i made custom tool for finding BlindSqli in bug bounty programs

Поделиться
HTML-код
  • Опубликовано: 26 окт 2024

Комментарии • 238

  • @lostsecc
    @lostsecc  2 месяца назад +19

    play at 1.25x speed ❤ for tool dm me in telegram channel t.me/lostsec

    • @egg144p
      @egg144p 2 месяца назад +1

      how can we access the tool?

    • @lostsecc
      @lostsecc  2 месяца назад +1

      i shared in telegram

    • @Earnnewskills
      @Earnnewskills 2 месяца назад

      @@egg144p yes

    • @totekingpadi
      @totekingpadi 2 месяца назад

      @@lostsecccan you share lostsec.jar again pls ?

    • @Kperogi
      @Kperogi 2 месяца назад

      No way to DM boss and I wanna talk to you

  • @AkashPatel-zd4wf
    @AkashPatel-zd4wf 2 месяца назад +22

    the only yt channel where there is no clickbait content on bug bounty. straight to point .

  • @andgoedu
    @andgoedu 2 месяца назад +6

    I more of a web pen tester , but i still come here every now and then and i do agree that this channel is awesome.

    • @lostsecc
      @lostsecc  2 месяца назад +1

      ❤️😇🤗

  • @Bullist
    @Bullist 2 месяца назад +1

    Dude this guy is actually so helpful. I don’t do pentesting, I work in helping antivirus detect malware, etc. but this is just so cool. Also, we both have a hacking setup with GTA V lmao 😂😂

  • @nonidentified89
    @nonidentified89 2 месяца назад +4

    Bro keep doing it we are with you always 💯 ❤.
    Dont worry of haters we will see them 💪❤️

    • @lostsecc
      @lostsecc  2 месяца назад +1

      ❤️🤗😇love u

    • @nonidentified89
      @nonidentified89 2 месяца назад +1

      @@lostsecc love u too brother 🫂

  • @itumelengmajoro9049
    @itumelengmajoro9049 2 месяца назад +2

    With proper Internet you get lots of positive results, but with lacking internet you get lots of false positive, I can't wait for exploatations, great tool bro, one of the best 💯😎 shout out to Lostsec 🎉🎉🏆

  • @RajatSharma_1111
    @RajatSharma_1111 2 месяца назад +1

    I am using your blindsql tool. This tool is really great but I have seen that for few of the targets, it shows that domain is vulnerable but when I check manualy, its actually blocked by cloudflare WAF. How can I proceed?

    • @lostsecc
      @lostsecc  2 месяца назад

      you need to bypass waf i shared the extensions and methodlogy to bypass

    • @RajatSharma_1111
      @RajatSharma_1111 2 месяца назад

      @@lostsecc where? In telegram channel?

    • @Meshv_patel
      @Meshv_patel 2 месяца назад

      ​@@lostsecc Hey, can you share it again plz how to bypass waf?..
      And when I copy website to browse is blocked. May is there old data from waybackurl ? So may be url removed so we can't access...?
      Actually I got lot of SQL found when I open almost all blocked?..
      How we can change url is valid or old version?

  • @milapshah582
    @milapshah582 2 месяца назад +1

    First of all, great video! I have a question: If I find a vulnerable SQL injection URL using a tool but it is blocked by a CDN or Cloudflare, how can I bypass that?

    • @lostsecc
      @lostsecc  2 месяца назад +1

      you need to try some tampers and use proxychains

  • @itsnot200
    @itsnot200 2 месяца назад

    Great video I would say without a doubt u r the best when it comes to teaching things!

  • @CyberSecHemmars
    @CyberSecHemmars 2 месяца назад +1

    Honestly, I love your content.
    I dont know if it is zsh you're using but I love your terminal look, kindly make a tutorial video on how to replicate it. Thank you.
    Please, great work bro.

  • @moin_256
    @moin_256 2 месяца назад

    Your video quality and content quality both are amazing!

  • @harze6818
    @harze6818 2 месяца назад

    I love this , but im afraid someone’s reports or something , you make every video legit I love you man.. please update if something gets detected etc ❤❤

    • @lostsecc
      @lostsecc  2 месяца назад +1

      sure ❤️

  • @Rudrakshacker
    @Rudrakshacker 2 месяца назад

    You are an inspiration ❤. Idk if you know me. But I am pretty active on x. Group chat I remember your reply once about the data leak that I found.. you really have an out of the box perspective. That's what inspires me 🙌

    • @lostsecc
      @lostsecc  2 месяца назад

      my pleasure brother happy to see this ❤️😇

  • @mhm2217hunter
    @mhm2217hunter 2 месяца назад +1

    what is NS takeover please shortly explain it sir😓

  • @kalooda99
    @kalooda99 2 месяца назад

    Bro , what is the difference between paramdpider and katana ???
    Tow for parameters ,is't it?

    • @lostsecc
      @lostsecc  2 месяца назад +2

      paramspider is passive crawler and katana is active & passive both

    • @kalooda99
      @kalooda99 2 месяца назад

      @@lostsecc thanks

  • @masoud603
    @masoud603 2 месяца назад

    cool tool. did you test it on BBP programs? most of payloads blocked by WAF or sanitization on BBP programs.

    • @lostsecc
      @lostsecc  2 месяца назад +3

      no i added benchmark payload also that bypass waf

  • @x0n1_1
    @x0n1_1 2 месяца назад

    hey bro your level of craft with web application hacking is pretty good. Most of the time, where do you hear about the tools you use?

    • @lostsecc
      @lostsecc  2 месяца назад +1

      self explore all

  • @Coollinux-c2b
    @Coollinux-c2b 22 дня назад

    bro you said you wanna make our own forum, have you got the name of the forum? what is that

  • @alberteinstein1325
    @alberteinstein1325 2 месяца назад +1

    bro when terminal customisation video?
    luv u

    • @lostsecc
      @lostsecc  2 месяца назад +1

      soon..

    • @alberteinstein1325
      @alberteinstein1325 2 месяца назад +1

      @@lostsecc bro fast bro iam waiting

    • @IVIoney23
      @IVIoney23 2 месяца назад

      @@lostsecc are you just doing this in the CMD terminal?

  • @AnglerMascot
    @AnglerMascot 2 месяца назад

    You are a gem . Make more videos like this and take love❤‍🔥

  • @maryjanechukwuma9707
    @maryjanechukwuma9707 2 месяца назад

    Thanks for all the amazing videos that you have been making, thanks for the tools that you have shared for free I appreciate it. I don't mean to be selfish but I just want to remind you about the WAF bypass you said you will share

  • @alberteinstein1325
    @alberteinstein1325 2 месяца назад

    how we want ur terminal custommisaation video so far 1 month iam asking u to put the video ur not taking any steps to put ... bro want happend to u ?

  • @Meshv_patel
    @Meshv_patel 2 месяца назад +1

    @lostsecc Hey, can you share it again plz how to bypass waf?..
    And when I copy website to browse is blocked. May be is there old data from waybackurl ? So may be url removed so we can't access...?
    Actually I got lot of SQL found when I open almost all blocked?..
    How we can change url is valid or old version?

    • @lostsecc
      @lostsecc  2 месяца назад +1

      first run all links through httpx and then try

    • @Meshv_patel
      @Meshv_patel 2 месяца назад

      @@lostsecc ok can I dm you?..

  • @L7N-b9b
    @L7N-b9b 2 месяца назад

    What distro are you using, friend?

  • @aatankbadboy3941
    @aatankbadboy3941 2 месяца назад

    Bro in real life hunt on real target and find sqli with this tool because then we got real feedback.....🎉❤

  • @Thestonez-vg2lp
    @Thestonez-vg2lp 2 месяца назад +1

    bro your music taste are just like me 🤣

  • @kenyan_hacker
    @kenyan_hacker 2 месяца назад

    Bro always hits target and make it look simple

  • @0xkirti
    @0xkirti 2 месяца назад

    Gonna add this tool on my project list and i will say to the company that i made this custom tool for sqli vulnerability finding 😂😊❤

  • @Sidharthas89
    @Sidharthas89 2 месяца назад

    Hey brother❤❤❤
    How much time have you spend on for making this tool.

    • @lostsecc
      @lostsecc  2 месяца назад

      very less time but will add some more things to make this tool effective

  • @Anirudh11
    @Anirudh11 2 месяца назад

    Hello Brother,
    I have been following you on youtube since long time, could you help me with the XSS automation?? i know the tools but couldn't figure out how to find it.
    Could you send me the steps to find it?? It would be great if you help me, Thank you

    • @lostsecc
      @lostsecc  2 месяца назад

      i am planing to make video on this.

  • @MustafaGains
    @MustafaGains 2 месяца назад

    Well the question is who gives u the permission to test these web applications?

    • @lostsecc
      @lostsecc  2 месяца назад

      Joe Biden

    • @MustafaGains
      @MustafaGains 2 месяца назад

      @@lostsecc ohh really damn you are impressive!!!!!

  • @An0nyw0us
    @An0nyw0us 2 месяца назад

    BRo first comment
    when would your github return??

    • @lostsecc
      @lostsecc  2 месяца назад

      maybe soon or i will make new ❤️

  • @AnirudhMadhuK-eb9bv
    @AnirudhMadhuK-eb9bv Месяц назад

    Sir, how to get your Bsqli tool?

  • @Sec_14
    @Sec_14 2 месяца назад

    Bro make a video about manul & automation + wafbypass Sqli methods

  • @potatogoal
    @potatogoal 2 месяца назад

    I love this channel staying up to date

    • @lostsecc
      @lostsecc  2 месяца назад +1

      ❤️🤗

  • @kapilrawat3848
    @kapilrawat3848 2 месяца назад +2

    Can you upload your tool on other site so i can download it

    • @lostsecc
      @lostsecc  2 месяца назад +2

      sure just little change and upload in new github acc

  • @phantomsecurity1
    @phantomsecurity1 2 месяца назад

    How can i contact to you?

  • @ashishchauhan9745
    @ashishchauhan9745 2 месяца назад

    bro copyright ki problem nahi hoti backgroud music se

  • @ClipZmovie7
    @ClipZmovie7 2 месяца назад

    bro how to make poc like can i record sqlmap or ghuri poc to reporting like SQL map find db

    • @lostsecc
      @lostsecc  2 месяца назад +1

      no just show them command and db screenshot

    • @ClipZmovie7
      @ClipZmovie7 2 месяца назад +1

      bro i never report sqli.is company allowed to use tools for poc like SQL map or ghauri because i see on bug hunting programs like automated tools output not allowed any experience? please share. I learned a lot from you and i got my first bounty of 200$ because of you.

  • @madhavanrio3210
    @madhavanrio3210 2 месяца назад

    sir when you upload for xss i am eagrly waiting for that

    • @lostsecc
      @lostsecc  2 месяца назад

      soon

    • @madhavanrio3210
      @madhavanrio3210 2 месяца назад

      @@lostsecc thank God, because I stucked on xss matrix so only ,
      And I recently noticed in that field you should be careful to bypass it , because you try all xss in this it's won't work without initial this payload

    • @madhavanrio3210
      @madhavanrio3210 2 месяца назад

      ruclips.net/user/shorts2KJ5wJfpqn4
      Refer This short it only 30 sec
      About textarea.

  • @NS-yj8fx
    @NS-yj8fx 2 месяца назад

    noop qesution how are u using kali terminal like this on windows I want to do the same set up I'm sick of vmware

    • @lostsecc
      @lostsecc  2 месяца назад

      install wsl2 and window terminal & kali from microsoft store

    • @NS-yj8fx
      @NS-yj8fx 2 месяца назад

      @@lostsecc you're best thank you so much

  • @dineshyaramala6973
    @dineshyaramala6973 2 месяца назад

    can you share resources how code like you no one can understand my code

  • @-Engineering01-
    @-Engineering01- 2 месяца назад

    Hi bro, your terminal bg is awesome could you share it ?

    • @lostsecc
      @lostsecc  2 месяца назад +1

      install wsl kali and ohmyposh themes

    • @-Engineering01-
      @-Engineering01- 2 месяца назад

      @@lostsecc I meant background image in your terminal, it's so good

    • @lostsecc
      @lostsecc  2 месяца назад

      dm me in telegram

  • @meghantashi
    @meghantashi 2 месяца назад

    Hey bro how do you find such .php based applications bug bounties ?

    • @lostsecc
      @lostsecc  2 месяца назад +1

      just use that oneliner that i showed in video

    • @meghantashi
      @meghantashi 2 месяца назад

      @@lostsecc Thanks, but most of the new BB comes with cloudfare protection isn't it ?

  • @mohmino4532
    @mohmino4532 2 месяца назад

    nice shot bro but with custom tamplet nuclei u can do the same

    • @lostsecc
      @lostsecc  2 месяца назад +1

      no that give false postive due to fast threads

    • @xynthewarrior
      @xynthewarrior 2 месяца назад

      @@lostsecc But your tool gives a lot of false positives too. Sometiems it says "Response time 10 seconds" then when you check, it loads instantly...

  • @ProGaming-fu6ht
    @ProGaming-fu6ht 2 месяца назад

    What is your type of device?

  • @TechSangam-x6m
    @TechSangam-x6m 2 месяца назад

    Bro can you suggest me bbp for idor and bac

    • @lostsecc
      @lostsecc  2 месяца назад

      pinterst

    • @TechSangam-x6m
      @TechSangam-x6m 2 месяца назад

      @@lostsecc don't you think there is too much competition ?

  • @mdlimonhosen5256
    @mdlimonhosen5256 2 месяца назад

    Yo, bro. I Like your video's most

  • @Filter_everything.123
    @Filter_everything.123 2 месяца назад

    Apna bhai on top ❤

  • @huzefaburhanuddin6334
    @huzefaburhanuddin6334 2 месяца назад

    You post million dollar content!!

  • @keizenberg
    @keizenberg 2 месяца назад

    Love your content bro !! Keep it up !!!

  • @belajarcoding547
    @belajarcoding547 2 месяца назад

    man ur BSQLI github not found :(

    • @lostsecc
      @lostsecc  2 месяца назад

      i shared in telegram

  • @arjuna902-
    @arjuna902- 2 месяца назад

    very helpful, thank you

  • @ramazkhan357
    @ramazkhan357 2 месяца назад

    kindly share the tool and thanks in advance

    • @lostsecc
      @lostsecc  2 месяца назад

      i shared in telegram channel link in pin comment

  • @zamzam_electronics_fanpage
    @zamzam_electronics_fanpage 2 месяца назад

    bro make a video on recon strategy

  • @HackAll-ue3sr
    @HackAll-ue3sr 2 месяца назад

    how to get the tool?please

    • @lostsecc
      @lostsecc  2 месяца назад +1

      i will share in telegram soon after some update

    • @HackAll-ue3sr
      @HackAll-ue3sr 2 месяца назад

      @@lostsecc thanks❤

  • @broomandmopmop
    @broomandmopmop 2 месяца назад

    good job buddy love to see the work

  • @spike666spike666
    @spike666spike666 2 месяца назад

    Your github channel gives a 404 error.

  • @clearnyahundi6331
    @clearnyahundi6331 2 месяца назад

    my bro did it again ❤

  • @Sidharthas89
    @Sidharthas89 2 месяца назад

    How to exploit with ghauri or sqlmap❤❤
    Thanks for video.

    • @lostsecc
      @lostsecc  2 месяца назад

      comming in telegram ❤️

    • @Sidharthas89
      @Sidharthas89 2 месяца назад

      @@lostsecc expected date

  • @belajarcoding547
    @belajarcoding547 2 месяца назад

    man ur github BSQLI not found🙃

  • @studyrelaxwithme4564
    @studyrelaxwithme4564 2 месяца назад

    Nice. Github link?

  • @bharathkalyan3961
    @bharathkalyan3961 Месяц назад

    How to install it ?

  • @Kerleee_
    @Kerleee_ 2 месяца назад

    how do you get that cmd

  • @lofigirlparaguay
    @lofigirlparaguay 2 месяца назад

    i love your wallpaper XD

  • @shuvokumarsaha8478
    @shuvokumarsaha8478 2 месяца назад

    Where is your tool

  • @exploitable0x1
    @exploitable0x1 2 месяца назад

    And sad bro your github got ban because of mass report..

    • @lostsecc
      @lostsecc  2 месяца назад +2

      no problem bro i will not stop ❤️

  • @MohiUddin_Shakil
    @MohiUddin_Shakil 2 месяца назад

    great video, my brother.

  • @niketpopat
    @niketpopat 2 месяца назад

    Tool Github link ??

  • @maryjanechukwuma9707
    @maryjanechukwuma9707 2 месяца назад

    bro I'm still waiting

  • @isaac-a1869
    @isaac-a1869 2 месяца назад

    Queria eu ter esse conhecimento 😔

  • @praveenb7249
    @praveenb7249 2 месяца назад

    thank you brother

  • @the_py_coder
    @the_py_coder 2 месяца назад

    Video successfully downloaded ❤

  • @Vulnerability_Vortex
    @Vulnerability_Vortex 2 месяца назад

    Nice video keep it up😍

  • @Earnnewskills
    @Earnnewskills 2 месяца назад

    tool downlod link

    • @lostsecc
      @lostsecc  2 месяца назад

      i send in telegram

  • @saptakdas9874
    @saptakdas9874 2 месяца назад

    But bro i think your github has been mass reported :(

  • @mirpurpigeons1777
    @mirpurpigeons1777 2 месяца назад

    Pls create a powerful xss tool❤❤❤❤

  • @Rootkit-n
    @Rootkit-n 2 месяца назад

    404 pls fixed it bro😢

  • @exploitable0x1
    @exploitable0x1 2 месяца назад

    Finally.......🎉🎉🎉

    • @lostsecc
      @lostsecc  2 месяца назад +1

      🤗❤️

  • @kanuemeka
    @kanuemeka 2 месяца назад

    Github blocked your account

    • @lostsecc
      @lostsecc  2 месяца назад

      check new acc

  • @egg144p
    @egg144p 2 месяца назад

    amazing tool 👏👏👏👏👏

  • @xynthewarrior
    @xynthewarrior 2 месяца назад

    A lot of false positives sadly

    • @lostsecc
      @lostsecc  2 месяца назад

      use active urls that not give redirect

  • @RajanChoudhary12
    @RajanChoudhary12 2 месяца назад

    What is your id on MC5?

  • @huncking
    @huncking 2 месяца назад

    Now is it possible to scan ip containing a login field like python3 lostsec 127.204.2.79:5005

    • @lostsecc
      @lostsecc  2 месяца назад +1

      no you need endpoint to test

  • @F0rc3Tv
    @F0rc3Tv 2 месяца назад

    sqlmap is also good ❤

  • @ManhRTX
    @ManhRTX 2 месяца назад

    phonk hacker

  • @pedrolosmios
    @pedrolosmios 2 месяца назад

    Yea 🎉❤

    • @lostsecc
      @lostsecc  2 месяца назад +1

      ❤️😇

  • @antoniosebastian6590
    @antoniosebastian6590 2 месяца назад

    Legend

  • @pedrolosmios
    @pedrolosmios 2 месяца назад

    Bravo 🎉❤😊

  • @ALLInclusiveCollection-hy3dd
    @ALLInclusiveCollection-hy3dd 2 месяца назад +2

    Bro you are doing good but your tools give false positives most of the time

    • @lostsecc
      @lostsecc  2 месяца назад +2

      there are many reasons for that buggy dns or main redirect issue due to redirect there is delay so always check manully what the reason..

  • @LionelMessi-ex2fc
    @LionelMessi-ex2fc 2 месяца назад

    How i can find my first bug and find a program with bugs ?

    • @lostsecc
      @lostsecc  2 месяца назад

      hunt on some public responsible disclosure programs

  • @Rip_Real_World
    @Rip_Real_World 2 месяца назад

    King 🔥📈

  • @YettouYettou-uj9du
    @YettouYettou-uj9du 2 месяца назад +1

    Do not download this shit it not tool for sql its just tool to excute comand on ur system

    • @lostsecc
      @lostsecc  2 месяца назад

      😐alrday showed the profe in telegram go and check there

  • @RajanChoudhary12
    @RajanChoudhary12 2 месяца назад +1

    Bro have you played Modern combat 5?

    • @lostsecc
      @lostsecc  2 месяца назад +2

      ys

    • @RajanChoudhary12
      @RajanChoudhary12 2 месяца назад +2

      So your id was param right?

    • @RajanChoudhary12
      @RajanChoudhary12 2 месяца назад +2

      I was active player on that game and was addicted for 2 yrs. 😂

  • @jaysonjoy6467
    @jaysonjoy6467 2 месяца назад

    Hello lostsec, Today you said you want to hack Bangladesh Navy website. I'll request you not to do it. I'm from Bangladesh. If you want you should go for Bangladesh police Site. They killed lots of students today more than 200 hundreds just today.

    • @lostsecc
      @lostsecc  2 месяца назад +1

      i did'nt hack i just show i bypassed that and also i reported them ❤️

    • @jaysonjoy6467
      @jaysonjoy6467 2 месяца назад

      @@lostsecc Thank you brother. We are passing a critical situation. Only Allah can help us. We feel like Palestinian. Pray for our student brother. Our Bangladeshi hacker group are hacking govt. site to let them realise that govt should stop genocide.

  • @AbushadSiddiqui-w2n
    @AbushadSiddiqui-w2n 2 месяца назад

    Bro can you also give the method txt file ?🫠

    • @lostsecc
      @lostsecc  2 месяца назад

      which method i shared in telegram channel

  • @madhavanrio3210
    @madhavanrio3210 2 месяца назад

    in 0.57
    Sir you missed this :( for begginers its tough
    cat url.txt | grep FUZZ | gf xss | grep -iavE 'pdf|txt|\?l=FUZZ$|\?contry=FUZZ$|\?q=FUZZ$|is/image' > out_fuzz.txt

  • @huncking
    @huncking 2 месяца назад

    🎉🎉🎉🎉🎉🎉🎉❤🙏🏼🥷🏼⚰️🔥🔥🔥🔥🔥🔥🔥 awesome 💯

  • @pedrolosmios
    @pedrolosmios 2 месяца назад

    Yea 🎉❤