#NahamCon2024

Поделиться
HTML-код
  • Опубликовано: 3 дек 2024

Комментарии • 15

  • @ZarakKhanNiazi
    @ZarakKhanNiazi 6 месяцев назад +11

    BBRE guy is the only person who cares about eyesight of content consumers, he used large fonts which we can read easily

  • @KarahannAe
    @KarahannAe 5 месяцев назад +3

    18:24 if anyone else was also confused when he says POST-AUTH REDIRECT he is talking about after the Oauth dance is over, he doesnt mean POST based oauth flow.

    • @BugBountyReportsExplained
      @BugBountyReportsExplained 27 дней назад

      I see how this can be confusing. Since then, I have changed how I say this part to after-auth redirect to be clearer.

  • @so3litude_
    @so3litude_ 6 месяцев назад +3

    Even though the state parameter is present in the request you should always check for CSRF I've found many targets vulnerable to this . Most of the people leave as soon as they see State parameter in the request. This happens because of misconfig in OUath flow where it doesen't validate the state parameter server side . It only checks if it is present or not.

    • @deporison
      @deporison 6 месяцев назад +1

      Also the login csrf is still possible because we still have the state and we can send it to the user

    • @BugBountyReportsExplained
      @BugBountyReportsExplained 6 месяцев назад +2

      very true! The presence doesn't mean it's checked

  • @heller64
    @heller64 5 месяцев назад

    most site now uses strict url validation on redirect_uri not even extra dot can be added btw thx greg

  • @bughunter9766
    @bughunter9766 6 месяцев назад +1

    Thanks Ben and Enjoooooooy 😊

    • @ZarakKhanNiazi
      @ZarakKhanNiazi 6 месяцев назад

      I love and enjoy hearing him say enjoy

    • @bughunter9766
      @bughunter9766 6 месяцев назад

      @@ZarakKhanNiazi All of us like it 😁✌️✌️✌️

  • @MarkFoudy
    @MarkFoudy 6 месяцев назад

    Thanks Ben!

  • @InfoSecIntel
    @InfoSecIntel 5 месяцев назад

    Hey brother can you add these to the playlist

  • @MianHizb
    @MianHizb 5 месяцев назад

    this was nice

  • @hamzabohra5083
    @hamzabohra5083 6 месяцев назад

    Second