Broken Access Control | Complete Guide

Поделиться
HTML-код
  • Опубликовано: 2 окт 2024

Комментарии • 57

  • @RanaKhalil101
    @RanaKhalil101  Год назад +7

    📚📚 Don't want to wait for the weekly release schedule to gain access to all the videos and want to be added to a discord server where you can ask questions? Make sure to sign up to my course: bit.ly/30LWAtE

  • @Stephanus21
    @Stephanus21 Год назад +16

    I know about you for a while now, just started with your videos , but I have to say you are one amazing teacher. Your soft voice and deep knowledge of the subject makes it a lot easier for me. Thank you so much. I will definitely buy your courses.

  • @MFoster392
    @MFoster392 Год назад +4

    I love your videos they're so helpful :)

  • @MrBlackhats
    @MrBlackhats Год назад

    yes make plz a bonus video about this topic!! thanks

  • @LeenPh
    @LeenPh 10 месяцев назад +2

    This is gold!
    I've understood many concepts and solved 40+ labs on the academy website, thanks to your content.
    I think I won't miss any single video on this channel!
    Wish you all the best ❤❤❤

  • @css2165
    @css2165 Год назад

    great video. will you upload ctf examples?

  • @shayansec
    @shayansec Год назад

    Great vid...Just revised this vuln.

  • @gaelslv2068
    @gaelslv2068 3 месяца назад

    عربيه واضح من الصوت

  • @1990shahid
    @1990shahid Год назад +2

    Thank you for the work you've put into making this 🙏🏾

  • @suyunovjasurbek
    @suyunovjasurbek 6 месяцев назад

    i like you'r vedios. thanks Mrs

  • @lifeofsq5653
    @lifeofsq5653 Год назад

    Hi Rana, Want to see how you are using Autorize in burpsuite to check for access contorl bypass

  • @Aquax1000
    @Aquax1000 8 дней назад

    Do something with your voice

  • @CRYSTAL-fd4fw
    @CRYSTAL-fd4fw 8 месяцев назад

    Mashalla sesiter

  • @sayantandatta2996
    @sayantandatta2996 Год назад

    Kindly update theic or speak louder please

  • @sakura-gd8nh
    @sakura-gd8nh 4 месяца назад

    Where can I use the lab is it free?????

  • @mohmino4532
    @mohmino4532 10 месяцев назад

    in fact is that I find it difficult to understand everything cuz my English skills are not perfect, but I do my best, and u still the number one to me tho .. so thx so much ma teacher تحية اليك من الجزائر .

  • @nibrasmuhammed5105
    @nibrasmuhammed5105 Год назад +1

    @rana khalil. 19:58 on this video, it is not vulnerable at all. I will tell the implementations. 1) Every request comes through a middleware which checks the jwt. if the jwt is altered, they will never get this function. since we are getting the id from jwt, we can ensure that the request comes from the owner of the the account. if someone altered id field of jwt, middleware return the request. hope you get it.

    • @kit4unez
      @kit4unez Год назад +2

      No. How does authentication middleware prevents attacker to exploit this piece of code? Even if I am authenticated as user1 and order with id 2 (for example) was created by user2, I still can make a DELETE request to /orders/2/ and delete that order, because there was no access control in that piece of code

    • @nibrasmuhammed5105
      @nibrasmuhammed5105 Год назад

      @@kit4unez talking about IDOR?

    • @richardIambert
      @richardIambert Месяц назад

      I think the purpose of the code review was to get people thinking about some of the ways in which broken auth vulnerabilites can be introduced into an app. Later in the video (~30:00), Rana explains that the vulnerability introduced by this code could be mitigated by performing access control checks elsewhere in the application, which checking the contents and integrity of a JWT in middleware would be an example of.

  • @gangsternerd8419
    @gangsternerd8419 Год назад +1

    Nobody teach as good as you, you make this thing easy to learn thanks Rhana❤

  • @sintayehutsegayeworku1855
    @sintayehutsegayeworku1855 Год назад

    Am totally new for IT field, am accountant in the banking industry. But now am learning computer science to be a hacker. I first see you in "David Bombal" RUclips channel interview and now am your follower.
    Thank You for Doing This (I really want to buy your course but I can't I am in Ethiopia.

  • @kanimani8226
    @kanimani8226 Год назад

    Rana I love your content
    hope you all best
    What about the OSWE , and your progress ?
    Have you size it ?

  • @ctc8998
    @ctc8998 7 месяцев назад

    bring back cortex

  • @snowden-IT
    @snowden-IT Год назад

    يعجبني حماسك والمثابرة شكرا على هذا الشرح

  • @tnt7298
    @tnt7298 Год назад

    Could u upload whole videos which comes under "Access Control vulnerabilities"?

  • @rolamahmoud9678
    @rolamahmoud9678 Год назад

    يعطيكي العافية انسة رنا يا ريت تعملي فيديوهات بالعربي وشكرا

  • @riteshasthana7824
    @riteshasthana7824 8 месяцев назад

    Thank you mam for such informative videos

  • @TheBlackmanIsGod
    @TheBlackmanIsGod Год назад

    So access control is like permissions????

  • @noorrehman6344
    @noorrehman6344 Год назад

    Please make web hacking course for udemy

  • @xbaleks4609
    @xbaleks4609 Год назад

    Chokrane Bzaff !
    Thank You so much !

  • @hdammotowa9695
    @hdammotowa9695 Год назад

    This is my first video, I understood everything and I can't wait for the practical explanation شكرا

  • @AamirAr-b2n
    @AamirAr-b2n Год назад

    Great job, Thank you from 🇵🇰

  • @ahmedmouad344
    @ahmedmouad344 Год назад

    Finally Ur back again and on time cause i finish my finals soon 🥰

  • @Davidgonzalez-tp4ew
    @Davidgonzalez-tp4ew Год назад

    La explicación es muy clara, excelente video 🌄🌠😉🇨🇴🇨🇴

  • @rahulgogra7089
    @rahulgogra7089 Год назад

    please make a video on the extension.🙏

  • @saadeddine6418
    @saadeddine6418 Год назад

    think you sister you the best

  • @Donut-qt9mr
    @Donut-qt9mr Год назад

    thanksyou for the valueable content

  • @Shintowel
    @Shintowel Год назад

    Love u sister please how to use autorize

  • @Ahmed-s3d5u
    @Ahmed-s3d5u Месяц назад

    thank you for course ❤❤❤

  • @gajendraupadhyay6740
    @gajendraupadhyay6740 Год назад

    Its really good...👍👍keep it up..

  • @omarkalom1962
    @omarkalom1962 Год назад

    Thanks from 🇮🇱✌️

  • @maakthon5551
    @maakthon5551 Год назад

    Simple and forward , Thanks!

  • @sintayehutsegayeworku1855
    @sintayehutsegayeworku1855 Год назад

    Thank You for doing this

  • @chowdhurytowhidahmed7780
    @chowdhurytowhidahmed7780 Год назад

    Love from by heart

  • @brudora3096
    @brudora3096 Год назад

    Thanks those videos ❤❤

  • @mohamedmahrous9500
    @mohamedmahrous9500 Год назад

    thank you ❤❤

  • @FaultyGlitch
    @FaultyGlitch Год назад

    Thank you

  • @amin_alaa
    @amin_alaa Год назад

    thanks

  • @balasubramaniamgopal8437
    @balasubramaniamgopal8437 Год назад

    Brilliant !!

  • @paulojr1384
    @paulojr1384 Год назад

    Thank you Hana

  • @css2165
    @css2165 Год назад

    perfection

  • @Axel-rs3cg
    @Axel-rs3cg Год назад

    really well explained ✌🏽

  • @Love-yv1fc
    @Love-yv1fc Год назад

    Thank you❤

  • @TheCyberWarriorGuy
    @TheCyberWarriorGuy Год назад

    :)

  • @Matinirx
    @Matinirx Год назад

    🤘🏻👌

  • @Omar0x_7
    @Omar0x_7 9 месяцев назад

    يا لو الشرح ده بالعربي