BUG BOUNTY: XSS AUTOMATION WITH A NEW TOOL! | 2023

Поделиться
HTML-код
  • Опубликовано: 4 фев 2025

Комментарии • 65

  • @gj9585
    @gj9585 Год назад +4

    please make a video on how to install katana in windows

  • @mamuli01
    @mamuli01 4 месяца назад

    its great seeing people moving to WSL all in one no external software required

  • @jaman_pentester
    @jaman_pentester Год назад +1

    Nice tools. 🎉

  • @letsgo...7842
    @letsgo...7842 Год назад +1

    Great 😊 working 😍

  • @rony8094
    @rony8094 Год назад +1

    fantastic

  • @letsgo...7842
    @letsgo...7842 Год назад +1

    Amezing ♨️

  • @shivakumarmv4249
    @shivakumarmv4249 Год назад +1

    Hi this is very nice tool. My request is if any special characters are identified by the tool that reflecting in response, will this tool able to generate the XSS payloads based on the identified special character? If not, try to bring this tool. this will be a great help.

  • @amoh96
    @amoh96 Год назад +4

    i see your videos alot about automation can u make methdology video about how to manuel testing & tips , tbh i found 4 xss in vdp 2 dublecate with automation & 2 valid with manuel testing

    • @ptyspawnbinbash
      @ptyspawnbinbash Год назад +1

      Is Manuel ok with him being tested?

    • @lekos1337
      @lekos1337 Год назад

      @@ptyspawnbinbashbro 💀💀💀

  • @doshamitv5020
    @doshamitv5020 Год назад +2

    What about a SQL one ? will you soon release it ? ( BLIND SQL ) test for all parametres

  • @suryaroja03
    @suryaroja03 Год назад +1

    awesome bro

  • @dzzaza24
    @dzzaza24 Год назад +1

    goooog job

  • @danielvergese9800
    @danielvergese9800 Год назад +2

    This tool looks to be great for most of the wp websites however do you have something for the website post logins?

    • @danielvergese9800
      @danielvergese9800 Год назад +1

      @BePracticalTech does the current payloads includes WAF bypass?

  • @SOBHITSHARMA
    @SOBHITSHARMA Год назад +3

    Great Video man! thanks alot, but I have a question, this too checks the url only which is accessible, without login that means we have pages or modules which are hidden until we login, how to use this tool after succesfull login and then real modules test takes place. Please suggest. I have been looking for different automation for xss but all of them only works for open pages but not after login or may be I dont know how to use them after login. Once again thanks for your efforts.

  • @pzer0man
    @pzer0man Год назад +2

    great video but after found xss vuln. teach how to exploit them pls.

  • @omaralsayyed4146
    @omaralsayyed4146 Год назад +2

    Hy
    can help me for this issue please!
    -uThe system cannot find the file specified.
    Command 'cat res.txt | grep '=' | sort -u' returned non-zero exit status 1.

    • @omaralsayyed4146
      @omaralsayyed4146 Год назад

      It's problem because this tool just run in linux ,
      i use windows 11 and cmd not support cat command ,
      I installed ubuntu subsystem and executed in bash and it work successfully : )
      @@BePracticalTech

  • @sgeetha472
    @sgeetha472 Год назад +1

    \"is reflecting but didnt produce payload instead it shows connection reset ..continuously...why?i injected a basic xss payload ..but tgere is no response in burpsuite repeater.why?

    • @sgeetha472
      @sgeetha472 Год назад

      @@BePracticalTech email sent

  • @mohamedhussain6602
    @mohamedhussain6602 Год назад +2

    katana not found what i do

  • @Fetrah2
    @Fetrah2 Год назад +3

    Can you help me bro? it says 'is reflecting in the response
    but when I try to use a paylaod it says access denied what should I do could you please help me?

  • @cryptikbyte
    @cryptikbyte 8 месяцев назад +1

    Bro please help karr kam se kam bolde pakda to nahi jaunga na??

  • @krivadnaaiservices
    @krivadnaaiservices 9 месяцев назад

    So file gas to be bamed katana.txt always? And for scan single url, do we have to give parameters

    • @BePracticalTech
      @BePracticalTech  9 месяцев назад

      Yes, you do need to provide the url containing the parameter eg. testphp.vulnweb.com/index.php?name=batman

  • @Tausif_Zaman
    @Tausif_Zaman 9 месяцев назад +1

    Katana isnot working
    No command katana found, did you mean:
    Command botan3 in package botan3
    Command cantata in package cantata from the x11-repo repository

    • @BePracticalTech
      @BePracticalTech  9 месяцев назад +1

      You need to install katana from github

    • @Tausif_Zaman
      @Tausif_Zaman 9 месяцев назад

      @@BePracticalTech Now its working 🫶. Take Love🖤 from Bangladesh 🇧🇩

  • @SOBHITSHARMA
    @SOBHITSHARMA Год назад +1

    Another thing, I tried the tool and it gave me list of urls which says
    [+] > is reflecting in the response
    [+] ' is reflecting in the response
    [+] " is reflecting in the response
    [+] < is reflecting in the response
    [+] / is reflecting in the response
    [+] Testing parameter name:
    but when I tried it with the payload which it says, I could not able to see xss on the webshite? Any suggestions?

    • @SOBHITSHARMA
      @SOBHITSHARMA Год назад

      @@BePracticalTech

    • @SOBHITSHARMA
      @SOBHITSHARMA Год назад

      @@BePracticalTech yep! not reflecting, so basically portal is auto encoding it.

    • @SOBHITSHARMA
      @SOBHITSHARMA Год назад

      @@BePracticalTech thank you man!

  • @Aniket18101
    @Aniket18101 Год назад

    Respect bro

  • @Arfat-Khan
    @Arfat-Khan Год назад

    Can you make a video on file upload in details

  • @shuvonofc
    @shuvonofc Год назад

    payloads are not show

  • @HawkPubg48
    @HawkPubg48 Год назад

    Can you add -proxy option please it will be beast thank you

  • @sugamdangal9974
    @sugamdangal9974 Год назад

    Will it be able to bypass Waf?

  • @eowaldemar8195
    @eowaldemar8195 Год назад

    Please, is it possible to provide the katana.txt file

  • @nikhiltiwari1477
    @nikhiltiwari1477 Год назад

    Is xss_vibes offline or online attack. Like does it create any traffic while ruuning?

  • @danmcgirr4210
    @danmcgirr4210 Год назад

    Great lesson!

  • @ali_aqeel
    @ali_aqeel Год назад

    Why don't you run on Linux?

  • @chandrasekharreddy1209
    @chandrasekharreddy1209 Месяц назад

    Xss vibes tool is not working

  • @tbjehad106
    @tbjehad106 Год назад

    is it just for reflected xss

  • @Gowtham_SS
    @Gowtham_SS Год назад +5

    Katana command not found bro

    • @pankajsaini8916
      @pankajsaini8916 Год назад

      Same

    • @josevannel4819
      @josevannel4819 Год назад

      Same here ayy

    • @krivadnaaiservices
      @krivadnaaiservices 9 месяцев назад +1

      He is not replying to anyone but only liking ur comments... hahaha

    • @xynthewarrior
      @xynthewarrior 5 месяцев назад +2

      Cuz it's obvious. You need to install tools before eventually using them lol.

  • @doshamitv5020
    @doshamitv5020 Год назад

    king

  • @krivadnaaiservices
    @krivadnaaiservices 9 месяцев назад

    He is not replying to anyone but only liking ur comments... hahaha

  • @mnageh-bo1mm
    @mnageh-bo1mm Год назад

    it's not a new tool man , this just xss strike 🙄🙄🙄🙄

  • @TheCyberWarriorGuy
    @TheCyberWarriorGuy Год назад

    :)

  • @sgeetha472
    @sgeetha472 Год назад

    how to generate payload?>,',",/, is reflecting is there any website to generate?

  • @deepspecial1161
    @deepspecial1161 Год назад

    brother can i get your telegram username i want talk something with thank you