Cross-Site Scripting (XSS) Explained And Demonstrated!

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • // Membership //
    Want to learn all about cyber-security and become an ethical hacker? Join this channel now to gain access into exclusive ethical hacking videos by clicking this link: / @loiliangyang
    // Courses //
    Full Ethical Hacking Course: www.udemy.com/...
    Full Web Ethical Hacking Course: www.udemy.com/...
    Full Mobile Hacking Course: www.udemy.com/...
    // Books //
    Kali Linux Hacking: amzn.to/3IUXaJv
    Linux Basics for Hackers: amzn.to/3EzRPV6
    The Ultimate Kali Linux Book: amzn.to/3m7cutD
    // Social Links //
    Website: www.loiliangya...
    Facebook: / loiliangyang
    Instagram: / loiliangyang
    LinkedIn: / loiliangyang
    // Disclaimer //
    Hacking without permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing so that we can protect ourselves against the real hackers.

Комментарии • 141

  • @WenboZhou
    @WenboZhou 2 года назад +56

    With knowing know it works, the importance of sanitizing user input is obvious. Great tutorial!

    • @maxselom839
      @maxselom839 Год назад

      How get free internet Access in windows do vidéo?

  • @True0Hustle
    @True0Hustle 2 года назад +7

    This was such a great example of how XSS gets implemented. Great example, Love you all your content. Keep up the great work :)

  • @michaelobando8560
    @michaelobando8560 2 года назад +20

    I would like to know what is "Broken Access Control" from OWASP TOP list. What is that vulnerability? Can you explain that vulnerability in a video please?

    • @daudameen1916
      @daudameen1916 2 года назад +2

      Broken access control is where the developers of the website believe that users will not act maliciously towards a website for example a developer may believe that a user will use the website just the way it is intended to however a hacker would manipulate access control methods to gain unauthorised access a common type of exploit for broken access control is when a hacker adapts parameters of a url to gain access to an admin account.

  • @sneibarg
    @sneibarg 2 года назад +6

    I like that you refer to yourself as "Script Kiddie Loi." As a former script kiddie of the late 90s, that resonates with me.

  • @FlyNewss
    @FlyNewss 2 года назад +9

    Sir can you make a video on how to do web exploration from beginning to advance please sir ??

  • @BesenTV
    @BesenTV 2 года назад +4

    I love it when you say: "That's it. It's GAME OVER!" lol

  • @asgaraliyev8740
    @asgaraliyev8740 2 года назад +3

    thank you

  • @dareenoch6880
    @dareenoch6880 2 года назад +5

    The endpoint has to be vulnerable to open redirect to perform a cross site scripting

    • @dareenoch6880
      @dareenoch6880 2 года назад +1

      A reflected xss*

    • @racapadexxa_
      @racapadexxa_ 2 года назад +1

      And there's a flag you can put on Cookie's (who's name I don't remember now) than disallows document.cookies access to certain cookies

  • @rom1463
    @rom1463 2 года назад +5

    Perfect I was watching Xss and I was ready to tap xss tutorial then loi is there nice !

  • @Monkeyindatrees
    @Monkeyindatrees 2 года назад +12

    would you please share the code you are using to try your demos out myself?
    Could be a cool thing

  • @leonplis9926
    @leonplis9926 2 года назад +4

    this is the best video you've uploaded until now by far. there isn't too much tutorials about XSS on youtube

  • @iShallEatChips
    @iShallEatChips 2 года назад +1

    Crazy that I just posted about this on another video you did, and then today I see this video made by you. Epic. Thanks for making this.

  • @saft2529
    @saft2529 2 года назад +2

    finally xss tutorial(really want to learn xss scripts)

  • @Sam-fh1ez
    @Sam-fh1ez 2 года назад +13

    Another great video, perfect explanations. This is what we need!

  • @ClashWithHuzefa
    @ClashWithHuzefa 2 года назад +3

    Relaxing, simple and good videos as always. no complaints

  • @sindhuja.dindigala7598
    @sindhuja.dindigala7598 2 года назад +1

    That hat suits you perfectly sir. Great content:)

  • @rai8855
    @rai8855 2 года назад +2

    Ohhhh waited for this one

  • @EmreLism
    @EmreLism 2 года назад +3

    Most of the Frameworks are XSS safe. Is there any next level xss?

  • @pushpakvuppalapati868
    @pushpakvuppalapati868 2 года назад +2

    Hey Liang !!! great follower of your videos. Love from India.. Can you please do a tutorial on DOM XSS.

  • @aaronbaldwin4900
    @aaronbaldwin4900 Год назад +1

    I love your channel. Succinct and straight to the point with good examples

  • @mrawesome5286
    @mrawesome5286 2 года назад +3

    Love you hacker loi ❣️❣️❣️❣️❣️❣️❣️ loving your sessions 🦋

  • @Potter_3810
    @Potter_3810 2 года назад +2

    all what you do is amazing
    as hacking I think you should a video on how installing software on a USB or hard disk just like in films

  • @GameReality
    @GameReality 2 года назад +3

    Absolutely amazing :D
    Love this ........ :)

  • @FrogInALog_
    @FrogInALog_ 10 месяцев назад

    me when I alert(1)

  • @JL-ud6xx
    @JL-ud6xx 2 года назад

    Good demo on how to perform xss practically!

  • @themistoclesnelson2163
    @themistoclesnelson2163 2 года назад +1

    Great video!

  • @ultron7461
    @ultron7461 2 года назад +1

    always awesome vdos. thanks for that. sir. 😊

  • @abdullahshune5150
    @abdullahshune5150 2 года назад

    that what am looking for am glad my teacher is HE :)

  • @infinitybrutal
    @infinitybrutal 2 года назад +1

    Let's Go With One More Toutorial

  • @hackerloit
    @hackerloit Год назад +1

    where can I try this steps for practicing ?

  • @dapakers
    @dapakers 2 года назад

    sir can u help us caprture scammer here at my place.weve already filed a police complaint yesterday.. but they cant do nothing.coz here at province theirs no such thing as cybersecurity agancy..

  • @akashbharti8748
    @akashbharti8748 2 года назад +2

    Gm from unkown

  • @ArSiddharth
    @ArSiddharth 2 года назад

    Nice video sir | I'm Big fan from india ❤️

  • @abdulrazzaq5577
    @abdulrazzaq5577 2 года назад

    Well explained
    Well done👍

  • @Thousif_talks
    @Thousif_talks 2 года назад +1

    Hello Sir, can you please Make an vedio on advanced android and windows hacking

  • @isabellalobo2577
    @isabellalobo2577 2 года назад

    Would it this apply to a website landing page link as well? I have clicked in a landing page link and it was a scam. Could my computer be hacked ? How do I fix it?

  • @Noname_vvb-w6n
    @Noname_vvb-w6n 19 дней назад

    you are my best

  • @rahultiwari.95
    @rahultiwari.95 2 года назад

    great video dude

  • @Skaxarrat
    @Skaxarrat Год назад

    Stellar explanation

  • @mytube7473
    @mytube7473 9 месяцев назад

    Nice, BUT its not clear in your video which of those burp attacks worked ?? I know you showed how to put it into the browser manually, but that would be just as slow as trying them all manually. Does burp indicate which worked?

  • @bayandamabuza6587
    @bayandamabuza6587 2 года назад

    Enlighten me, but already have login credentials

  • @jail8011
    @jail8011 2 года назад

    You should do a full ethical hacking course

  • @michealsichilongo
    @michealsichilongo 2 года назад +1

    Awesome 👍👍

  • @husinhmada7618
    @husinhmada7618 2 года назад

    Please make a video explaining the write exploiting vulnerabilities and port

  • @user-ke8of7xl9v
    @user-ke8of7xl9v 2 года назад +2

    Sorry, I'm a little confused 👀💧 I can see the injection part but can't see how exactly how someone's credentials can be stolen.
    I'm guessing that someone's session ID is being stolen. I might be able to understand better if this was demonstrated with a second device.
    Good video though. I know making videos takes a lot of effort 👀👍

    • @imaboyinblack
      @imaboyinblack 2 года назад +2

      the phpsessionid he got was the admin account's session id so he replaced his own one with the admin's one after he logged out and then that put him into the admin account, but i dont think it can just pull straight up CREDENTIALS like a password

    • @jaystan4597
      @jaystan4597 Год назад

      @@imaboyinblack once you have the session id, no need for password

  • @nirajsalunkhe5532
    @nirajsalunkhe5532 2 года назад +1

    Thank you sir😀

  • @daivomjoshi56
    @daivomjoshi56 2 года назад

    WHICH ONE WOULD YOU PREFFER ? WHICH ONE IS THE BEST IN ALL TERMS ??
    KALI LINUX or PARROT OS ?

    • @nono-fq1tl
      @nono-fq1tl 2 года назад

      Both are very solid distros. Started with kali but enjoying the parrot more recently.

    • @daivomjoshi56
      @daivomjoshi56 2 года назад

      @@nono-fq1tl Which one has more functionality and capabilities ?

  • @_bite_meals
    @_bite_meals 2 года назад

    Hey I am 1st to like 😁

  • @technofire4899
    @technofire4899 2 года назад

    Ur video to much help full 😌🥺🥺

  • @arghya_2010
    @arghya_2010 2 года назад

    You are a genius

  • @team_narsimha
    @team_narsimha 2 года назад

    Loi your all time best hacker

  • @FunTime-qj9hn
    @FunTime-qj9hn 2 года назад +1

    can i get wifi passwords on mobile

  • @leblanc666666
    @leblanc666666 2 года назад

    definitely interested in DOM-XSS, that stuff always makes my nose bleed :P

  • @user-oy5ij3oy4r
    @user-oy5ij3oy4r Год назад

    from where i can get the file xss.txt ? ?
    thank you !

  • @t2pfearmaxx
    @t2pfearmaxx 2 года назад

    @loi i need your help asap

  • @soniatix
    @soniatix 2 года назад

    Perfect ! Thanks !

  • @sakshamsharma9763
    @sakshamsharma9763 2 года назад +1

    Sir can you make a video on how to do web exploition from beginning to advance please sir ??

  • @unknownanonymous6247
    @unknownanonymous6247 2 года назад

    Sir pls upload a video on how to setup a proxy chains

  • @rukyp
    @rukyp Год назад

    very naice, i laike.. 🙂

  • @icycreeks1471
    @icycreeks1471 2 года назад

    Hello mr loi, need tut how to set up hackazon

  • @abdullahshune5150
    @abdullahshune5150 2 года назад

    Teacher I have A Idea For Your Next Class Is About SQLite3 Database Thank You it would help me 100%

  • @coleXao
    @coleXao 11 месяцев назад

    You demonstrated it on this hackaton page...so suposedly these parameters that you type on the url would work on any other site?

  • @whothefuhkizzy8797
    @whothefuhkizzy8797 2 года назад

    Yo man I’m just starting out with hacking. I’ve got kali Linux booted up from my hard drive but I’m having a hard time finding out where to begin because this shit is a lot to learn. Can you or anyone else point me in the right direction of some good educational sources? Where did you learn everything you know

  • @ReligionAndMaterialismDebunked

    :25 no fingertip covering of the gloves. 💀💀😅😅 Wipe that stuff later? XD

  • @tatsugaya3548
    @tatsugaya3548 2 года назад

    Yeahhhh i'm there !!!

  • @ShubhamPawde
    @ShubhamPawde 2 года назад

    Love u loi for such ur content

  • @aruyoshin8103
    @aruyoshin8103 2 года назад

    Can we upload php shell using this vulnerability?

  • @dickjohnson6927
    @dickjohnson6927 Год назад

    "to test your site" yeah sure my site *wink*

  • @Doralex1708
    @Doralex1708 2 года назад +1

    The payloads that you used are directly from Burp or did you coded them yourself ?

  • @andy_SgS
    @andy_SgS 2 года назад

    What software does he use to enhance his microphone?

  • @bauyrzhanmustafa4334
    @bauyrzhanmustafa4334 10 месяцев назад

    Is that method similar to CSRF or what?

  • @singing_dev
    @singing_dev 2 года назад +2

    Thank you so much for this video Hacker Loi, I'm a huge fan 💙

  • @dguy-xk4fc
    @dguy-xk4fc 9 месяцев назад

    5:49 that is problematic indeed

  • @bradcage7345
    @bradcage7345 2 года назад

    Please make a video on call spoofing

  • @RockyBhai-dz2lc
    @RockyBhai-dz2lc Год назад

    Is in hacking,need high ammount of money....?

  • @hey88ho
    @hey88ho 2 года назад

    Can someone please tell me how can we prevent this from happening?

  • @arefabdollahi5649
    @arefabdollahi5649 2 года назад

    shuch a wow ,I LOVE YOUUUUUUUU LOI ,you are the best

  • @boss-pk4qk
    @boss-pk4qk 2 года назад

    What about getting into car systems

  • @ritiktiwari8535
    @ritiktiwari8535 7 месяцев назад

    I did not get anything after 5:24 can anyone please explain it?

  • @ohhyoutube1314
    @ohhyoutube1314 2 года назад +1

    hello hackerloi can u plz make a tutorial on how to embed payload in an image file in kali linux

  • @darkerh4ck3r61
    @darkerh4ck3r61 2 года назад

    You are my idol

  • @kurd1208
    @kurd1208 2 года назад

    bro how to recieve to netcat and where i write my ip adrees in alert please help me

  • @nusn43
    @nusn43 2 года назад +1

    Mantap

  • @ricardogabrieldavid4688
    @ricardogabrieldavid4688 Год назад

    Thanks a lot

  • @usmansiddique3694
    @usmansiddique3694 2 года назад

    how can I will be a member of this youtube channel so I can watch videos

  • @CyberSecForce
    @CyberSecForce 2 года назад

    Super 👌

  • @awaw1110
    @awaw1110 2 года назад

    I literally watched a white hat hacker do his thing

  • @mestanislao857
    @mestanislao857 2 года назад

    Thank you..

  • @name_unavailable7
    @name_unavailable7 5 месяцев назад

    Where can I get the file for the website

  • @fonte1184
    @fonte1184 2 года назад

    Please what OS do I need to get started

  • @lolamax25
    @lolamax25 2 года назад

    does it work against secured web sites?

  • @1uk416
    @1uk416 2 года назад

    Yeaaa boi

  • @godalfred2266
    @godalfred2266 2 года назад

    My question - is hacking of online games possible ??????

  • @user-qt3bd3mx4h
    @user-qt3bd3mx4h 2 года назад

    Hello 👋

  • @sotecluxan4221
    @sotecluxan4221 2 года назад

  • @Corrupted__303
    @Corrupted__303 2 года назад

    hello i=sir big fan can you show how to remove the new virus .vfgj

  • @LogicalPersonAllTime
    @LogicalPersonAllTime 2 года назад

    i also want to learn EH i cant pay please help

  • @dinujaonline6312
    @dinujaonline6312 2 года назад

    a new hat

  • @03458324406
    @03458324406 2 года назад

    How to get membership

  • @akshaykusagur5104
    @akshaykusagur5104 2 года назад

    Why you can't say slowly, it's little bit difficult for beginner