$25k GitHub account takeover & justCTF 2023 CSRF+XSS writeup

Поделиться
HTML-код
  • Опубликовано: 22 окт 2024

Комментарии • 18

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  4 месяца назад +1

    💻 Challenge yourself in 2024 justCTF online teaser: 2024.justctf.team
    Sponsored by:
    HexRays - get 20% off for IDA pro training sessions with exclusive code BBRE20: bbre.dev/hexrays
    Trail of Bits: cutt.ly/veucZatb
    OtterSec: cutt.ly/leucL7cz
    SECFORCE: cutt.ly/5eoKRyNL

  • @princewilliam7876
    @princewilliam7876 4 месяца назад +5

    Where I can learn more about namespace tokenizor and parser

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  4 месяца назад +4

      look for mutation xss. Articles by Michał Bentkowski are great. Also, recently in BBRE Premium I covered a talk about it

  • @Zizo8182
    @Zizo8182 4 месяца назад +1

    Thanks for sharing

  • @monKeman495
    @monKeman495 4 месяца назад +1

    is preflight request with strict referer or sop policy before post or put request can thwart the payload ?

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  4 месяца назад +1

      thwart?

    • @monKeman495
      @monKeman495 4 месяца назад

      @@BugBountyReportsExplained sorry it's stop , in my case program use put method for adding information to account but put method block the cors request .so i tried using __method=get and some other tricks like using in with origin set with src but no luck

  • @eduardopereira2718
    @eduardopereira2718 2 месяца назад

    really cool video. thanks

  • @Username8281
    @Username8281 4 месяца назад +6

    Amazing channel. Does anyone know any similar channels?

  • @PhilocyberWithRichie
    @PhilocyberWithRichie 4 месяца назад

    No fucking way you have a Mate behind you!! hahaha you are great dude! Good video thanks for sharing!

  • @steiner254
    @steiner254 4 месяца назад

    nice!

  • @Quantum_Playz78
    @Quantum_Playz78 4 месяца назад

    2nd view × 2nd comment × 2nd liked = 1 subscriber. Fact I already subscribed your channel more than a year.

    • @zzzzzzzzZzZZzzzaZzz
      @zzzzzzzzZzZZzzzaZzz 4 месяца назад

      Thanks for your report and efforts. Unfortunately, the vulnerability has already been reported and thus your report will be marked as duplicate

    • @ediopaul0
      @ediopaul0 12 дней назад

      @@zzzzzzzzZzZZzzzaZzz LOL

  • @0xshahriar
    @0xshahriar 4 месяца назад

    1st view + 1st comment

    • @data_eng_tuts
      @data_eng_tuts 4 месяца назад

      Yeah, bug bounty hunting is shit !