Это видео недоступно.
Сожалеем об этом.

Easy way to Find Blind Stored XSS | Bug bounty poc

Поделиться
HTML-код
  • Опубликовано: 8 мар 2024
  • Disclaimer: This video is for strictly educational and informational purpose only. I own all equipment used for this demonstration. Hacking without permission is illegal so always ensure you have proper authorization before using security tools in any network environment. thanks.

Комментарии • 219

  • @mishogeorgiev6349
    @mishogeorgiev6349 5 месяцев назад +30

    the only channlle on youtube that actually shows real pentesting. Good music choice.

    • @lostsecc
      @lostsecc  5 месяцев назад +5

      thnq so much its means a lot for me ❤️☺️

    • @sirajgamer7977
      @sirajgamer7977 5 месяцев назад

      Can I speak with you in private ​@@lostsecc

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      telegram join @lostsec

  • @martinoliva3126
    @martinoliva3126 5 месяцев назад +4

    Great job bro, I love seeing real pentesting!

    • @lostsecc
      @lostsecc  4 месяца назад +1

      ❤️😇

  • @Shubham_Karne
    @Shubham_Karne 5 месяцев назад +4

    Most valueable content i found on RUclips ❤❤

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      nicee to hear this ❤️😇

  • @WSsd4
    @WSsd4 5 месяцев назад +5

    Your channel rising 👏 its all because of your talents and hard work.

    • @lostsecc
      @lostsecc  5 месяцев назад +3

      thnq so much brother good to see this type of reply ❤️😇

    • @WSsd4
      @WSsd4 5 месяцев назад +1

      @@lostsecc yeah keep going bro! I am proud of you

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️

  • @clearnyahundi6331
    @clearnyahundi6331 4 месяца назад

    Lostsec l consider you my diamond mine. God bless you my guy.....LOVE from ZIMBABWE ❤

    • @lostsecc
      @lostsecc  4 месяца назад +1

      my pleasure brother ☺️❤️😇Love you ❤️

  • @jakee.
    @jakee. 5 месяцев назад +3

    You deserve An Huge Subs!
    I’m Gonna wait for the Bug hunting Tutorials!!👌🏻👌🏻🐦‍🔥

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      sure all thing comming...❤️😇

  • @huncking
    @huncking 5 месяцев назад +1

    Truly appreciate you ❤️🙏🏻

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      my pleasure ❤️😇

  • @monikasharma2931
    @monikasharma2931 5 месяцев назад +3

    Nice tutorial and very helpful ❤

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️😇

  • @ryuz9485
    @ryuz9485 4 месяца назад

    the best content ever made I learned a lot of tools
    Can you please talk and teach us step by step in you upcoming vids ?

    • @lostsecc
      @lostsecc  4 месяца назад

      sure next video will be lit af ❤️

  • @RajaKumar-no6su
    @RajaKumar-no6su 2 месяца назад +1

    Hey Bro! What could be the weakness of this site. Is this site not doing proper Sanitisation? Or are there other causes?

    • @lostsecc
      @lostsecc  2 месяца назад +1

      yes input field not sanitize properly

  • @b4arabe132
    @b4arabe132 4 месяца назад

    i didnt understand the role of the first tool why u didnt directly jump to the second step (injecting the script directly), thank u so much for the content brother u r amazing

    • @lostsecc
      @lostsecc  4 месяца назад

      bcz i want to show cookie and more sruffs so i put that in end ❤️

    • @b4arabe132
      @b4arabe132 4 месяца назад

      @@lostsecc aahh okey thenk u so much im watching ur videos right now hahahh

  • @d4nm4c
    @d4nm4c 5 месяцев назад

    Love the tools you share!

  • @ferasalfarsi897
    @ferasalfarsi897 5 месяцев назад +1

    جزاك الله خير على الفيديو
    وننتظر منك المزيد

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      thnq so much ❤️ sure i will make

    • @amarsalim3718
      @amarsalim3718 5 месяцев назад

      ما فهمت واش قاعد يسوي ممكن تشرح لي و رمضانك مبارك

  • @user-vr6pg5lq9n
    @user-vr6pg5lq9n 5 месяцев назад

    Great keep going
    The community needs people like u

    • @lostsecc
      @lostsecc  5 месяцев назад

      my pleasure brother 😇❤️

  • @kingofgaming6743
    @kingofgaming6743 4 месяца назад

    Bro how do you only have 7k subs. Ur awsome

    • @lostsecc
      @lostsecc  4 месяца назад

      my 7k is like my 1million ❤️😇all are like brotherss

  • @tomashublik5586
    @tomashublik5586 5 месяцев назад

    Thanks for the "hacked by" html, imma slightly edit it and use for myself :)

  • @Inf3x_Me
    @Inf3x_Me Месяц назад

    I cannot run kali linux on virtualbox please can you tell me how did you do pentests with windows environment ?

    • @lostsecc
      @lostsecc  Месяц назад

      just install wsl2 kali

  • @akashpokemonhunter7502
    @akashpokemonhunter7502 5 месяцев назад +1

    Bro finishing portswigger labs and watching your video is enough for bug bounty hunting

    • @lostsecc
      @lostsecc  5 месяцев назад +3

      😇❤️ some amzing content comming soon bro

    • @akashpokemonhunter7502
      @akashpokemonhunter7502 5 месяцев назад +2

      @@lostsecc thanks bro u are creating a success in my life

    • @lukeastorw
      @lukeastorw 5 месяцев назад

      No. 1 understand coding how websites work, learn basics(JavaScript) ​@@akashpokemonhunter7502

  • @Noctuu
    @Noctuu 5 месяцев назад

    3:45 HHAHAHAHAHA LMAO I LOVE THAT

    • @lostsecc
      @lostsecc  5 месяцев назад

      ☺️❤️

  • @user-mk3zz8zn9b
    @user-mk3zz8zn9b 5 месяцев назад

    Bro i know your focusing on the beginners perspective, but i would love to see your way of thinking going through the harder and more complex topics like saml, and oauth, ssti and meta and tags there is no proper structural info on the web about meta tag vulnerabilities and s, and the video was cool, THANKS. I would also love share some of my work on your channel if youre willing, let me know..peace

    • @lostsecc
      @lostsecc  5 месяцев назад

      yeah i know all attacks my fav one is crlf so all will be comming soon..😉❤️

  • @prod.Kodein
    @prod.Kodein 2 месяца назад

    Hey bro you have great videos! Can you please tell me how long have you been doing this? I started 2 months ago learning javascript first.

    • @lostsecc
      @lostsecc  2 месяца назад +1

      just focus on owsp top10 and just learn little bit programming not neccesryy it take your so much time so better to focus on bugs..and do little bit programing in free time..

    • @prod.Kodein
      @prod.Kodein 2 месяца назад

      @@lostsecc that you so much for advice! Your channel is unique!

  • @MohammadWadi
    @MohammadWadi 2 месяца назад

    Hey bro I’ve been watching you for a week and your so good but i have a question im new to all these things i dont know coding nor bug bounty could you please tell me where to start thank you

    • @lostsecc
      @lostsecc  2 месяца назад

      start from portswigger labs

  • @Jaefrow
    @Jaefrow 5 месяцев назад +1

    Can I have the xss code, please? 😭🙏🏻🙏🏻

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      dm me in telegram t.me/lostsec

  • @AyushKumar-rg1uk
    @AyushKumar-rg1uk 3 месяца назад

    nice find but what's the impact looks like self xss

    • @lostsecc
      @lostsecc  3 месяца назад

      chain it with csrf

  • @kukevarius
    @kukevarius 5 месяцев назад +2

    How do you find vulnerable sites

    • @lostsecc
      @lostsecc  5 месяцев назад +3

      dork & bounty program

    • @Noctuu
      @Noctuu 5 месяцев назад

      ​@@lostseccthat first part may mean attacking websites that don't want u to attack them lmao

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      @@Noctuu we are good guy we report them

  • @ThoriqNs
    @ThoriqNs 5 месяцев назад

    Hey, i wanna start learning about bug hunting. Where do i start from?

    • @lostsecc
      @lostsecc  5 месяцев назад +3

      learn from portswigger and solve labs..

  • @kenjikakashi
    @kenjikakashi 5 месяцев назад

    May I ask for an explanation how or what happened when the page changed at 3:45?

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      its injection same like xss but its framed in website interface..

    • @kenjikakashi
      @kenjikakashi 5 месяцев назад +1

      @@lostsecc Thanks a lot, I do hope you post more a lot of this.

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      sure ❤️

  • @danteswrath2706
    @danteswrath2706 5 месяцев назад

    Could you teach me? Ive been getting so frustrated with trying to find bugs.

    • @lostsecc
      @lostsecc  5 месяцев назад

      just join my telegram channel that will help you t.me/lostsec

  • @darkmix4192
    @darkmix4192 5 месяцев назад

    I'm completed ethical hacking course but, don't have bug bounty knowledge. how to learn basic concepts and starting easy way to find bugs? Where? When? How do you learn bug bounty

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      just dm me in telegram.i will share premium.course free @lostsec

    • @darkmix4192
      @darkmix4192 5 месяцев назад

      @@lostsecc can you give your telegram I'd name?

  • @korea7moda
    @korea7moda 5 месяцев назад +1

    good luck bro 😊

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      thnq bro ❤️☺️

    • @korea7moda
      @korea7moda 5 месяцев назад +1

      @@lostsecc 😊

  • @H4cker_Nafeed
    @H4cker_Nafeed 5 месяцев назад

    You know something which we don't know...how do u find new targets ?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      dork or just pick randomly

  • @mahfujurrahman77
    @mahfujurrahman77 5 месяцев назад

    What impact this blind xss?? Same issue closed at N/A in hackerone

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      its stored xss bruhhh they can pay you high bounty if you find it 🧐

    • @mahfujurrahman77
      @mahfujurrahman77 5 месяцев назад

      @@lostsecc here you can find your own cookie via blind xss, whats the impact here??

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      you can inject cookie stealing script in your payload and when victim click on your profile pic there cookie will be stolen and send to your hosted server..

  • @user-ox2el9vw5q
    @user-ox2el9vw5q 3 месяца назад

    Bro tell me the name of tool that your using

    • @lostsecc
      @lostsecc  3 месяца назад

      there are many i shared in my github repo

    • @user-ox2el9vw5q
      @user-ox2el9vw5q 3 месяца назад

      Give me the link bro

  • @haroonwaheed3166
    @haroonwaheed3166 5 месяцев назад

    Thanks for providing such a great content. I have a question that you have uploaded a script from the notes into the username , i tried to find it in the local storage but did not get that. Can you explain about that script or where we can find them?

    • @lostsecc
      @lostsecc  5 месяцев назад

      thank you ❤️just msg me in telegram i will send @lostsec

    • @liamrodriq4299
      @liamrodriq4299 5 месяцев назад

      @@lostsecc telegram?

  • @mnageh-bo1mm
    @mnageh-bo1mm 5 месяцев назад

    but isn't this a self xss? how are you going to deliver it to victims ?

    • @lostsecc
      @lostsecc  5 месяцев назад

      chain with ssrf

    • @mnageh-bo1mm
      @mnageh-bo1mm 5 месяцев назад

      @@lostsecc how? you didn't show in the video at all

  • @tejaschitkara1531
    @tejaschitkara1531 5 месяцев назад

    Bri i've been watching your videos from a long time now... And u might as well know me....
    I've been doing all i could...
    Its just that at last, something lags behind and im not able to find vulnerabilities... Can u help me personally??? 😢

    • @lostsecc
      @lostsecc  5 месяцев назад

      sure just msg me in telegram

    • @sheewavee2924
      @sheewavee2924 5 месяцев назад

      @@lostsecc hii, I need help too. I tried to join your telegram channel but was unable to.

    • @lostsecc
      @lostsecc  5 месяцев назад

      t.me/lostsec

  • @Ajay_Yadav_Smart
    @Ajay_Yadav_Smart 5 месяцев назад

    Amazing brooooooo..❤❤

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq bro ❤️

  • @Tonksec
    @Tonksec 5 месяцев назад

    Man you are good

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq brother ❤️😇

  • @MrSimpleJemsYonatan
    @MrSimpleJemsYonatan 4 месяца назад

    Thank you so much bro

    • @lostsecc
      @lostsecc  4 месяца назад +1

      welcome brother ❤️😇

    • @MrSimpleJemsYonatan
      @MrSimpleJemsYonatan 4 месяца назад

      @@lostsecc please don't give up just because youtube rules bro, you can just make another account and we always follow you😁🙏 u r the best

    • @lostsecc
      @lostsecc  4 месяца назад +1

      this is the reason that i dont want to give up bcz i finds brother like you all☺️😇

    • @MrSimpleJemsYonatan
      @MrSimpleJemsYonatan 4 месяца назад

      @@lostsecc don't give up

  • @CHRISTIVN.OFFICIAL
    @CHRISTIVN.OFFICIAL 5 месяцев назад

    You on hackerone?

  • @hack4lx
    @hack4lx 5 месяцев назад

    both are self attackes...

    • @lostsecc
      @lostsecc  5 месяцев назад

      chain with csrf

  • @mnageh-bo1mm
    @mnageh-bo1mm 5 месяцев назад

    dude can you share all the sites you use for testing?

    • @lostsecc
      @lostsecc  5 месяцев назад

      join telegram channel i share there all @lostsec

    • @mnageh-bo1mm
      @mnageh-bo1mm 5 месяцев назад

      @@lostsecc i already joined it ... can you do a post with all of them at once and link it here?

  • @gojo99998
    @gojo99998 3 месяца назад

    Hey bro can you pls give me payload that you used in the end

    • @lostsecc
      @lostsecc  3 месяца назад

      join my telegram channel t.me/lostsec

    • @gojo99998
      @gojo99998 3 месяца назад

      @@lostsecc I have already joined many weeks ago but I couldn't find there 😕

    • @lostsecc
      @lostsecc  3 месяца назад

  • @sirajgamer7977
    @sirajgamer7977 5 месяцев назад

    Who can I install those tools

    • @lostsecc
      @lostsecc  5 месяцев назад

      i will share all tool in telegram channel @lostsec

  • @soulvideos7834
    @soulvideos7834 5 месяцев назад

    But bro pngtree don't have bug bounty program how you report bug and got 1000$ , please tell

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      i said its worth 1000$ just find it on bounty program and earn

  • @black_candles1212
    @black_candles1212 5 месяцев назад

    did you actually make 1000 from this? where did you submit it to

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      if you found this on bountty program its worth then 1k

  • @whateveritis0
    @whateveritis0 5 месяцев назад

    Any idea how to hunt on web3

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      video comming soon

    • @whateveritis0
      @whateveritis0 5 месяцев назад

      @@lostsecc waiting

  • @ficklem285
    @ficklem285 4 месяца назад

    This is self xss?

    • @lostsecc
      @lostsecc  4 месяца назад +1

      chain it with csrf

  • @EdrianMonk
    @EdrianMonk 5 месяцев назад

    very good

    • @lostsecc
      @lostsecc  5 месяцев назад

      thank you ❤️

  • @eobardthawnemcoc
    @eobardthawnemcoc 5 месяцев назад

    Bro if you don't mind tell what's ur pc/laptop specs

    • @lostsecc
      @lostsecc  5 месяцев назад

      bro i have hp.laptop but soon i will.make best setup for pc

    • @eobardthawnemcoc
      @eobardthawnemcoc 5 месяцев назад

      @@lostsecc yayay thank you also i have hp laptop too but it's kinda mid 😭

  • @mamunwhh
    @mamunwhh 5 месяцев назад

    can your share this payload second one?

    • @DeadlyFortato
      @DeadlyFortato 5 месяцев назад

      Skid

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      just msg me in telegram @lostsec

  • @macikj
    @macikj 5 месяцев назад

    Name of the song? thanks! you are legend

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      search literely me part 1 & 2 in yt

    • @macikj
      @macikj 5 месяцев назад

      @@lostsecc thanks

  • @WSh8500
    @WSh8500 5 месяцев назад

    How do you find websites to test for

    • @lostsecc
      @lostsecc  5 месяцев назад

      just randomnly & dork & bounty program

    • @davidvideos1359
      @davidvideos1359 4 месяца назад

      @@lostseccwhat’s dork

    • @lostsecc
      @lostsecc  4 месяца назад

      will share in telegram

  • @baravind719
    @baravind719 5 месяцев назад

    Actually most of the time it won't work on the email parameter

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      its not in email parameter its in username

    • @baravind719
      @baravind719 5 месяцев назад

      @@lostsecc yes in username too

  • @neo_the_chosen_one777
    @neo_the_chosen_one777 4 месяца назад

    i was almost doing shit....ethical shit ofcourse.....

  • @egg.egg.egg.egg.
    @egg.egg.egg.egg. 5 месяцев назад

    u earned a new sub! could you provide me the html file u put on the username tab please?

  • @neo_the_chosen_one777
    @neo_the_chosen_one777 4 месяца назад

    hi bro ,hope everything is ok ,the png tree website is yours?

    • @lostsecc
      @lostsecc  4 месяца назад +1

      no

    • @neo_the_chosen_one777
      @neo_the_chosen_one777 4 месяца назад

      @@lostsecc fuck your are a master code like me......thanks for your fast response....

    • @neo_the_chosen_one777
      @neo_the_chosen_one777 4 месяца назад

      @@lostsecc im starting my run on bug bounty...

    • @neo_the_chosen_one777
      @neo_the_chosen_one777 4 месяца назад

      @@lostsecc you are a master code like me...nice too meet you bro...

    • @lostsecc
      @lostsecc  4 месяца назад +1

      my pleasure bro 😇

  • @Realworlddummy
    @Realworlddummy 5 месяцев назад

    God loves you ❤

    • @lostsecc
      @lostsecc  5 месяцев назад

      love you three ☺️❤️

  • @playboicartihey
    @playboicartihey 5 месяцев назад

    dawg this is self xss nobody will see this on that url only you can see it

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      chain this with csrf

    • @playboicartihey
      @playboicartihey 5 месяцев назад

      @@lostsecc did u find a csrf?

  • @weebgaming1991
    @weebgaming1991 4 месяца назад

    Keep it up brother 🩶🩵

  • @user-ys6xt2zc6b
    @user-ys6xt2zc6b 5 месяцев назад

    self xss?

    • @lostsecc
      @lostsecc  5 месяцев назад

      chain it with csrf

    • @user-ys6xt2zc6b
      @user-ys6xt2zc6b 5 месяцев назад

      @@lostsecc not very serious though

  • @0xbr0d
    @0xbr0d 5 месяцев назад

    cool cool, where can i find this ?😅, and how do i sub again

    • @lostsecc
      @lostsecc  5 месяцев назад

      just msg me in telegram @lostsec ,☺️and for sub again click subscribe button three times 😉

    • @0xbr0d
      @0xbr0d 5 месяцев назад

      @@lostsecc just did

  • @aftabsaifi2436
    @aftabsaifi2436 5 месяцев назад

    Payload?

    • @lostsecc
      @lostsecc  5 месяцев назад

      join telegram @lostsec

  • @apple_00
    @apple_00 5 месяцев назад

    Good

  • @amith69699
    @amith69699 4 месяца назад

    @Lostsec can you explain what does that xss.report site reveal ?? please!

    • @lostsecc
      @lostsecc  4 месяца назад

      its reveal cookie inernal ip addrws local cache storage dom etc

  • @mr-dark
    @mr-dark 5 месяцев назад

    good 🔥🔥

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️😇

  • @unknownboi9084
    @unknownboi9084 5 месяцев назад

    I wish i could earn someday and help my parents 😭😭

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      sure just keep patience and hardwork ❤️

    • @unknownboi9084
      @unknownboi9084 5 месяцев назад

      @@lostsecc you got another sub. 🗿

  • @Mr.G3nt3lm4n
    @Mr.G3nt3lm4n 5 месяцев назад

    🔥🔥🔥

  • @itzxdark
    @itzxdark 5 месяцев назад

    tutorial plz

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      its a tutorial bro 🌝

    • @itzxdark
      @itzxdark 5 месяцев назад

      @@lostseccok

  • @Hunter-0x01
    @Hunter-0x01 5 месяцев назад

    name All extension ?

    • @lostsecc
      @lostsecc  5 месяцев назад

      join telegram i will post there with link @lostsec

    • @Hunter-0x01
      @Hunter-0x01 5 месяцев назад

      Ok ♥️

  • @Supp772
    @Supp772 5 месяцев назад

    ❤❤❤

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️😇

  • @baraamansi7637
    @baraamansi7637 5 месяцев назад

    bro this is self xss not blind

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      its stored you can use cookie stealing script and when victim click on your profile there cookie will be stolen by you..

    • @baraamansi7637
      @baraamansi7637 5 месяцев назад

      When victim visits the url he will get redirected to his own account , Unless attacker account isn't public or his username isn't shown in the admin dashboard , this doesn't considered a bxss

    • @lostsecc
      @lostsecc  5 месяцев назад

      you can chain this with csrf to xss and send to victim it will work..

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      its not get based xss in url parameter its post based stored xss

    • @baraamansi7637
      @baraamansi7637 5 месяцев назад

      ​@@lostsecc the attack vector is that you will enforce victim to create account with your controlled email and then extract the cookies , okay this is possible but what is the impact since this isn't victim's primary account , So you basically extracting cookies from a dummy account you made . The best way to exploit would be to find cache poisoning vulnerability . Nice find btw

  • @vikas340
    @vikas340 5 месяцев назад

    Brother CORS exploit code send kr do ab to

    • @lostsecc
      @lostsecc  5 месяцев назад

      msg me in telegram @lostsec

    • @vikas340
      @vikas340 5 месяцев назад

      @@lostsecc brother already joined your telegram

    • @vikas340
      @vikas340 5 месяцев назад

      @@lostsecc please send brother 🥹

    • @vikas340
      @vikas340 5 месяцев назад

      @@lostsecc yesterday we already talked but you say i upload in group but still not uploaded yet brother

    • @lostsecc
      @lostsecc  5 месяцев назад

      send again bro i am sending...there are many messges so sorry for that just msg me once

  • @FakePzZang
    @FakePzZang 5 месяцев назад

    u need to join fbi

  • @H4ckerNafeed
    @H4ckerNafeed 5 месяцев назад

    Can u upload how to make hacked by coffin template?

    • @lostsecc
      @lostsecc  5 месяцев назад

      i.will send code

  • @Bl00dyRobin
    @Bl00dyRobin 4 месяца назад

    HackerOne, BugCrowd, YesWeHack ?
    Are you paid on what platform?

  • @DandelionsCops
    @DandelionsCops 5 месяцев назад

    bro i dmed you in tele

    • @lostsecc
      @lostsecc  5 месяцев назад

      i check bro