Web Application Hacking - File Upload Attacks Explained

Поделиться
HTML-код
  • Опубликовано: 5 июл 2024
  • 00:00 Intro
    00:40 File uploads primer
    03:33 Lab 1: Popcorn
    08:59 Chaining vulnerabilities
    10:02 Path traversal
    16:55 Outro
    Pentests & Security Consulting: tcm-sec.com
    Get Trained: academy.tcm-sec.com
    Get Certified: certifications.tcm-sec.com
    Merch: merch.tcm-sec.com
    Sponsorship Inquiries: info@thecybermentor.com
    📱Social Media📱
    ___________________________________________
    Twitter: / thecybermentor
    Twitch: / thecybermentor
    Instagram: / thecybermentor
    LinkedIn: / heathadams
    TikTok: / thecybermentor
    Discord: / discord
    💸Donate💸
    ___________________________________________
    Like the channel? Please consider supporting me on Patreon:
    / thecybermentor
    Support the stream (one-time): streamlabs.com/thecybermentor
    Hacker Books:
    Penetration Testing: A Hands-On Introduction to Hacking: amzn.to/31GN7iX
    The Hacker Playbook 3: amzn.to/34XkIY2
    Hacking: The Art of Exploitation: amzn.to/2VchDyL
    The Web Application Hacker's Handbook: amzn.to/30Fj21S
    Real-World Bug Hunting: A Field Guide to Web Hacking: amzn.to/2V9srOe
    Social Engineering: The Science of Human Hacking: amzn.to/31HAmVx
    Linux Basics for Hackers: amzn.to/34WvcXP
    Python Crash Course, 2nd Edition: amzn.to/30gINu0
    Violent Python: amzn.to/2QoGoJn
    Black Hat Python: amzn.to/2V9GpQk
    My Build:
    lg 32gk850g-b 32" Gaming Monitor:amzn.to/30C0qzV
    darkFlash Phantom Black ATX Mid-Tower Case: amzn.to/30d1UW1
    EVGA 2080TI: amzn.to/30d2lj7
    MSI Z390 MotherBoard: amzn.to/30eu5TL
    Intel 9700K: amzn.to/2M7hM2p
    G.SKILL 32GB DDR4 RAM: amzn.to/2M638Zb
    Razer Nommo Chroma Speakers: amzn.to/30bWjiK
    Razer BlackWidow Chroma Keyboard: amzn.to/2V7A0or
    CORSAIR Pro RBG Gaming Mouse: amzn.to/30hvg4P
    Sennheiser RS 175 RF Wireless Headphones: amzn.to/31MOgpu
    My Recording Equipment:
    Panasonic G85 4K Camera: amzn.to/2Mk9vsf
    Logitech C922x Pro Webcam: amzn.to/2LIRxAp
    Aston Origin Microphone: amzn.to/2LFtNNE
    Rode VideoMicro: amzn.to/309yLKH
    Mackie PROFX8V2 Mixer: amzn.to/31HKOMB
    Elgato Cam Link 4K: amzn.to/2QlicYx
    Elgate Stream Deck: amzn.to/2OlchA5
    *We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.
  • НаукаНаука

Комментарии • 21

  • @CaptainTrashRat
    @CaptainTrashRat Год назад +48

    These videos are great, but could you knock up the volume by like 20%? Just a tad quiet, other than that, excellent stuff!

  • @Boolap1337
    @Boolap1337 Год назад +3

    This series is just getting better, keep it coming!

  • @ilbona87
    @ilbona87 Год назад +1

    Nice one, I'm loving this series!

  • @nightninja8128
    @nightninja8128 Год назад

    Another great lesson. Thanks, Alex!

  • @VectorGameStudio
    @VectorGameStudio Год назад +1

    The path traversal combined with upload attacks is new to me, i like it

  • @vijithpramod3348
    @vijithpramod3348 Год назад +2

    Great ❤ Thanks for the video..

  • @elmehdiezziar
    @elmehdiezziar Год назад +1

    Thanks for the information 🛡️

  • @ahmed_pinger
    @ahmed_pinger Год назад +1

    Awesome Video ♥️♥️♥️♥️

  • @videkrem
    @videkrem Год назад +2

    You guys are doing God's work. Thank you so much

  • @marcosgoncalves9768
    @marcosgoncalves9768 Год назад +1

    You guys rock.. I'm learning heaps with ur videos. How can I get an internship at TCM security ??? 👂👂👂👊👊👊

  • @karanbhutada950
    @karanbhutada950 Год назад

    would love to know more about Oauth Misconfiguration and HTTP request smuggling

  • @bukarbetoismail763
    @bukarbetoismail763 Год назад

    Good video very helpful

  • @gilles3366
    @gilles3366 Год назад +3

    I'm happy with the new web hacking oriented videos. my wish would be that there are more videos of this kind based on the top 10 owasp 2021. good luck for the rest

  • @andreic6250
    @andreic6250 Год назад

    Unfortunately the audio stream for this file is very very low I've tried it on the number of devices please when making a video boost your audio

  • @danishazizkhan6099
    @danishazizkhan6099 Год назад

    We want ssrf and csrf video

  • @howtodefeatgangstalking
    @howtodefeatgangstalking Год назад +1

    But in 99% of the cases. Even if you can upload a php shell for example. There is no way to navigate to the php shell upload via url to even execute it. In a real life senario with pretty much all websites these days. Your not going to be able to access the php upload to even execute it.

    • @1952JBoy
      @1952JBoy Год назад +1

      Depends on how the application has been designed. For example, if the app stores files in the application root (which they should not), then users will be able to access it

    • @thomasmarques2816
      @thomasmarques2816 Год назад +1

      @@1952JBoy it's rare nowadays, but yeah it's the way to exploit this

  • @mr.togrul--9383
    @mr.togrul--9383 Год назад

    nice username lol