Это видео недоступно.
Сожалеем об этом.

Find stored xss via svg file upload | Bug bounty poc

Поделиться
HTML-код
  • Опубликовано: 3 фев 2024
  • in this video i am going to show you how to find xss by svg file upload that is stored xss and count as p3.
    Disclaimer: This video is for strictly educational and informational purpose only. I own all equipment used for this demonstration. Hacking without permission is illegal so always ensure you have proper authorization before using security tools in any network environment. thanks.

Комментарии • 30

  • @tpevers1048
    @tpevers1048 10 дней назад

    Just self xss and also you cannot check the profile of others but really good one

    • @lostsecc
      @lostsecc  10 дней назад

      just for demonstration svg xss❤️

    • @tpevers1048
      @tpevers1048 10 дней назад

      But bro if you found it yourself I can call you a pro because the idea is the thing that's difficult also it's make me laughing that you found xss on bxss thats a tool for xss hunters 🤣🤣🤣

    • @lostsecc
      @lostsecc  10 дней назад

      😂ywah 🤭

  • @user-pj2px9jz8p
    @user-pj2px9jz8p 19 дней назад

    So website for blind xss still have xss bug 😅

  • @dittonachan
    @dittonachan 6 месяцев назад

    Is that xss payload saved as .svg format?

  • @sepho942
    @sepho942 5 месяцев назад

    how long have you been studying csec for

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      i just done collage only for degree no real education at all i learn all from youtube and google

    • @sepho942
      @sepho942 5 месяцев назад

      @@lostsecc can you send over some good web hacking resources? been learning for 8 days so far and i need more resources

  • @apple_00
    @apple_00 6 месяцев назад +1

    I need jpg payload ❤

    • @lostsecc
      @lostsecc  6 месяцев назад

      uploading soon

    • @lostsecc
      @lostsecc  6 месяцев назад

      check out github.com/coffinxp/SVG-Payloads/

    • @apple_00
      @apple_00 6 месяцев назад

      @@lostsecc not working 💔

    • @apple_00
      @apple_00 6 месяцев назад

      @@lostsecc please make videos.
      Haw to make jpg. Payload xss

    • @lostsecc
      @lostsecc  6 месяцев назад

      try same ...it work..use my payload coffinxss.svg

  • @ahsan50505
    @ahsan50505 6 месяцев назад

    self?

    • @lostsecc
      @lostsecc  6 месяцев назад

      its actually stored but the website refresh its profile pic so its not impactful but if you use this anywhere it will count as p2 or p3

  • @HdhdssbsnSysysy
    @HdhdssbsnSysysy 6 месяцев назад

    How much this poc iz

    • @lostsecc
      @lostsecc  6 месяцев назад

      what i did not understand

    • @HdhdssbsnSysysy
      @HdhdssbsnSysysy 6 месяцев назад

      How much money

    • @lostsecc
      @lostsecc  6 месяцев назад

      its not a bounty program

  • @REDSPYTECH
    @REDSPYTECH 6 месяцев назад

    Bro can you send me payload

    • @lostsecc
      @lostsecc  6 месяцев назад +1

      github.com/coffinxp/SVG-Payloads

  • @sw4pn3h0x8
    @sw4pn3h0x8 6 месяцев назад

    Any bounty?

    • @lostsecc
      @lostsecc  6 месяцев назад

      its not in bounty program

  • @alientec258
    @alientec258 6 месяцев назад

    wow cool , thx

  • @jawirtersakiti
    @jawirtersakiti 6 месяцев назад

    noob

    • @lostsecc
      @lostsecc  6 месяцев назад

      thnq ❤️