CRLF + XSS + cache poisoning = Access to Github private pages for $35k bounty

Поделиться
HTML-код
  • Опубликовано: 21 дек 2024

Комментарии • 22

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  3 года назад

    Hi! Welcome to the comment section! I hope you enjoyed the video!
    Get the first issue of BBRE newsletter: mailing.bugbountyexplained.com/news1
    You have time until Saturday 8th May to sign up if you want to receive the 2nd newsletter.

  • @ahmadshami5847
    @ahmadshami5847 3 года назад +16

    It's amazing how 2 high school students did all that! now those are some newborn legends

    • @TheKing-ul5pw
      @TheKing-ul5pw 3 года назад

      RUclips open redirection ruclips.net/video/aSS23VHAqbU/видео.html

  • @brijendarsingh3358
    @brijendarsingh3358 3 года назад

    Clear and concise explaination . thankyou for helping the community .

  • @-bubby9633
    @-bubby9633 3 года назад +3

    Another fantastic explanation, super concise and easy to understand as always! Thanks for working so hard to keep us update to date and informed. Noticing that little distinction in the source code between converting to int for accessing the page but not when setting the cookie val as a 14 and 17 year old is seriously impressive. Not to mention the cookie scoping bypasses afterwards. Pretty sure at that age I was nothing more than a dumb script kiddie pressing buttons on Havij 😂

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 года назад +4

      Thank you Andrew. If someone would tell me that guys in such age found a $35k bug, I would think it's maybe an IDOR, some business logic or something like that but Id never think a chain like this..

  • @imuser007
    @imuser007 3 года назад +2

    this is amazing man well explained

  • @estebanroman3258
    @estebanroman3258 3 года назад

    Holyyyy moly! This is huges! Thanks and this channel it's amazing!

  • @bugr33d0_hunter8
    @bugr33d0_hunter8 3 года назад +1

    You the man, i love your videos, and the time you put into them. I was always wondering when someone would, reverse engineer the bugs so we can see how they went about finding the bug, along with a proof of concept. I knew the young wipper snappers would rise up and make my job even harder, lol. I love that shirt, looks good on you. I go the gym as well, have to fill out my club shirts, hehe.

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 года назад +2

      Hahah thanks for the comment!
      I struggle now to find gym alternatives when they are closed but Im doing my best to keep my shirts pumped up!💪

    • @henrypowell3496
      @henrypowell3496 2 года назад

      so you understood the whole vid? you are genius, man

  • @0SPwn
    @0SPwn 3 года назад +1

    Crazy. I'm 14 and these guys are obviously doing some crazy stuff!

    • @sontapaa11jokulainen94
      @sontapaa11jokulainen94 3 года назад

      I wish you a happy journey into cyber security!

    • @0SPwn
      @0SPwn 3 года назад +1

      @@sontapaa11jokulainen94 Thank you, you too.

  • @blablablabla29382
    @blablablabla29382 3 года назад +1

    Success unlocked: pay back the bank for all school years.

  • @dojoku88
    @dojoku88 3 года назад

    wow That’s awesome,,

  • @cybersecurity3523
    @cybersecurity3523 3 года назад

    Good bro

  • @machinexa1
    @machinexa1 3 года назад

    😊👌

  • @toriyono8018
    @toriyono8018 3 года назад

    First 🥇