How to exploit a blind SSRF?

Поделиться
HTML-код
  • Опубликовано: 15 ноя 2024

Комментарии • 31

  • @janekmachnicki2593
    @janekmachnicki2593 Год назад +1

    Thanks for another briliant tutorial .Great job

  • @mohmino4532
    @mohmino4532 Год назад +1

    Awesome as usual ma man 🤩 but why did u put this { foo;} ? and what is his role in this process 🙃

    • @intigriti
      @intigriti  Год назад +1

      Thank you! The "foo" bit isn't needed, shellshock payloads often just use "() {:;}" to declare the bash function.

    • @mohmino4532
      @mohmino4532 Год назад +1

      @@intigriti i see thanks again ❤

  • @jacobfurnish7450
    @jacobfurnish7450 Год назад +1

    4:14 when you say is any host in the internal network vuln to shellshock, internal network meaning origin server or would you also have to bypass a CDN like CloudFlare or AWS in order to exploit?

    • @intigriti
      @intigriti  Год назад +1

      Once you've found and exploited the SSRF, it's the web server scanning the internal network which is unlikely to be protected.

  • @SrRunsis
    @SrRunsis 3 года назад

    THanks so much for this video Intigriti!!!! You guys are awesomee

  • @lol-hz9mc
    @lol-hz9mc 3 года назад +3

    That's an interesting explanation!!! Thanks

    • @intigriti
      @intigriti  3 года назад +1

      Glad you liked it!

  • @shpockboss3834
    @shpockboss3834 3 года назад

    On every target ,do we have to try same IP? or where can we get IP?

    • @intigriti
      @intigriti  3 года назад

      This is something you'd have to guess. Read up on private IP ranges and then you'll see which to scan!

  • @fahadfaisal2383
    @fahadfaisal2383 3 года назад +1

    This vulnerability is common is websites?

    • @intigriti
      @intigriti  3 года назад +1

      SSRFs have become quite common!

  • @huuloc8719
    @huuloc8719 3 года назад +3

    Nice.

  • @itsm3dud39
    @itsm3dud39 2 года назад

    i used other commands like id, /etc/passwd .. they are not working.why only whoami command working?

    • @intigriti
      @intigriti  2 года назад

      There could be a number of measures in place preventing you from running other commands.

  • @hackersguild8445
    @hackersguild8445 2 года назад

    Thanks for sharing. Nice video :)

  • @alan.m.rebeira
    @alan.m.rebeira 3 года назад +2

    😍😍😍

  • @tudasuda5501
    @tudasuda5501 3 года назад +1

    Thnx!

  • @solo_code_rider4660
    @solo_code_rider4660 2 года назад

    Thanks

  • @AnthonyMcqueen1987
    @AnthonyMcqueen1987 2 года назад

    This is it time to shut them down. lol JK

  • @MichaelCooter
    @MichaelCooter 3 года назад +1

    First!