This FFUF secret trick everybody need to know | Bug hunting poc

Поделиться
HTML-код
  • Опубликовано: 28 июн 2024
  • // Disclaimer //
    Hacking without permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing & bug hunting so that we can protect ourselves against the real hackers..
  • НаукаНаука

Комментарии • 256

  • @ChaRambo
    @ChaRambo Месяц назад +5

    I love when i open youtube and see a new upload from Lostsec in my notifications!

    • @lostsecc
      @lostsecc  Месяц назад

      ☺️🙈❤️🫂

  • @mylosovich24
    @mylosovich24 4 дня назад +1

    Hey Coffin, nice Fuff stuffs! Sending mental fist bumps

  • @madhavanrio3210
    @madhavanrio3210 Месяц назад +10

    Bro gta 5 fan 😂

  • @Ajay_Yadav_Smart
    @Ajay_Yadav_Smart Месяц назад +3

    I was waiting for this video..
    Thanks bro..❤❤

  • @Raduim
    @Raduim Месяц назад +1

    Congratulations for 10k buddy 💗🎉

    • @lostsecc
      @lostsecc  Месяц назад +1

      thnq brother ❤️🤗

  • @hatemaliyan3933
    @hatemaliyan3933 Месяц назад +1

    Great content 🎉, can you please do video for methodology when u find login pages how u work with that... Thank you 🙏

  • @tomiwafalade5480
    @tomiwafalade5480 Месяц назад +5

    First!!

  • @aftabsaifi2436
    @aftabsaifi2436 Месяц назад +1

    Can you please add caption according to video in your next videos.. this may help a lots of begginers

  • @ilixymx
    @ilixymx Месяц назад +1

    Hell Nah!!! . Bro got a official song too 💀💀

  • @ShermaMahdi
    @ShermaMahdi Месяц назад +1

    You de Man Mate🔥🔥🔥🔥🔥🥰🥰 U deserve Million Likes Bro💯💯💯💯

    • @lostsecc
      @lostsecc  Месяц назад +1

      🙈❤️😇

    • @ShermaMahdi
      @ShermaMahdi Месяц назад +1

      @@lostsecc Wana Say Love U man💯 Your Xss Payload Worked for me mate. Waiting the outcome of my first H1 report. Your magic Works Bro♥️♥️♥️

  • @IBO.ATTACKS
    @IBO.ATTACKS Месяц назад

    عنجد بحب طؤيقتك بالشغل
    you are great bro 😎

    • @lostsecc
      @lostsecc  Месяц назад

      thnx man ❤️☺️

  • @user-qt6md8nh6h
    @user-qt6md8nh6h Месяц назад +1

    Bro, for bug bounty i need to learn the entire javascript , which are the parts i have to learning if anything I'm missing or extra please add it.
    Thanks a lot for sharing u're knowledge to the community god bless you❤

  • @mrfadel4790
    @mrfadel4790 Месяц назад +1

    we need more from you...❤❤

  • @Shadow-Algeria
    @Shadow-Algeria Месяц назад

    I am following you. Good luck, my friend❤

  • @anatomygamer1129
    @anatomygamer1129 Месяц назад +2

    Hey brother can you please share a xss pdf ?

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in my telegram channel bro

  • @Pal0vieeee
    @Pal0vieeee Месяц назад

    Osmmm || ur content nd background music 😁🥳❣️

    • @lostsecc
      @lostsecc  Месяц назад +1

      thnq ji 🤗❤️

    • @NethaxStark
      @NethaxStark Месяц назад

      @@lostsecc indian bolte

  • @endless2333
    @endless2333 Месяц назад

    you could use burp intruder for this attack? Just wondering. Congrats on 10k!

    • @lostsecc
      @lostsecc  Месяц назад +1

      yes u can but ffuf is so fastt and some more cool features

  • @TSTpodcasts
    @TSTpodcasts 17 дней назад

    What if the passwords shown are salted? How can you be sure they are real password? can we decrypt them or try logging in with them?
    Great work bro. Learning so much from you!

    • @lostsecc
      @lostsecc  17 дней назад

      use johntheripper tool with rockyou list

  • @MuhammedEmirARSLAN01
    @MuhammedEmirARSLAN01 Месяц назад +1

    Yo man why you still rockin' Burp 1.7.13? Got a special reason or you just old school like that?... xD

    • @lostsecc
      @lostsecc  Месяц назад +1

      its light weight and dont freez like latest burpsuite memory full problems ...

  • @jht8909
    @jht8909 Месяц назад

    love watching the vids, this one was awesome 👍

    • @lostsecc
      @lostsecc  Месяц назад

      thanks mate ❤️

  • @RajanChoudhary12
    @RajanChoudhary12 Месяц назад

    We are Kings Brother. I am King you are King. Bhai Bhai

  • @apple_00
    @apple_00 Месяц назад

    بژی شیرە کور

  • @namangupta681
    @namangupta681 Месяц назад +1

    same url but when i give -mr for matching regex it wont give me anything!! where when I remove -c -mr "root:", it brings me result and then I have to filter it with size:1226.
    why not working with -mr???????

    • @lostsecc
      @lostsecc  Месяц назад

      make sure you have installed all tools used in this oneliner

    • @namangupta681
      @namangupta681 Месяц назад

      @@lostsecc i have all the tools gf , waybackurls.. this ffuf cmd don't show anything with -c -mr without it its working

    • @namangupta681
      @namangupta681 Месяц назад +1

      @@lostsecc why this -mr is not working i have followed same process and checked it 4 5 times still -mr not working

    • @lostsecc
      @lostsecc  Месяц назад

      send me screenshot in telegram

    • @namangupta681
      @namangupta681 Месяц назад

      Please check dm

  • @thiagopereira8800
    @thiagopereira8800 Месяц назад

    Hey man, great content!! :) quick question, is ffuf better than intruder to test for lfi, etc?

    • @lostsecc
      @lostsecc  Месяц назад

      yes it has very high speed threads mode+regex

    • @thiagopereira8800
      @thiagopereira8800 Месяц назад

      @@lostsecc got it, will give a chance here! Thanks

  • @dinethrahewage5869
    @dinethrahewage5869 Месяц назад

    Hey, Mate. How did you install URLdedupe on Windows 11???

    • @lostsecc
      @lostsecc  Месяц назад

      just paste binary in /usr/local/bin

  • @doshamiheh9800
    @doshamiheh9800 18 дней назад

    how do you set a background image and logo on your terminal please coffin?

    • @lostsecc
      @lostsecc  18 дней назад

      its option in window terminal download it from microsoft store

    • @doshamiheh9800
      @doshamiheh9800 18 дней назад

      @@lostsecc Okay i did that , but when i duplicate the tab , the background dissapears :( and show another terminal not the usual one

  • @Voiceee-ix8zn
    @Voiceee-ix8zn Месяц назад +1

    alert("1")

    • @Voiceee-ix8zn
      @Voiceee-ix8zn Месяц назад +1

      see the above comment is not filtered in the source why doesn't it run?

    • @lostsecc
      @lostsecc  Месяц назад

      bcz of csp and all other protection and server side encoding..

  • @Ba1X1aoTao
    @Ba1X1aoTao 14 дней назад

    Very helpful❤

  • @someyounggamer
    @someyounggamer Месяц назад

    Congrats on 10k subs.

    • @lostsecc
      @lostsecc  Месяц назад

      thnq bro ❤️🤗

  • @P45PU7
    @P45PU7 Месяц назад +1

    on my linux gf command not found, how do I do it? 🤥

    • @lostsecc
      @lostsecc  Месяц назад

      you need to install gf pattren

  • @cameronribeiro9660
    @cameronribeiro9660 Месяц назад

    I know this is off topic: but to everyone running wsl2 in windows: I was able to install run Ubuntu 24.04 wsl2 on W11 bare metal host (the only way it works) but Kali wsl2 didn’t want to install: but: Any of you tried Running latest Ubuntu as your host and a kali VM inside virtualbox? That is where I have had the best luck. Was just wondering anyone else’s experience.

  • @3bbodal-obaidi602
    @3bbodal-obaidi602 Месяц назад +1

    I don't understand ;-;
    gf: command not found
    urldedupe: command not found
    waybackurls: command not found

    • @lostsecc
      @lostsecc  Месяц назад

      you need to install all these commands

  • @IllIIIIIIllll
    @IllIIIIIIllll Месяц назад

    But what was in the response? I didn't understand.

  • @Sidharthas89
    @Sidharthas89 Месяц назад

    Awesome brother ❤❤❤
    Where can I get this awesome lfi payloads.
    You have set your wallpaper kali .

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram bro

  • @H4cker_Nafeed
    @H4cker_Nafeed Месяц назад

    What tool do you use for this ? And what is the purpose of using FUFF in the parameter ? And does it work only in php based endpoints? By doing this WAF don't block us ?

    • @lostsecc
      @lostsecc  Месяц назад +1

      its work in all post and get param

  • @EnLopXf
    @EnLopXf Месяц назад

    I'm waiting on demonstration of web defacement

  • @rishabhrana3773
    @rishabhrana3773 Месяц назад

    Bro how you check fod xss in multiple fields in one go can you tell please

    • @lostsecc
      @lostsecc  Месяц назад

      use intruder there is many options like pitchfork etc

    • @rishabhrana3773
      @rishabhrana3773 Месяц назад

      @lostsecc can i use it at same on different location

  • @vikasnaval3190
    @vikasnaval3190 Месяц назад

    Fantastic as always 😍

    • @lostsecc
      @lostsecc  Месяц назад

      thnx mate ❤️

  • @mistDexploit
    @mistDexploit Месяц назад

    bro finilly I found your play list in telegram Channel 😂🤝

  • @exotic2032
    @exotic2032 Месяц назад

    Bro can you make video in website info gathering and enumeration how professional get deeper information about website like subdomain endpoint directories present vulnerabilitys

  • @NethaxStark
    @NethaxStark Месяц назад

    We can't use this trick for other attacks like the xss by changing the payload list Am I right?

    • @lostsecc
      @lostsecc  Месяц назад

      you can try ssti by regex 49

    • @NethaxStark
      @NethaxStark Месяц назад

      @@lostsecc ok I am new please please could you elaborate it!

  • @SevenHeavenlyig
    @SevenHeavenlyig 15 дней назад

    Can you please share the wordlist which u used first ?

    • @lostsecc
      @lostsecc  15 дней назад

      i shared in my github

    • @SevenHeavenlyig
      @SevenHeavenlyig 14 дней назад

      @@lostsecc bro your GitHub is not showing up in the index search. It shows 404 error

  • @NethaxStark
    @NethaxStark Месяц назад +1

    Song name?

  • @d4rk_s4mur41
    @d4rk_s4mur41 Месяц назад

    Hi, amazing work bro! Where did you get wordlist? Can you share the link to this wordlist and other wordlists if you can

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram bro

  • @RajanChoudhary12
    @RajanChoudhary12 Месяц назад

    But i really saw you after a lot of time

  • @user-ro8th6xt9c
    @user-ro8th6xt9c Месяц назад

    why u use old version of burp?

    • @lostsecc
      @lostsecc  Месяц назад

      latest burp consume lots if ram and hangs..old one is ligh weight and give good results..

  • @samhansen-dev
    @samhansen-dev Месяц назад

    I like the image you have for the background of your terminal.Please share the link😅

  • @TheWahb123
    @TheWahb123 Месяц назад

    How do you bypass waf when dirbusting with ffuf or wfuzz ?

    • @lostsecc
      @lostsecc  Месяц назад +1

      change the ffuf default user-agent

  • @BMV-kl1br
    @BMV-kl1br Месяц назад

    brother why u using old burp suite

    • @lostsecc
      @lostsecc  Месяц назад

      its light weight in latsst burp its consume lots of ram and hangs alot also it has spider feature that will help u more

  • @user-nj8fi2ix8i
    @user-nj8fi2ix8i Месяц назад

    Hello Brother I got this error whenever i tried to install GF tool i tried every method still i can't get solution
    fatal: not a git repository (or any of the parent directories): .git

    • @lostsecc
      @lostsecc  Месяц назад

      dm me in telegram give anydesk id

    • @user-nj8fi2ix8i
      @user-nj8fi2ix8i Месяц назад

      @@lostsecc Yes i did kindly check your DM

  • @shycat-yq5ij
    @shycat-yq5ij Месяц назад

    Keep it up bro

  • @Impaler_XV
    @Impaler_XV Месяц назад

    bro i’m dumb ngl so i might be asking sum stupid but is it possible to change the screen res of an iphone 13 on ios 18 ??

    • @lostsecc
      @lostsecc  Месяц назад

      bro i never tried it so no idea

    • @Impaler_XV
      @Impaler_XV Месяц назад

      @@lostsecc i thought maybe if restoring a modified backup on your pc you might be able to change the screen res inside it but maybe apple has security measures to not let that happen? if you have time i’ll genuinely give you a 20$ visa gift card to help me find a way to do it on ios 18 beta 2, i’ll pay you first too as long as you show me that it works bro

  • @timovc5340
    @timovc5340 Месяц назад

    can i somehow configure ffuf so it doesnt show stuff like ././././../../etc/passwd instead of just ../../etc/passwd? I mean it's the same after all

    • @lostsecc
      @lostsecc  Месяц назад +1

      just add normal lfi payload list

  • @Voiceee-ix8zn
    @Voiceee-ix8zn Месяц назад

    Do you have your github?
    I need XSS payloads

    • @lostsecc
      @lostsecc  Месяц назад

      github.com/coffinxp/payloads

    • @Voiceee-ix8zn
      @Voiceee-ix8zn Месяц назад

      @@lostsecc How did you make so many LFI payloads 💀💀💀

  • @footballisfun7858
    @footballisfun7858 Месяц назад

    Bro, you are a genius 😂

  • @charlie-he9ft
    @charlie-he9ft 11 дней назад

    How u find theese targets.

  • @fanky2696
    @fanky2696 Месяц назад

    the type of vuln is path traversal ??

  • @cameronribeiro9660
    @cameronribeiro9660 Месяц назад

    Also: I actually thought you were Russian. I’m thinking from India though cause everyone from India seems to be running wsl2 in W.

    • @lostsecc
      @lostsecc  Месяц назад

      wsl2 is lit..no faced any problem till now

  • @srinaths6855
    @srinaths6855 28 дней назад

    hi bro could share the yours payloads ... that will be help full to us

  • @paktiko1986
    @paktiko1986 Месяц назад

    amazing, Brother

    • @lostsecc
      @lostsecc  Месяц назад

      thnq brother ❤️😇

  • @jkai_8
    @jkai_8 Месяц назад

    very nice video

  • @kartik_exe_
    @kartik_exe_ Месяц назад

    hey bro you still remeber me? and nice you upgraded to windows 11 and bro i want to ask whats ur age and u from where?

  • @user-ne8zp2by6u
    @user-ne8zp2by6u Месяц назад +1

    How to you install gta 5 without virus free bro?

    • @lostsecc
      @lostsecc  Месяц назад

      i download from epicgames offical site

  • @tlcmajed967
    @tlcmajed967 Месяц назад

    Wich version of burp do you use and why dont use last version ?

    • @lostsecc
      @lostsecc  Месяц назад

      latest burp consume lots of memory and hangs so i used old one its give better results and spider feature

    • @tlcmajed967
      @tlcmajed967 Месяц назад

      @@lostsecc can u give me number of version pls ?

    • @lostsecc
      @lostsecc  Месяц назад +1

      i shared in my github check out

    • @tlcmajed967
      @tlcmajed967 Месяц назад

      @@lostsecc thx bro ❤️❤️

  • @akroidofficial
    @akroidofficial Месяц назад

    what about in modern webs like MEAN, MERN ?

    • @lostsecc
      @lostsecc  Месяц назад

      you can try must change default user agent before ffuf command

  • @spramoda_8979
    @spramoda_8979 Месяц назад +1

    Broo❤❤

  • @aatankbadboy3941
    @aatankbadboy3941 Месяц назад

    Bro what happened when we got this etc/passwd file and what's name of this vulnerability

    • @lostsecc
      @lostsecc  Месяц назад +1

      LFI directory traversal

  • @BiFr0ost
    @BiFr0ost 11 дней назад

    can u share the list of the payloads pls?

    • @lostsecc
      @lostsecc  11 дней назад +1

      i shared in telegram and github

    • @BiFr0ost
      @BiFr0ost 10 дней назад

      @@lostsecc ur github account looks like is block :(

  • @0xazyz897
    @0xazyz897 Месяц назад

    i like your channel , but bro be careful , what you're doing is illegal because you're live hacking real targets and uploading it to RUclips , also the vulnerabilities that you are demonstrating are not patched yet , i tested it and it worked , Keep going my G and Be aware 😉

    • @lostsecc
      @lostsecc  Месяц назад

      dont worry bro people want to watch real targets testing not labs

    • @fahadismail7430
      @fahadismail7430 Месяц назад

      you're absolutely right bro.. keep doing it ...I personally love real life

  • @__CJ.__
    @__CJ.__ Месяц назад

    crazy bro ❤💯🖐

  • @wave-bomber
    @wave-bomber Месяц назад

    How do you maks this colorized shell??? 💀💀💀

    • @lostsecc
      @lostsecc  Месяц назад

      install window terminal with kali wsl2

    • @wave-bomber
      @wave-bomber Месяц назад

      @@lostsecc im asking for this spacific style with this spacific image. Its a default?

    • @lostsecc
      @lostsecc  Месяц назад

      you need to change walpaper from its setting

  • @yahai_
    @yahai_ Месяц назад +1

    ❤❤

  • @lilrucky2766
    @lilrucky2766 Месяц назад

    bro what's the appliaton u write codes on?

    • @lostsecc
      @lostsecc  Месяц назад +1

      window terminal wsl2 kali

  • @learn7352
    @learn7352 Месяц назад

    Song title bro? I felt excited when I heard it

    • @lostsecc
      @lostsecc  Месяц назад +1

      dark beach slowed

  • @cyber_india
    @cyber_india Месяц назад

    Which worldlist you used?

    • @lostsecc
      @lostsecc  Месяц назад +1

      i will share in telegram

  • @kingmanxx4883
    @kingmanxx4883 Месяц назад

    Whay use ffuf? , bro use jast intruder in burp

    • @lostsecc
      @lostsecc  Месяц назад +1

      intruder dont do much this much fast and not all have burp pro

  • @jkai_8
    @jkai_8 Месяц назад

    where can i get the lf1 payload

    • @lostsecc
      @lostsecc  Месяц назад +1

      i shared in telegram

    • @jkai_8
      @jkai_8 Месяц назад

      @@lostsecc whats your telegram

    • @jkai_8
      @jkai_8 Месяц назад

      @@lostsecc found it and joined your telegram thanks so much

  • @thehoffgamming7752
    @thehoffgamming7752 Месяц назад

    No talk, no write. Just moving cursor. Wow

  • @Hariomp30
    @Hariomp30 Месяц назад

    verry helpfull bro

  • @sarthakshrivastava6602
    @sarthakshrivastava6602 Месяц назад

    Which terminal are you using

    • @lostsecc
      @lostsecc  Месяц назад

      window terminal wsl2 kali

  • @tomiwafalade5480
    @tomiwafalade5480 Месяц назад

    Love you bro!!!

    • @lostsecc
      @lostsecc  Месяц назад

      love you three bro ❤️

  • @cyberx14
    @cyberx14 Месяц назад

    Hey Great Content Can I Get that lFI payloads file?

    • @lostsecc
      @lostsecc  Месяц назад +1

      i shared in telegram channel must check

    • @studyrelaxwithme4564
      @studyrelaxwithme4564 Месяц назад

      I can't find It in your telegram channel

  • @ashishchauhan9745
    @ashishchauhan9745 Месяц назад

    background sound name

  • @garrinormanivannacov370
    @garrinormanivannacov370 Месяц назад

    amazing bro!

  • @nlegendgaming8324
    @nlegendgaming8324 Месяц назад

    Please give us some new nuclei-templates 🙈 (your private templates ) 🌚

  • @madhavanrio3210
    @madhavanrio3210 Месяц назад

    Sir it possible on random urls or only php pages

  • @CircularArc
    @CircularArc Месяц назад

    Yo bro can you make a video on how to start bug hunting

  • @HackerBuvi
    @HackerBuvi Месяц назад

    first commends in lfi what file and i will try but error: no such pattern

    • @lostsecc
      @lostsecc  Месяц назад +1

      you need to install gf pattren

    • @HackerBuvi
      @HackerBuvi Месяц назад

      @@lostsecc thankyou bro

  • @BEESCO-BB
    @BEESCO-BB Месяц назад

    Bro It was very hard 😂😂

  • @bakibakikumin7965
    @bakibakikumin7965 Месяц назад

    can you share wordlist brother?

  • @srikanth4326
    @srikanth4326 Месяц назад

    What is the terminal u are using ? How to get it

    • @lostsecc
      @lostsecc  Месяц назад

      its window terminal with wsl2 kali you can install it from microsoft store

    • @srikanth4326
      @srikanth4326 Месяц назад

      ​@@lostsecc thank you 👍 ....

  • @Booom1444-_-
    @Booom1444-_- Месяц назад

    where can i get that payload?

    • @lostsecc
      @lostsecc  Месяц назад

      i will share in telegram

  • @Cyber_rick087
    @Cyber_rick087 28 дней назад

    Hey bro can you share your payload txt file ??

  • @patfire785
    @patfire785 Месяц назад

    Smart trick!

  • @QXJlIHlvdSBibGluZD8
    @QXJlIHlvdSBibGluZD8 Месяц назад

    Awesome video bro!
    Keen to understand how you got the first command when piped to acknowledge
    | gf lfi | urldedupe
    I have waybackurls working but i am not sure how to get gf to see the lfi payload

    • @lostsecc
      @lostsecc  Месяц назад +1

      you need to install gf and its pattren i shared in telegram

  • @histoire-de-blackhat3346
    @histoire-de-blackhat3346 Месяц назад

    in description

    • @lostsecc
      @lostsecc  Месяц назад

      check telegram bro

  • @madhavanrio3210
    @madhavanrio3210 Месяц назад

    Dude 🎉❤

  • @histoire-de-blackhat3346
    @histoire-de-blackhat3346 Месяц назад

    show all command that you do

  • @fdl11
    @fdl11 Месяц назад

    Can i have lfi payload?

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram channel

  • @matatiga
    @matatiga Месяц назад

    t