$1700 Bounty | Unauthenticated Command Injection Vulnerability | Bug Bounty Methodology | POC

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024
  • -----------------------------------------------------------------------
    Twitter: / abhishekmorla
    Website: abhishekmorla....
    Linkedin: / abhishekmorla
    ------------------------------------------------------------------------
    reference :
    github.com/swi...
    / command-injection-bypa...
    ⚠️ Disclaimer: This content is solely for educational purposes and should not be used for unauthorized activities. Always obtain proper authorization before performing any security testing.

Комментарии • 27

  • @user-yr6uj4gv5m
    @user-yr6uj4gv5m 7 месяцев назад +17

    It would be great if you could make a video explaining how you found the bug from the beginning to the end :)

    • @lmaoo254
      @lmaoo254 6 месяцев назад +3

      It's a htb box, named paper, search it up if you want to know how he found the bug. Also you don't get paid ($1700) for solving a htb box

    • @Noctuu
      @Noctuu 5 месяцев назад

      @@lmaoo254why’d he put 1700$ bug bounty in the title then

    • @tomdotsh
      @tomdotsh 5 месяцев назад

      I've seen plenty of people do THM / HTB rooms and claim it to be a pirvate program and get paid from it@@Noctuu

  • @shainshashaik1473
    @shainshashaik1473 7 месяцев назад +1

    Thank you for showing trail and error .. with your video.. i got remote shell .. thanks a lot ❤❤

  • @shuvokumarsaha8478
    @shuvokumarsaha8478 7 месяцев назад +2

    It would be great if you could make a video explaining how you found the bug from the beginning to the end :) 2

  • @dittonachan
    @dittonachan 7 месяцев назад +2

    great bro, learning alot from you, do you have any blog or writeups, I want to start hunting too

    • @abhishekmorla1
      @abhishekmorla1  7 месяцев назад +4

      Search my name you will get some medium writeups

  • @__pain__05
    @__pain__05 7 месяцев назад +1

    can you make a video for recon????

  • @shreemadav9596
    @shreemadav9596 7 месяцев назад

    Great find 💯💪

  • @user-xo4rr5en3e
    @user-xo4rr5en3e 7 месяцев назад

    omg, so cool

  • @playmorefunny2340
    @playmorefunny2340 7 месяцев назад

    this is crazy

  • @miteshvalvi1170
    @miteshvalvi1170 7 месяцев назад

    how you find cmd parameter

    • @abhishekmorla1
      @abhishekmorla1  7 месяцев назад +1

      Thats the recon part..you wont find in this video

  • @user-of9qp9ce4g
    @user-of9qp9ce4g 7 месяцев назад

    🎉🎉🎉🎉🎉

  • @Srocify
    @Srocify 7 месяцев назад

    what the target name ?

    • @abhishekmorla1
      @abhishekmorla1  7 месяцев назад +1

      private program

    • @Srocify
      @Srocify 7 месяцев назад

      keep going dude i hope i can be like you

    • @user-hb2rl4zn2m
      @user-hb2rl4zn2m 7 месяцев назад

      ​@@abhishekmorla1how did you came to know this this is this file uploaded to rce ? How you came to this post request

  • @jomynn
    @jomynn 7 месяцев назад

    How to report this bug?

    • @abhishekmorla1
      @abhishekmorla1  7 месяцев назад

      search for hackerone reports regarding same

  • @CyberTechwithNikhil
    @CyberTechwithNikhil 7 месяцев назад

    It's my suggestion bro, try to add some nice hackers songs music😅, to make and and watching experience better it's my suggestion just depend upon you.

    • @abhishekmorla1
      @abhishekmorla1  7 месяцев назад +1

      Yeah i dont have time for choosing songs bro..😅 but will start again by using some non copyright songs

    • @CyberTechwithNikhil
      @CyberTechwithNikhil 7 месяцев назад +1

      @@abhishekmorla1 ofcourse you can do that also