this is gonna happen you have to install the files for it to install and it takes hours its not just gonna bring you ti the login screen

  • @presequel
    @presequel 10 месяцев назад

    nice advice, only not sure if the money part of the goal is what i expect in a goal...but maybe thats part of bugbounty, the bounty thing :D

  • @theairsharma
    @theairsharma 10 месяцев назад

    bro was going with ×0.125 speed. But it was good

  • @Missjaatni3566
    @Missjaatni3566 10 месяцев назад

    Hlo

  • @otonomimusic
    @otonomimusic 11 месяцев назад

    1.25x speed recommended

  • @presequel
    @presequel 11 месяцев назад

    great videos, i really enjoy them. they are easy to follow and i learn a lot, thanx!

  • @LuminaraLyric
    @LuminaraLyric 11 месяцев назад

    This attack is no longer effective in the modern version of Juice Shop (v15.0.0 in this instance). While attempting this attack, a new user is generated with the given XSS string. However, the system now filters out all HTML tags from the supplied string, resulting in the creation of a new user with an empty string as their login