Server-Side Request Forgery (SSRF) | Complete Guide

Поделиться
HTML-код
  • Опубликовано: 23 ноя 2024

Комментарии • 64

  • @davidlakomski3919
    @davidlakomski3919 2 года назад +42

    Just picking a random video from your channel to tell you that you're doing a marvelous teaching job! You managed to explain very complex topics in a very gentle and simple way, I hope I could one day reach a tenth of your teaching quality. Congratulations and thank you so much for your work

    • @RanaKhalil101
      @RanaKhalil101  2 года назад +10

      Thank you! I appreciate the kind words ❤

  • @tullacss
    @tullacss 10 месяцев назад

    I have watched a couple of videos, but I struggled to grasp the meaning of SSRF. However, after watching your video, I gained a much clearer understanding. Jazakallah khairan, sister Rana 🤲

  • @MAX-nv6yj
    @MAX-nv6yj Год назад +3

    أحبك في الله يا أختي والله سهلتي علي المعلومات بصورة جميلة وواضحة بارك الله فيك وجزاك الله كل خير على هذا الشرح الرائع والمتميز

  • @anjulgrover2114
    @anjulgrover2114 Год назад +2

    Great teacher and very well taught .... Explained very well.

  • @emrah2525
    @emrah2525 Год назад +2

    Thank you Rana ! I really appreciate your effort. These videos are really wonderful

  • @masicre9574
    @masicre9574 2 года назад +6

    Mam please upload more videos on client side and server side attacks....Your videos are much awaited...Please upload videos on XSS soon...waiting for that

  • @rongliao9255
    @rongliao9255 10 месяцев назад

    Look forward to more great tutorials! One of the best and comprehensive talks on this subject!

  • @ghinwabadawi983
    @ghinwabadawi983 8 месяцев назад

    cant stop watching your videos and learning! you make learning these complex subjects so easy! i just subscribed to your course to do more hands-on 😊😊

  • @NoobJang
    @NoobJang Год назад

    thx for the video, it really clarified my knowledge on SSRF.
    Thankyou so much for making this video, you are a great teacher.
    Consider making a patreon like the guy down below said.

  • @spsumon1298
    @spsumon1298 2 года назад +2

    Your videos are much awaited.Please upload videos continuously❤❤❤❤❤❤❤❤❤

  • @manbeats6702
    @manbeats6702 2 года назад +1

    Need Videos For Every Portswigger Labs Ur Videos are easily understandable

  • @muninitishkumaryaddala7814
    @muninitishkumaryaddala7814 Год назад +2

    Hi Ma'am. I follow your videos. The content is great in all your videos. In this video particularly, I felt that DNS rebinding could have been explained in a more clearer way as this is my first time encountering it. Just a feedback from my side. I hope this helps you in making your content better someway.

  • @zuberkariye2299
    @zuberkariye2299 3 года назад +2

    Amazing vid, shukran sis!

  • @alaaalmekdad9062
    @alaaalmekdad9062 Год назад

    great rana but i hope u can do this in arabic version for arab white hat hackers . im so glad to see u in youtube and i will support u cuz u deserve that , big thanks and i wait a lot from u ! ty

  • @PhilocyberWithRichie
    @PhilocyberWithRichie 2 года назад +1

    Great video and explanation Rana! thanks for sharing this high quality content!!!

  • @josephgitahi2090
    @josephgitahi2090 Год назад

    This is awesome just saw you on David Bombal and I can see why such a great tech name recommends you. Great work👍

  • @JohnSmith-wz7he
    @JohnSmith-wz7he 2 года назад +1

    Totally Awesome! Thank you !

  • @zTech300
    @zTech300 3 года назад +1

    Was waiting for this.

  • @dub161
    @dub161 9 месяцев назад

    Thanks for making this. Can you please change auto generated subtitles from Indonesian to English?

  • @nibeditadhani6149
    @nibeditadhani6149 2 года назад +1

    kindly share a video on XXE attack

  • @JuanBotes
    @JuanBotes 3 года назад +3

    thanks for the content

  • @Sec1515
    @Sec1515 2 года назад

    This is superb, thank you so much!!

  • @yassers1893
    @yassers1893 2 года назад +1

    Thank you, it is awesome… can you advice us about oscp certification?

  • @macleo7825
    @macleo7825 3 года назад +2

    Thanks for the video

  • @moustafaahmed5609
    @moustafaahmed5609 2 года назад +2

    can you change auto-generated subtitle in English instead Indonesian, please?

  • @Saw-o3h
    @Saw-o3h 2 года назад +1

    One of the most precise and well-organized videos I have ever seen. Unfortunately, I'm from Iran otherwise I would definitely get your course. is there any way I can get it?

  • @SecurityTalent
    @SecurityTalent 3 года назад +2

    Thanks sister....

  • @brunosm0
    @brunosm0 2 года назад +1

    thank you, gracias Rana

  • @uaebikers
    @uaebikers Год назад

    Theory is a torture😅
    Time for practical

  • @sawtintkyaw887
    @sawtintkyaw887 3 года назад +1

    Thank you so much.

  • @suresh_shankar
    @suresh_shankar Год назад

    good explanation

  • @howandwhythingswork
    @howandwhythingswork 2 года назад +1

    Thank you

  • @ex0day
    @ex0day 7 месяцев назад

    great job!!! you Rock!!

  • @SagrikaSoni
    @SagrikaSoni Месяц назад

    Thank u so much ❤

  • @Dy13yDx
    @Dy13yDx Год назад

    precious one

  • @ahmedramadan9550
    @ahmedramadan9550 9 месяцев назад

    thank youuuu

  • @SomLegends
    @SomLegends 2 года назад

    Rana SSRF lab 4-8 is hidden we can not wach it

  • @quyenthokimquang8682
    @quyenthokimquang8682 Год назад

    Hi madam, thank you for your great content, I have a question that at 07:47, you talked about clicking on add items or delete items is an external request that will be blocked by the firewall. I just wonder why that is the case? Thank you again because your videos are giving me a lot of useful knowledge.

    • @alexandreromao7978
      @alexandreromao7978 Год назад

      Hello Quyen.
      In the "real word", real work environments often block external ip addresses from accessing internal systems and its functionalities. Imagine a monitoring system functionality inside a network that requires no authentication, for disaster recovery purposes. As it represents a risk, it can only be accessed internally by administrators. As so, if you make a request to the service, you will get blocked (e.g. firewall). WIth SSRF, you are tricking the actual application to make that request to his own server, through the loopback network interface, and as so, it is not you requesting, but the vulnerable application hosted in the server. As it is allowed to access internally, you have access. The same with "Add Items".

  • @texashighered9539
    @texashighered9539 10 месяцев назад

    U r the best.

  • @SceneRewind
    @SceneRewind 2 года назад

    What network diagram do you know to draw?

  • @steiner254
    @steiner254 2 года назад +1

    Awesome

  • @BathiReddy-o8t
    @BathiReddy-o8t 4 месяца назад

    Explanation speed is very fast, it would be better if you reduce the speed.

  • @سامرسعيد-ي1ب
    @سامرسعيد-ي1ب 2 месяца назад

    Thanks from iraq

  • @poiuymnbvc8339
    @poiuymnbvc8339 Год назад

    mam, can you make course for xxs ?

  • @hackingetico1
    @hackingetico1 Год назад

    Todo esto es casi igual al sistema bug bounty

  • @Shintowel
    @Shintowel 2 года назад

    Makasih rana

  • @bhanupratapsinghtomar551
    @bhanupratapsinghtomar551 3 года назад +1

    🤩😍

  • @lorrainenewton2338
    @lorrainenewton2338 3 года назад

    I love you sist

  • @TheBashir007
    @TheBashir007 Год назад

    Sisterrrrrrrrrrrr u are amazinggggggggggg
    Jazakallah
    Made some bucks out of your video
    Some bucks wink wink

  • @Shintowel
    @Shintowel 2 года назад

    Love u

  • @ca7986
    @ca7986 2 года назад

    🙏👌

  • @-videoworldfadi8464
    @-videoworldfadi8464 2 года назад

    Want talk toghether

  • @rohitchhimpa901
    @rohitchhimpa901 Год назад

    make audio clear

  • @RanaKhalil101
    @RanaKhalil101  3 года назад +11

    Don't want to wait for the weekly release schedule to gain access to all the videos and want to be added to a discord server where you can ask questions? Make sure to sign up to my course: bit.ly/30LWAtE ✨✨

    • @francisdonald4298
      @francisdonald4298 2 года назад

      Learning pentest is there need for programming???

    • @chrisfx9097
      @chrisfx9097 2 года назад

      @@francisdonald4298 Not necessarily but it will help you understand better and learn faster. If you're pentesting a web application and you want to perform an SQL injection attack, you'll need to 'at least', understand the syntax of PHP and how SQL is used to query a database.... If you're doing an XSS attack, you'll need to understand JAVASCRIPT.

  • @anrstudio9916
    @anrstudio9916 Год назад

    Good content but terrible voice 😨😨😨

  • @earthlyelder
    @earthlyelder 2 года назад

    Thank you