Это видео недоступно.
Сожалеем об этом.

Microsoft IIS Server mass Hunting | Bug bounty poc

Поделиться
HTML-код
  • Опубликовано: 20 фев 2024
  • Disclaimer: This video is for strictly educational and informational purpose only. I own all equipment used for this demonstration. Hacking without permission is illegal so always ensure you have proper authorization before using security tools in any network environment. thanks.
    in this video i am going to show you how to hunt for microsoft iis vulnerability and you can report it in bug bounty program and earn good bounties..

Комментарии • 376

  • @0xdreadnaught
    @0xdreadnaught 5 месяцев назад +16

    today on quick ways to meet the feds...

    • @sepho942
      @sepho942 4 месяца назад +2

      mullvad vpn: you sure about that?

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked 5 месяцев назад +31

    Great video! Great music! Great finds! I'm going to get shortscan because of you. I've not heard of it before, that I remember at least. Plus, some this vulnerability is interesting, and the Burp Suote plug-in is great. Hehe

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      thnq so much its means a lot for me 😇❤️

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 5 месяцев назад

      Plus, this* Suite*

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 5 месяцев назад

      ​@@lostseccYou're welcome a bunch! Thank you, too! My pleasure. Shalom.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked 5 месяцев назад

      ​@@lostseccI installed shortscan manually and via the go install, and neither worked when I tried to launch shortscan. Shortscan doesn't appear in blue when I try to use the tool. Would you be aware of what's going on?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      you need to move that binary to usr/local/bin directory

  • @SageChaozu
    @SageChaozu 2 месяца назад +1

    That's interesting how you found those domains like that by finding people who didn't update the default IIS home page. I recognize some of the domains from work and may reach out to get them to secure their stuff. I try to warn them to not leave their servers so vulnerable but they really think no one can access something unless they put out the URL.
    I like this video because its very educational and hope it spreads more awareness

  • @bboymyers3853
    @bboymyers3853 5 месяцев назад +4

    Is this you finding this bug without any prep? I barely understand what's going on but it's incredible to see this in real time and see you complete a thousand dollar bug within 17 mins. The amount of time and effort you must've put in to hack at this level is incredible

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      Thnq so much for supporting my brother ❤️😇 i also reported many iis bugs to Dell bug bounty program..

  • @Levi6412
    @Levi6412 5 месяцев назад +2

    I got one too just 30 mins before in a sub domain because of your video it helps me to find it😊 in the beginning i did not know, those also can be counted as a bug until i see your video.... Thank you for making me motivated and information

    • @lostsecc
      @lostsecc  5 месяцев назад

      happy to see my videos help somone ,❤️😇

    • @aatankbadboy3941
      @aatankbadboy3941 3 месяца назад

      Can you tell more about your finding 🎉

  • @SonixAEP
    @SonixAEP 5 месяцев назад +6

    By the way the 'scan interrupted' error that you were getting was because when you pasted the url in burp suite you didnt remove the space at the end. Try removing the space and then it wont give you an error. Great video overall

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      yes i noticed it bro thnq you so much 😇❤️

    • @anthoooooooo
      @anthoooooooo 5 месяцев назад

      that triggered me.

  • @macebtw6116
    @macebtw6116 5 месяцев назад +5

    I’m interested in knowing how you’re running bash in the windows command prompt

    • @ikken
      @ikken 5 месяцев назад +3

      WSL

    • @0xReedy
      @0xReedy 5 месяцев назад

      he can also install bash and hook it to the path without the wsl rabbitwhol @@ikken

  • @user-cl8gr1sy8i
    @user-cl8gr1sy8i 5 месяцев назад +5

    What did you even accomplish that you can't with simple keyword fuzzing? Seems like a pretty dumb attack to have to look for tilde exploit vulnerable hosts rather than fuzzing all

    • @lostsecc
      @lostsecc  5 месяцев назад

      its not just a fuzzing that exploit more thing then fuzzing stuffs..its use ~ character and all methods like get post patch stuffs etc

  • @kashyapsugandh7319
    @kashyapsugandh7319 5 месяцев назад +1

    Great video! Please create a video about how you setup kali with tools using wsl

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      sure ❤️

  • @WaterLover2
    @WaterLover2 5 месяцев назад +3

    where did u study bug bounty from? or even ethical hacking. i want to start learning it myself

    • @lostsecc
      @lostsecc  5 месяцев назад +4

      youtube & tryhackme & portswiggerlabs is enough

    • @REDCULT-is-Live
      @REDCULT-is-Live 5 месяцев назад

      ​@@lostseccyou're real gem 💎 dude

  • @jasonhudson8722
    @jasonhudson8722 Месяц назад

    I want to point out something, when you started putting the URLs in the burpsuite extension on some of them you added a space, that is the reason why many of them return invalid host name. you can clearly see that on the ones that don't have a space at the end the scan started normally, unlike the ones with the added space.

    • @lostsecc
      @lostsecc  Месяц назад +1

      ywah i know bro i noticed after making video ❤️

  • @Byrus_dsp
    @Byrus_dsp 5 месяцев назад +2

    Thank for your POC, It's very usefull.

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️😇

  • @crawdy1369
    @crawdy1369 5 месяцев назад +6

    Greatly underrated man,
    love the music ;)

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️😇

  • @mr-dark
    @mr-dark 5 месяцев назад +3

    Well done, what a wonderful thing ❤

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq so much brother ❤️

  • @HacknMate
    @HacknMate 5 месяцев назад

    OK, the good things first:
    1. Good Music
    2. Good walkthrough
    3. Good tool
    4. Good Browser Extension
    5. Good Burp Extension
    Now, the bad:
    This bug (unless you find something significant which you can exploit, and proof that can be exploited), will not be considered for bounty. Trust me, I've tried it in many many MANY programs and got all N/A, Info at best. However, this can help to enumerate more directories and find vulnerabilities inside them where others failed to look.

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      this is only effective if you find some sensitive directory there otherwise its not worth to report..

  • @user-id8sz3sm1b
    @user-id8sz3sm1b 8 дней назад

    Thanks for this video bro 😍

  • @IllllIIlIIllI
    @IllllIIlIIllI 5 месяцев назад +1

    amazing content dude, keep it up!

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq for supporting brother ❤️

  • @CapuiICazzu
    @CapuiICazzu 5 месяцев назад +2

    what i saw in this video was scanning - im not sure where the 1000$ is in there

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      by scanning this you also get sensitive files from the internal server

    • @shamim_12
      @shamim_12 5 месяцев назад +1

      thats just a clickbait to get views and clicks

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      google what is microsoft iis tilde vulnerability

    • @REDCULT-is-Live
      @REDCULT-is-Live 5 месяцев назад

      Information disclosure of sensetive data. ​@@shamim_12

  • @cjhackerz
    @cjhackerz 3 месяца назад

    I am doing it for "Educational Purposes" good vid, avoid this sound track if you care about monetization in future.

  • @mountainsoflavainc
    @mountainsoflavainc 5 месяцев назад

    nice video, good POC, i definitely find this cool, just getting more into ethical hacking and shit from game hacking, this is cool.

    • @lostsecc
      @lostsecc  5 месяцев назад

      yes bug hunting is cool field you can earn much money in bounty no any limits...

  • @nonidentified89
    @nonidentified89 5 месяцев назад +12

    Bro you are truly "GOD" love your work very very helpful ❤💯

    • @lostsecc
      @lostsecc  5 месяцев назад

      love you brother ❤️😇

    • @rahidislam8114
      @rahidislam8114 4 месяца назад

      so what is this actually?

  • @yungxxilax9194
    @yungxxilax9194 5 месяцев назад

    hey friend just asking, it does give you some money by just searching for vulnerable servers and then issuing a report for the owner? Or do you think BBP is better?

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      hunt on bugcrowd,hackerone,intigriti they will.pay you..

  • @CallMeZelax
    @CallMeZelax 5 месяцев назад +2

    that extension with the sql injection stuff?

    • @lostsecc
      @lostsecc  5 месяцев назад

      extension name: Hack tool

    • @REDCULT-is-Live
      @REDCULT-is-Live 5 месяцев назад

      And the URL extractor's name?​@@lostsecc

  • @monikasharma2931
    @monikasharma2931 5 месяцев назад +4

    Amazing tutorial 🎉❤

    • @lostsecc
      @lostsecc  5 месяцев назад

      😇❤️

  • @anonraxor317
    @anonraxor317 4 месяца назад

    when you pasting the links in burp, last portion of the link appears a space. thats why may be it shows scan interrupts

    • @lostsecc
      @lostsecc  4 месяца назад

      yes,brother ❤️

  • @paktiko1986
    @paktiko1986 5 месяцев назад +8

    amazing tutorial

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq so much bro 😇

    • @Hhz-jx7lp
      @Hhz-jx7lp 5 месяцев назад

      ​@@lostseccdo you know how to decrpyt and inercept all https(TLS 1.3) data in my wifi of my other devices

    • @Hhz-jx7lp
      @Hhz-jx7lp 5 месяцев назад +1

      ​@@lostseccand can you tell me ,all extensions in firefox you use

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      hacktool / link ghoper / find something /

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      use wireshark

  • @basroos_snafu
    @basroos_snafu 5 месяцев назад

    Remove the trailing spaces after pasting the url's for a 1000% more successfull scan attempt! Interesting video though!

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      thnq so much 😇❤️ i noticed that after video upload bcz i tried this first time so i did'nt notice that

  • @aran_farzami
    @aran_farzami 4 месяца назад

    May I ask, when you opened the sites you found with Durk, after that you found the Windows Server sites with a plugin??

    • @lostsecc
      @lostsecc  4 месяца назад

      you can find window iis vulnerability there

    • @aran_farzami
      @aran_farzami 4 месяца назад

      @@lostsecc I know, but how did you find the address of the Windows sites?

    • @aran_farzami
      @aran_farzami 4 месяца назад

      If you can give me your telegram ID, I can send you a message

    • @lostsecc
      @lostsecc  4 месяца назад

      @lostsec

    • @aran_farzami
      @aran_farzami 4 месяца назад

      @@lostsecc thanks

  • @n4yfreefire428
    @n4yfreefire428 Месяц назад

    name of extension that give you paths ?

  • @user-zc1mc5ml9v
    @user-zc1mc5ml9v 5 месяцев назад +1

    I have a problem with install shortscan can't i installed from github but can't build | i already have go please haw can i install it

    • @eyezikandexploits
      @eyezikandexploits 5 месяцев назад

      What error are you getting, maybe downlod the release compiled version

  • @Shortclipped
    @Shortclipped 5 месяцев назад +3

    Good stuff brother

    • @lostsecc
      @lostsecc  5 месяцев назад

      Thnq brother ❤️😇

  • @Lyrics04d
    @Lyrics04d 3 месяца назад

    Can you search for vulnerabilities in the termux terminal to start with the bonty bug?

    • @lostsecc
      @lostsecc  3 месяца назад

      i dont use that

    • @Lyrics04d
      @Lyrics04d 3 месяца назад

      @@lostsecc Ok and what do you recommend for me to start in that bug bonty world?

  • @main7737
    @main7737 5 месяцев назад

    If you are already aware, please ignore this:
    (Your IP is shown, if you are using VPN, then don't mind :) )

    • @lostsecc
      @lostsecc  5 месяцев назад

      yes its ip vanish vpn ip best one they dont share logs to anyone..

  • @kaminey9220
    @kaminey9220 5 месяцев назад +1

    Amazing video bro keep it up i learned somenew thing todya can i get those extension names ?

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq for supporting brother ❤️😇

  • @Rimuruux
    @Rimuruux 5 месяцев назад

    That terminal of yours is because you have a server or is it just Windows emulator of Linux Terminal?

    • @peptobepto
      @peptobepto 5 месяцев назад

      i think hes probably just using the linux subsystem for windows. Not a very good solution. If you wanna start pentesting, please just install parrot

    • @0xReedy
      @0xReedy 5 месяцев назад

      cmd with the baisects hookedup using the path should do if he cant operate 2 systems at once windows still up @@peptobepto

  • @HansSec
    @HansSec 5 месяцев назад

    Great video man.. Also, hpw are you using the httpx-toolkit command?? I want to useit but I find no way to install it and use it as you are, do you have the installation guide or any github repo where i can install it?? thanks man!

    • @lostsecc
      @lostsecc  5 месяцев назад

      just type sudo apt install httpx-toolkit that it

  • @enperuprithvi
    @enperuprithvi Месяц назад

    is this we can report as aa vulnerability in bug bounty program if possible wht is the ulernability name

    • @lostsecc
      @lostsecc  Месяц назад

      microsoft iis tild

  • @molotov5000
    @molotov5000 5 месяцев назад +1

    how did you make that thing in the cmd like what is coffinxp

    • @0xReedy
      @0xReedy 5 месяцев назад

      terminal but he changed background,name,icon it is indeed linux terminal

  • @58statment
    @58statment Месяц назад

    1:05 bro, what's the name of this extension..?

  • @SplinterAI
    @SplinterAI 5 месяцев назад

    Do you use a custom wordlist for this the scan?

  • @Elmoudix
    @Elmoudix 5 месяцев назад +1

    this song of mr robot ?

    • @lostsecc
      @lostsecc  5 месяцев назад

      yes

    • @Elmoudix
      @Elmoudix 5 месяцев назад

      forget forget

  • @LetsTryThisWay
    @LetsTryThisWay 4 месяца назад

    so, what is critical information we get from server this methode ?

    • @lostsecc
      @lostsecc  4 месяца назад

      internal sensitive files information disclosure

  • @SHINDE1RU
    @SHINDE1RU 5 месяцев назад +1

    Dude, i literally found like 10 min ago a IIS main page xD ill run this on it

    • @lostsecc
      @lostsecc  5 месяцев назад

      niceee ❤️🔥

    • @SHINDE1RU
      @SHINDE1RU 5 месяцев назад +1

      @@lostsecc quick question sir, turns out, those 2 IIS i found on a bug bounty program, were vulnerable to "iis tilde enumeration".
      Should i make like 2 reports or 1 report for the 2 urls? (different domains, but same program)

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      make two reports first day report one second day report another high chance for more bounty..make sure you find some senstive directory or files..

  • @Iampopg
    @Iampopg 3 месяца назад

    How are you using Linux terminal on windows?

    • @lostsecc
      @lostsecc  3 месяца назад

      its wsl2 kali

  • @IrishKingzz
    @IrishKingzz 5 месяцев назад

    Is that response headers bookmark for BHD?

    • @lostsecc
      @lostsecc  5 месяцев назад

      what is bhd ?

  • @cll00180
    @cll00180 5 месяцев назад +1

    amazing bro, keeps making videos

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      thnq brother ❤️😇

    • @user-hg8re3ql2k
      @user-hg8re3ql2k 5 месяцев назад

      hey why i find you in every pen testing video XDD

  • @vikaspatel8061
    @vikaspatel8061 3 месяца назад

    Shortscan is not working in mine system , can you please guide me for that

    • @lostsecc
      @lostsecc  3 месяца назад

      dm me in telegram @lostsec

  • @bugbouty
    @bugbouty 4 месяца назад

    what is the extention name u used for extract subdomains

  • @UrRealestCritic
    @UrRealestCritic 5 месяцев назад +1

    Are you using a virtual machine ?? Good video bro

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      no, its wsl2 with kali linux

  • @r3plican
    @r3plican 2 месяца назад

    what plugin u use that for payload sql

    • @lostsecc
      @lostsecc  2 месяца назад

      what plugin

    • @r3plican
      @r3plican 2 месяца назад

      @@lostsecc in ur firefox, that u input sql

  • @sigmadetected7270
    @sigmadetected7270 3 месяца назад

    Bro, I don't know why but shortscan is not working, showing fatal error, not connecting to server. Please help bro

    • @lostsecc
      @lostsecc  3 месяца назад

      uninstall and install again

    • @lostsecc
      @lostsecc  3 месяца назад

      maybe bcz of missing packages

  • @embededmind418
    @embededmind418 5 месяцев назад

    Everything's fine but why you are using that bloated spyware of gill bates..?

  • @NotToBeTooTakenSeriously
    @NotToBeTooTakenSeriously 5 месяцев назад

    what linux subsystem are you using?

  • @ichibot-app
    @ichibot-app 5 месяцев назад

    My fav part was when you just exposed your IP address on the captcha

    • @lostsecc
      @lostsecc  5 месяцев назад

      you think i am skidd ? 😂 thats my ip vanish vpn ip 😉

    • @ichibot-app
      @ichibot-app 5 месяцев назад

      @@lostsecc it literally says comcast lol

    • @XaxxyJones
      @XaxxyJones 5 месяцев назад

      @@lostsecc Since when do ip vanish own comcast ips lol but well done providing the extact time and date that dynamic ip was used I'm sure you will recive a letter in the mail soon ;)

    • @lostsecc
      @lostsecc  5 месяцев назад

      it was not mine isp ip its from vpn bruhh i checked it.. they also provide anonymous security..

    • @ichibot-app
      @ichibot-app 5 месяцев назад

      @@lostsecc lmao it's comcast... they have a direct agreement with NSA.... since they are a US company lmao

  • @user-pe1og1vs5x
    @user-pe1og1vs5x 3 месяца назад

    mereko yahi same bug mila isme ham shortscan ka screenshort laga sakte hai

  • @lyxcheats
    @lyxcheats 5 месяцев назад +1

    extensions names? please

  • @curated_euphoria_experience
    @curated_euphoria_experience 5 месяцев назад

    Bro. What are the mozilla plugins u have installed

    • @lostsecc
      @lostsecc  5 месяцев назад

      i will share all.list soon

  • @erxic
    @erxic 5 месяцев назад +1

    Who do you report finding this bug to? Microsoft or the government or who?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      i just made it for yt

  • @harshh25.02
    @harshh25.02 5 месяцев назад +1

    amazing. can you share your terminal background

    • @lostsecc
      @lostsecc  5 месяцев назад

      walpaper ? or theme

    • @harshh25.02
      @harshh25.02 5 месяцев назад

      that skull background
      @@lostsecc

    • @lostsecc
      @lostsecc  5 месяцев назад

      www.pinterest.com/pin/653514595912182033/

  • @kokurate
    @kokurate 5 месяцев назад

    That's very great video, anw could you share your extensions when doing bug bounty ?

    • @lostsecc
      @lostsecc  5 месяцев назад

      i will share in my telegram channel

    • @kokurate
      @kokurate 5 месяцев назад

      @@lostsecc that's very quick respond, anw looking forward for this xD

  • @CHOLOSOC
    @CHOLOSOC 2 месяца назад

    Any guide to setting up windows😊

  • @SankalpaBaral1337
    @SankalpaBaral1337 5 месяцев назад

    Great content brother.

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq so much brother ❤️

  • @f4b1022
    @f4b1022 5 месяцев назад

    u Just gained a sub

    • @lostsecc
      @lostsecc  5 месяцев назад

      my pleasure ❤️😇

  • @ahmedlotfy9071
    @ahmedlotfy9071 5 месяцев назад +2

    Keep going , thanks for sharing ❤

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      ❤️😇

  • @lukasweickert1841
    @lukasweickert1841 5 месяцев назад

    what is the add on u used at 15:44?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      Hack tools extension

  • @iq_rasco
    @iq_rasco 5 месяцев назад

    I am having difficulty installing the tool. Can you help me please?

  • @user-in2jf7tx1q
    @user-in2jf7tx1q 5 месяцев назад

    bro stop using automated tools and templates, show us your craft by 0days on the shell hard coded then Mr.Robot song theme will get along, anyway nice work buddy keep up 👍

    • @lostsecc
      @lostsecc  5 месяцев назад

      in have surprise for you soon i will post some mr robot thing in community tab

    • @user-in2jf7tx1q
      @user-in2jf7tx1q 5 месяцев назад

      @@lostseccyeah bro keep inspiring me

  • @kingofgaming6743
    @kingofgaming6743 5 месяцев назад

    what WSL u using?

  • @AzriRich88
    @AzriRich88 5 месяцев назад

    Nice! Cool bro!

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq bro ❤️

  • @itsm3dud39
    @itsm3dud39 5 месяцев назад +1

    is this similar to directory bruteforcing??

    • @lostsecc
      @lostsecc  5 месяцев назад

      ys

    • @itsm3dud39
      @itsm3dud39 5 месяцев назад

      ok@@lostsecc 👍

    • @0xReedy
      @0xReedy 5 месяцев назад

      but what are the links you got in the end of the video ? i didnt get it is it like leaked users data or something ?@@lostsecc

    • @lostsecc
      @lostsecc  5 месяцев назад

      yes its leaked sensitives files of internal server..

    • @d4nm4c
      @d4nm4c 5 месяцев назад

      Seemed like you weren’t authenticated to any of the sensitive data. What is the IIS vulnerability you were exploiting? Was it just to files that are supposed to require auth but weren’t?

  • @IlIIllIlIlIIlIlIlIlIIl
    @IlIIllIlIlIIlIlIlIlIIl 5 месяцев назад

    You consider yourself a skid? I want to know if this is real stuff like a stuff a hker can do cuz it seem like you got some knowledge but your using other people tools soo yeah i mean it still counts as skid? I sure that i am not better than you but just wandering if its still count as a skid thing?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      i got many halloffames not by using these tools..i also do manual testing but for some task you need tools bcz that is part of hunting all people use tool like subdomain finder httpx waybackurls so without tool you can go in deep hunting...but dont relay only on tool..

    • @0xReedy
      @0xReedy 5 месяцев назад

      what do you mean by manual testing can you explain it if you dont mind :)
      @@lostsecc

  • @netor-3y4
    @netor-3y4 5 месяцев назад

    how many time to find target like dis

    • @lostsecc
      @lostsecc  5 месяцев назад

      just found randomly

  • @korea7moda
    @korea7moda 5 месяцев назад +1

    good luck 😊

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      😇❤️

  • @sovenok-hacker
    @sovenok-hacker 5 месяцев назад

    5:12 There is a space in URL ;)

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      yes bro i noticed ❤️

  • @JOAKNG
    @JOAKNG 5 месяцев назад

    after getting all these links whats the point? Im not a bug bountier is it worth?

    • @lostsecc
      @lostsecc  5 месяцев назад

      you will find some internal sensitive files and directory by this..

    • @0xReedy
      @0xReedy 5 месяцев назад

      so these links are indeed users pages but you gain access on them ?@@lostsecc

  • @thereisnotomorrow0
    @thereisnotomorrow0 5 месяцев назад

    bro go install not worrking could you help me how to install tool

    • @lostsecc
      @lostsecc  5 месяцев назад

      maybe verison issue dm me in telegram @lostsec

  • @christiancepeda5457
    @christiancepeda5457 5 месяцев назад

    can you pleae share that skull image in your terminal?! that is AMAZING

    • @lostsecc
      @lostsecc  5 месяцев назад

      msg me in telegram @lostsec

    • @christiancepeda5457
      @christiancepeda5457 5 месяцев назад

      @@lostsecc i can't find you. that username doesn't exist :/

    • @lostsecc
      @lostsecc  5 месяцев назад

      t.me/lostsec

  • @taktycznybsp5262
    @taktycznybsp5262 5 месяцев назад

    Can you give the name of extensions on your browser? I want to test them

  • @ace-veen35
    @ace-veen35 4 месяца назад

    Mr Robot Music nice

  • @user-pe1og1vs5x
    @user-pe1og1vs5x 3 месяца назад

    but url says 403 Forbidden

    • @lostsecc
      @lostsecc  3 месяца назад

      yeah ignore that if you want you can bypass but they will not bypass easily so..better to focus on other domain

  • @Fractal_reComm
    @Fractal_reComm 5 месяцев назад

    namoral sou mt seu fã mno palavra de hqk4r obg pelo conteudo

  • @user-in2jf7tx1q
    @user-in2jf7tx1q 5 месяцев назад

    and last thing please don't use gui precisely burpsuite, try to do it on the terminal it's way cooler

  • @sammy49668
    @sammy49668 5 месяцев назад

    where did u learn bug hunting brother??

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      google & linkdin & twitter & medium & portswigger academy & tryhackme & bwapp & youtube & github

  • @VibeVisions950
    @VibeVisions950 3 месяца назад

    Interesting ...❤

  • @alhussienalshorman5128
    @alhussienalshorman5128 5 месяцев назад

    Toji u r the best, How i can install shortscan

    • @lostsecc
      @lostsecc  5 месяцев назад

      github.com/bitquark/shortscan

  • @muhammadharis2212
    @muhammadharis2212 5 месяцев назад +1

    Great thanks

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️😇

  • @valona4432
    @valona4432 3 месяца назад

    Love the music

    • @lostsecc
      @lostsecc  3 месяца назад +1

      ❤️

    • @valona4432
      @valona4432 3 месяца назад

      @@lostsecc bro i want a roadmap to pearn this things can you tell me

  • @randomdudefpv4927
    @randomdudefpv4927 5 месяцев назад

    5:00 - those domains were working, but that space after pasting ruined everything :D

    • @lostsecc
      @lostsecc  5 месяцев назад

      yes i noticed it bro ❤️

  • @user-cl8gr1sy8i
    @user-cl8gr1sy8i 5 месяцев назад

    lol the reason you get invalid host is probably due to the space after the url

    • @lostsecc
      @lostsecc  5 месяцев назад

      yes i noticed bro ❤️

  • @naveenrawat1549
    @naveenrawat1549 Месяц назад

    Wait this is vulnerability 😮😮 i got iis server of a domain but I thought this nothing to report but what, and one thing this is it ? I mean what next ? And can you tell me what extensions you are using !!!

    • @lostsecc
      @lostsecc  Месяц назад

      just use shortscan with -F flag and after getting dir or file link open it

    • @naveenrawat1549
      @naveenrawat1549 Месяц назад

      @@lostsecc is that it ??

    • @aasislimbu4961
      @aasislimbu4961 Месяц назад

      @@naveenrawat1549 don't do this kind of bullshits in random websites like this lostsec guy. Just a waste of time and this video is all clickbait.

  • @ferdiaek5557
    @ferdiaek5557 4 месяца назад

    isnt it better to use shortscan ?

    • @lostsecc
      @lostsecc  4 месяца назад +1

      alrady use in this video

    • @ferdiaek5557
      @ferdiaek5557 4 месяца назад

      @@lostsecc my bad mate

    • @ferdiaek5557
      @ferdiaek5557 4 месяца назад

      @@lostsecc can you tell me whats the extension you are using ?

    • @lostsecc
      @lostsecc  4 месяца назад +1

      its link gopher and find something and hacktools.

    • @ferdiaek5557
      @ferdiaek5557 4 месяца назад

      @@lostsecc appreciate it mate

  • @someyounggamer
    @someyounggamer 2 месяца назад

    I need a pro burp

    • @lostsecc
      @lostsecc  2 месяца назад +1

      dm me in telegram

  • @alimo584
    @alimo584 5 месяцев назад

    Bro
    How you find subdomain in begning scan

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      subfinder -d domain.com -all -recursive -o subdomains.txt

  • @dangerboys4866
    @dangerboys4866 5 месяцев назад

    Hello bro can you teaching me web application penetration testing

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      learn from portswigger academy free

  • @eobardthawnemcoc
    @eobardthawnemcoc 5 месяцев назад

    what extensions are you using

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      find something & hack tool

    • @eobardthawnemcoc
      @eobardthawnemcoc 5 месяцев назад

      thank you@@lostsecc

    • @lostsecc
      @lostsecc  5 месяцев назад

      addons.mozilla.org/en-US/firefox/addon/findsomething/

  • @SalamSalamli-ex3tm
    @SalamSalamli-ex3tm 5 месяцев назад

    bro could you share this tool i try to install with 'go install' but this is not working

    • @lostsecc
      @lostsecc  5 месяцев назад

      direct install binary and move to /usr/local/bin

    • @SalamSalamli-ex3tm
      @SalamSalamli-ex3tm 5 месяцев назад

      @@lostsecc I don't quite understand what you mean.should I clone the tool with "git clone" and then mv it to /usr/local/bin?

    • @SalamSalamli-ex3tm
      @SalamSalamli-ex3tm 5 месяцев назад

      I don't understand what you mean, should install the tool with 'git clone' and then mv /usr/local/bin?@@lostsecc

  • @ygx6
    @ygx6 5 месяцев назад

    is that.. comic sans..

  • @user-ec3jo9nb3c
    @user-ec3jo9nb3c 5 месяцев назад

    how to use this terminal, cmd on windows bro thanks in advance

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      goto microsoft store install window terminal and then install wsl2 with kali linux from microsoft store

  • @blackking8919
    @blackking8919 5 месяцев назад

    We can really earn or it's depends on possibilities bro??

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      its depend on your hardwork and passion only

    • @blackking8919
      @blackking8919 5 месяцев назад

      @@lostseccif you don't mind can i know how much you earn bro?😅

    • @user-ge7ep5sc2d
      @user-ge7ep5sc2d 5 месяцев назад

      ​@@lostsecc.

  • @hertzvibe3798
    @hertzvibe3798 5 месяцев назад

    extensions?? please

    • @lostsecc
      @lostsecc  5 месяцев назад

      i wil share list