Turbo Intruder: Abusing HTTP Misfeatures to Accelerate Attacks by James Kettle

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024

Комментарии • 29

  • @danieljordan1793
    @danieljordan1793 5 лет назад +23

    This guy is awesome, his content is always original and extremely helpful!

  • @sakettestsakettest8009
    @sakettestsakettest8009 4 года назад +5

    This guy is incredible ❤️

  • @saeedkamranfar684
    @saeedkamranfar684 4 года назад +1

    GREATE, James kettel is the legend of web security

  • @CU.SpaceCowboy
    @CU.SpaceCowboy 3 года назад +1

    i saw a video of him getting a shell on a code sandbox website with like 2-3 broken up lines of php. hes legendary.

  • @rnz2363
    @rnz2363 3 года назад +1

    i did not have a clue about HTTP pipelining. good info here. thx

  • @SatouSei13
    @SatouSei13 Год назад

    Amazing tool. Thank you! 🙏🙏

  • @a.for.arun_
    @a.for.arun_ 2 года назад

    @albinowax Legend!!!

  • @freem4nn129
    @freem4nn129 Год назад

    nice !! thx for this

  • @killzann7757
    @killzann7757 3 года назад

    This is incredible, thanks

  • @mthulisi8840
    @mthulisi8840 4 года назад

    Excellent stuff!

  • @yoshi5113
    @yoshi5113 2 года назад

    I love James Kettle ..

  • @DeepakPrajapati-ny3bj
    @DeepakPrajapati-ny3bj 5 лет назад

    Thank you for this very informative and very helpful video.

  • @DragonStoneCreations
    @DragonStoneCreations 3 года назад +1

    How to configure multiple injection points in the request?
    I tried using %s in 2 locations, payload is injected only first %s :(

    • @poxato
      @poxato 3 года назад

      there's a premade script in the scripts section of the turbo intruder for multiple Parameters.

  • @ZoomAnimationHere
    @ZoomAnimationHere 4 года назад

    Thanks

  • @shayberkovich8104
    @shayberkovich8104 4 года назад

    Still don't understand why James hasn't incorporated this into Intruder functionality - that would add multiple insertion points, wordlists and other Intruder features for free. Instead, he decided to implement this as a separate extension.

  • @Ramazan05duldug
    @Ramazan05duldug 4 года назад

    Thanks! )

  • @skylinegeekhackerone8560
    @skylinegeekhackerone8560 5 лет назад

    i get error, SyntaxError: ("mismatched input 'table' expecting INDENT", ('', 26.0, 'table.add(req)
    ')) when i user race.py to check race condition

  • @jessicaito5212
    @jessicaito5212 Год назад

    What am I doing wrong. I am only getting 100-141 RPS. Do I need to get anything other then Turbo Intruder?
    My settings are
    concurrentConnections=25
    requestsPerConnection=100
    Pipeline=True

  • @TheHackTodayOfficial
    @TheHackTodayOfficial 5 лет назад

    cool!

  • @SplinterAI
    @SplinterAI 2 года назад

    You are the man !! Can you download turbo intruder for free?

    • @slayeeerrr
      @slayeeerrr 2 года назад

      It is integrated with Burp Suite as a plugin, and it is available even on Community Edition! :-)

  • @tombautista2913
    @tombautista2913 5 лет назад

    I am trying to tweak setting just like you've guided but not able to achieve those thousands and thousands of RPS.

    • @tombautista2913
      @tombautista2913 5 лет назад

      I can provide you with more details but I don't have my own website I was just trying it on random websites on internet which is illegal know that.

    • @tibabalaseo2046
      @tibabalaseo2046 2 года назад

      @@tombautista2913 Maybe those websites just blocked you off IP? But it's been 2 years so i'm sure you know that

  • @slaxblake
    @slaxblake 5 лет назад

    How to use it for race condition @Bugcrowd

  • @SplinterAI
    @SplinterAI 2 года назад

    Is there any chance that you would consider helping me Find my first bug bounty ! Im stuck Im stuck . Great video thou .

  • @bigdatax6512
    @bigdatax6512 3 года назад

    hey there i want to ask something ..how can i contact you