Это видео недоступно.
Сожалеем об этом.

Reflected xss that made 500$ Bounty | Bug bounty poc

Поделиться
HTML-код
  • Опубликовано: 21 июн 2024
  • // Disclaimer //
    Hacking without permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing & bug hunting so that we can protect ourselves against the real hackers..

Комментарии • 245

  • @user-gc6gp7cm9c
    @user-gc6gp7cm9c Месяц назад +7

    First time aisa bnda dekha jo tny views or subscriber hony k bawjuud b hr comment k reply deta hy❤

    • @lostsecc
      @lostsecc  Месяц назад +3

      always ❤️😇🤗

  • @DeeJay2000
    @DeeJay2000 Месяц назад +26

    Watching your video feels demotivated sometimes. You found so many bugs and i didn't even find a single one

    • @lostsecc
      @lostsecc  Месяц назад +22

      no bro,i have just passion to try new things evryday i dont hunt more i research more and i love that...

    • @ashishchauhan9745
      @ashishchauhan9745 Месяц назад +1

      same

    • @Free.Education786
      @Free.Education786 Месяц назад

      😂🎉❤

    • @aasislimbu4961
      @aasislimbu4961 Месяц назад +1

      @@ashishchauhan9745 You think a bug bounty program would have an xss on their main page. This isn't even a reflected xss. Not to mention, lostsec probably didn't got any bounty. Everything's clickbait .Have you seen any proof in any of his videos of him getting bounty?. So don't get demotivated. lostsec just pastes a bunch of payload in random websites and posts the video and bros methodology is just running tools.

  • @lostsecc
    @lostsecc  Месяц назад

    for payloads check out telegram channel:
    t.me/lostsec

  • @cameronribeiro9660
    @cameronribeiro9660 Месяц назад +1

    Lostsec: one thing: if in all your videos your just using wsl and browser: you said you just got new msi thin 15: leave your previous laptop as is with windows host and wsl: and grab another NVMe: Install Ubuntu host: put VB on it: make a Ubuntu VM (so you can clone in case anything goes wrong) and do everything your doing in the Ubuntu VM. Then you have the Linux terminal and still have whatever web browser you want. Windows as a host runs Ubuntu VM slow, but if Ubuntu is both your host and VM, the VM is fast. Also for everyone: Kali is designed to only be run as a VM or as instance on aws ec2. No one at OFSEC will recommend you run Kali bare metal. But for reliability: you will probably have easier time with Ubuntu or Fedora. Even to the point all the RHEL guys are starting to switch to Ubuntu.

    • @lostsecc
      @lostsecc  Месяц назад

      kali have its own updated repo and many tools preinstalled in that repo so dont need to download it from other sources..your all things are updated like latest kernal and all stufss in kali.in ubunto you need download all tools from other source s..

    • @cameronribeiro9660
      @cameronribeiro9660 Месяц назад

      @@lostsecc Honored I got a reply from you! Yeah I have a Kali, Ubuntu, and W11 VM. Is it just me or are PATHs for both Go and Python annoying in Linux? I have one Kali VM then I will not let anything happen to because I was able to get a specific scanner installed in my favorite scanner. I have not been able to install the same scanner in any other Linux VM I have. But also: I think I see you’re using Windows 10. I have been able to get the base Ubuntu installed in wsl (whichever one they automatically install when they install wsl), and I was able to get Ubuntu 24.04 and also wsl Fedora installed. But so far in windows 11 as a bare metal install, Kali rolling just doesn’t want to install. But yeah: it seems all the strictly cyber guys are in Kali, and all the former devs/programmers are all in Ubuntu. But now it’s seeming more and more popular to run W with wsl. I think the real challenge all beginners are gonna have to overcome is: literally every “hacker” I know of: does it differently: everyone pretty much has to develop their own “method”. And then what’s gonna piss a lot of them off is that some of the guys who started in the mirror early 90s still today a little python But not that much. And they all made most of their money in the days when Yahoo was it.

  • @suyashpjadhav
    @suyashpjadhav Месяц назад +1

    New setup has a big screen ❤❤

  • @baraamansi7637
    @baraamansi7637 Месяц назад +1

    Nice finding bro ,However what is the impact since it can't be delivered to vicitm

    • @lostsecc
      @lostsecc  Месяц назад

      no much its post xss

  • @Charlieop2
    @Charlieop2 Месяц назад +2

    Payload kaha sei mila

  • @ali_aqeel
    @ali_aqeel 23 дня назад

    My brother, where can I find the six bylaw xss? I couldn’t find him even on Telegram. Can you send him via comment or write his name?

    • @ali_aqeel
      @ali_aqeel 22 дня назад

      I would like you to respond to the comment, where can I find the xss plugin that I tried on?

  • @Ajay_Yadav_Smart
    @Ajay_Yadav_Smart Месяц назад +1

    Bro You uploaded a video yesterday and your video got deleted today.
    Would you like to upload that video on your Telegram channel?.

  • @speedyfriend67
    @speedyfriend67 Месяц назад +1

    How to distinguish between stored and reflected xss?

    • @lostsecc
      @lostsecc  Месяц назад +1

      reflected means only its reflect on client side only..in stored its stored in databse of website

    • @speedyfriend67
      @speedyfriend67 Месяц назад

      @@lostsecc ohhh so I think i found a stored XSS On websites
      Thanks for the info :)

  • @gamingandtech5151
    @gamingandtech5151 Месяц назад +1

    Good job! I cant even get a single bounty lol.

    • @lostsecc
      @lostsecc  Месяц назад +1

      u will get keep going ❤️

  • @Corona13mx
    @Corona13mx Месяц назад

    I’m new and wanting to learn, sorry if it sounds nooby. My question is why is it significant what you found? What can be done with the two things that came up? Anything I can read that you recommend?

    • @lostsecc
      @lostsecc  Месяц назад +3

      account takeover if its reflected in url parameter

    • @LeBigKoklm
      @LeBigKoklm Месяц назад

      @@lostsecc with what knowledge do you end with this ?

    • @Henry-ue6hh
      @Henry-ue6hh 29 дней назад

      @@lostsecc but it does not seem like these xss are in the url parameter in the video

  • @akashpokemonhunter7502
    @akashpokemonhunter7502 Месяц назад +1

    Bro give me a guide pr roadmap of yours u followed to become a professional bug Bounty hunter bro tell me the books and resources and course u have finished for this

    • @lostsecc
      @lostsecc  Месяц назад +4

      just read some yt theory video understand the concept after that solve portswigger labs then read some writups or hackerone reports..

  • @Brutalslayer69
    @Brutalslayer69 Месяц назад

    Basically those where multiple xss bugs in one input field did you report them all at once??

  • @mistDexploit
    @mistDexploit Месяц назад

    nice bro keep going and upload videos Daily I'll support you
    but please share your play list even a screen shot from your musics is okay I'll search them by my self (:

    • @lostsecc
      @lostsecc  Месяц назад +2

      dark beach slowed

  • @tomiwafalade5480
    @tomiwafalade5480 Месяц назад

    I must commend your consistency 🙌

  • @BMV-kl1br
    @BMV-kl1br Месяц назад +1

    can i get those payloads that u using ?? on this video

    • @lostsecc
      @lostsecc  Месяц назад

      check telegram bro

    • @BMV-kl1br
      @BMV-kl1br Месяц назад

      @@lostsecc didnt got brother

  • @user-rg8wu2gk3d
    @user-rg8wu2gk3d Месяц назад

    Nice work bro keep going.. Love from Pak

    • @lostsecc
      @lostsecc  Месяц назад

      my pleasure brother ❤️😇🤗

  • @endless2333
    @endless2333 Месяц назад

    Hey lostsec, will you upload the ffuf video again? Saw that this amazing platform removed 😂
    Thanks

    • @lostsecc
      @lostsecc  Месяц назад +1

      its in review hope its back ❤️

  • @ArchSzzK
    @ArchSzzK Месяц назад

    Could you please tell about your new lap
    I'm planing to buy one or can u suggest one

    • @lostsecc
      @lostsecc  Месяц назад

      msi thin 15 bestt and light weight

    • @ArchSzzK
      @ArchSzzK Месяц назад

      @@lostsecc thanks a lot brother

  • @frandaurat
    @frandaurat Месяц назад

    do you recomend to start on a VDP, gain some reputation and then go to private programs, or just start on public BBPs

    • @lostsecc
      @lostsecc  Месяц назад

      try according to your skills if u have good skills why not hunt on bbp but yeah u can start with vdp but dont invest muvh time on these..

    • @frandaurat
      @frandaurat Месяц назад

      @@lostsecc ok thx bro for everything :)

    • @ali_aqeel
      @ali_aqeel 23 дня назад

      ​@@lostsecc My brother, what is BBP and VDP?

    • @lostsecc
      @lostsecc  23 дня назад

      bbp:bug bounty program where u get money paid if you found bug
      vdp&rvdp:its responsible disclosure programs where u did'nt get anything paid just points or hof

  • @Ronjit-n9q
    @Ronjit-n9q Месяц назад

    bro great ❤️❤️.bro please give some beginner friendly video so that fresher like me can find some love you ❤️❤️🥰

    • @lostsecc
      @lostsecc  Месяц назад

      just stay with channel and telegram i will upload all

  • @behenuemichael6051
    @behenuemichael6051 Месяц назад

    which sites you recommend for bug bounty for begginners ? I mean are there any sites that include programs that are more likely to have vulnerabilities or easy to find vulnerabilities ?

    • @lostsecc
      @lostsecc  Месяц назад +1

      portswigger lab is best for upgrade your skills bro..

  • @anuzravat
    @anuzravat Месяц назад

    why havent lapinoz fixed it yet

    • @lostsecc
      @lostsecc  Месяц назад

      some company dont care about there security

  • @enperuprithvi
    @enperuprithvi Месяц назад

    If it is ok you can share the payload for our reference

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram channel must check

  • @gregorygarcia6819
    @gregorygarcia6819 Месяц назад

    Like to learn how to get started

    • @lostsecc
      @lostsecc  Месяц назад

      i shared path in telegram channel must check

  • @eduardosaavedra5359
    @eduardosaavedra5359 Месяц назад

    Hi, bro. I'm trying to start in this world. One question: where or how do you report that vulnerability?

    • @lostsecc
      @lostsecc  Месяц назад

      use hunter.io extension

    • @eduardosaavedra5359
      @eduardosaavedra5359 Месяц назад

      ​@@lostsecc Ok. But I understand that hunter looks for email addresses, so how did you know which one of them to send the report to or what did you do with the extension? Also, how did you know that there was a rewards program for that vulnerability? Sorry, it's just that I have a lot of questions. 😅 I would apreciate it if you could help me.

    • @lostsecc
      @lostsecc  Месяц назад

      there is option for that and show you also support email just report on that

    • @eduardosaavedra5359
      @eduardosaavedra5359 Месяц назад

      @@lostsecc Oh, got it. Thank you so much!

  • @aasislimbu4961
    @aasislimbu4961 Месяц назад +1

    They don't even have a bug bounty program and if they had they wouldn't have self xss on their main page. This isn't even a reflected xss. Not to mention, You probably didn't got any bounty. Everything's clickbait.

    • @lostsecc
      @lostsecc  Месяц назад

      yes its clickbait

    • @aasislimbu4961
      @aasislimbu4961 Месяц назад +1

      @@lostsecc Just a simple payload alert(3) is working, that means your other payloads are useless except for one payload. What is the benefit if you bypassed the cloudflare but your payload isn't executing. If you are truly passionate about hacking, you should stop wasting your time on copy pasting useless payloads and learn some real hacking.

    • @lostsecc
      @lostsecc  Месяц назад

      i know that this only for this video..so you all got idea..

  • @vennividdivicci
    @vennividdivicci Месяц назад

    Those payloads not icluded on ur github repo

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram bro

  • @byte-sec
    @byte-sec Месяц назад

    Previous month, I reported around 8 RXSSes :)

  • @zedvn3792
    @zedvn3792 Месяц назад

    Why is it Reflected I don't even see it on the url
    How can you expose the victim to XSS of this type?

    • @lostsecc
      @lostsecc  Месяц назад

      its post based xss

  • @patrickdibia4898
    @patrickdibia4898 Месяц назад

    Nice video bro, can you share your xss payload list?

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram bro

  • @EntertainmentRT
    @EntertainmentRT Месяц назад

    Bro please do video about ur new pc

  •  Месяц назад

    Hey man, could you share your xss cheatsheet?

  • @garrinormanivannacov370
    @garrinormanivannacov370 Месяц назад

    I love this, plis share how to hunt with dorking my brother 🙏

    • @lostsecc
      @lostsecc  Месяц назад

      join telegram brother i shared there all..

  • @nerdimmortal
    @nerdimmortal Месяц назад

    hello bro first of all thank of providing this kind of valuable content . brother while on a a program i found a ftp access of a third party website now iam confused what can i do with that because that company does't have b.b program

    • @lostsecc
      @lostsecc  Месяц назад

      you can upload shell and get full system access

    • @nerdimmortal
      @nerdimmortal Месяц назад

      @@lostsecc thanks for replying but as I said they didn't have any active bug bounty program 😕

    • @lostsecc
      @lostsecc  Месяц назад

      noprbm just report them on there support email

    • @nerdimmortal
      @nerdimmortal Месяц назад

      @@lostsecc ohkk thanks sir 🙂

  • @user-gc6gp7cm9c
    @user-gc6gp7cm9c Месяц назад

    Superb, sir i am beginner please suggest me a yt channel in hindi for clear my concepts

    • @lostsecc
      @lostsecc  Месяц назад

      just read writups or hackerone reports are better..

  • @H4cker_Nafeed
    @H4cker_Nafeed Месяц назад

    That isn't self xss ? Coz there was nothing changing in the url ? If its a self xss then how do they get accepted this ?

    • @lostsecc
      @lostsecc  Месяц назад

      yes its self xss bro

    • @H4cker_Nafeed
      @H4cker_Nafeed Месяц назад

      @@lostsecc then how did they get this accepted ?

    • @lostsecc
      @lostsecc  Месяц назад

      @@H4cker_Nafeed click bait brother 😉❤️

    • @H4cker_Nafeed
      @H4cker_Nafeed Месяц назад

      @@lostsecc Nice IQ

  • @Loading_Code
    @Loading_Code Месяц назад

    Bro aap kitna time dete ho

  • @mnsds1332
    @mnsds1332 Месяц назад

    what you suggest for starters and which roadmap is good for you?

    • @lostsecc
      @lostsecc  Месяц назад +2

      portswigger

    • @mnsds1332
      @mnsds1332 Месяц назад

      @@lostsecc thnx bro

  • @the_sandman00
    @the_sandman00 Месяц назад

    Can we get the list of waf bypass payloads?

  • @JehraMehraj
    @JehraMehraj Месяц назад

    Bro i have watched your vedios of recon ( bug bounty vedo 1 & 2 ). I followed that..now i am stuck what to do with this information. Like js etc. i am a beginner and we dont know this . Plz help us about this. You r the only hope now. I have requested so many youtubers about this but no one replied. Plz help . How to proceed ahead further. Thankyou very much bro for your all efforts.

    • @lostsecc
      @lostsecc  Месяц назад

      after collecting js file use secret finder or you can directly send that urls with .js in nuclei they will automate find all keys..

    • @JehraMehraj
      @JehraMehraj Месяц назад

      @@lostsecc yes bro I did that , as I said I have followed your all steps and also found some keys like heroku api keys something like that. What can I do with those keys. Is that any vulnerability. Whats the use use of those keys. Sorry for wasting your precious time for this silly questions but bro you are my only mentor now. Can't explain your greatness in words as you are helping the beginners like us. Thankyou.

  • @kapilrawat3848
    @kapilrawat3848 Месяц назад

    bro, i need that payload list that you used for xss

    • @lostsecc
      @lostsecc  Месяц назад +1

      check telegram bro in media ❤️

  • @amansubedi538
    @amansubedi538 Месяц назад

    Good Job brother keep it up❤

  • @MihneaGurzau
    @MihneaGurzau Месяц назад

    Hello, can you put your xss scripts available for us it will help a lot please😊😅

    • @lostsecc
      @lostsecc  Месяц назад

      alrady shared bro in telegram must check

  • @aashishsubedi9144
    @aashishsubedi9144 Месяц назад

    name of background music ?

    • @lostsecc
      @lostsecc  Месяц назад

      dark beach slowed

  • @shishir8854
    @shishir8854 Месяц назад

    Bro could you share that xss payload cheat sheet please

    • @lostsecc
      @lostsecc  Месяц назад +1

      i shared in telegram channel bro

  • @madlad_.
    @madlad_. Месяц назад

    Bro give that notebook

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram bro

  • @studiospan6426
    @studiospan6426 Месяц назад

    Hey Nice Find though based on above video it looks like self XSS and did the company really rewarded for it? Also i checked the website and i see that the issue is still reproducible and haven't fixed yet the company awarded you before even fixing the bug that's too kind lol 😂. Bro Please tell me from where you find your targets to test i reported too reflected xss on bug crowd and they are in triaged state for 1 month 😢. idk if they forgot it or what...

    • @lostsecc
      @lostsecc  Месяц назад

      bro thats clickbait all people do so the video goes to more audidence ❤️

    • @studiospan6426
      @studiospan6426 Месяц назад

      @@lostsecc Ok though I will advice not to do that as it misleads people into believing bug bounty is easy and they can earn a living out of it just by running some automated tools and not learning base of it. "You must learn to make it before break it"

    • @lostsecc
      @lostsecc  Месяц назад

      all big youtuber use man..and its not fake if u find same in bbp you will get i just share the methodlogy..

    • @studiospan6426
      @studiospan6426 Месяц назад

      @@lostsecc yes I admit your recon and automation workflow videos are actually quite good but what I meant to say is many people think bbp is get rich quick skim by hearing from bounty news from other youtubers. So we shouldn't fool them just an opinion obviously it's your channel and video who am I tell...

    • @lostsecc
      @lostsecc  Месяц назад

      just active on twitter you will know how people earning from this daily...

  • @khanshaheb4500
    @khanshaheb4500 Месяц назад

    Your payload is not working now.

  • @Raduim
    @Raduim Месяц назад

    Congratulations 🎉👏

  • @Pal0vieeee
    @Pal0vieeee Месяц назад

    Yrr aapki payload list send krdo plzz ❤ ur genius man ... ❤

    • @lostsecc
      @lostsecc  Месяц назад +1

      check telegram in media tab i shared all..

  • @alvindhiyaulhayyi4902
    @alvindhiyaulhayyi4902 Месяц назад

    Can you share payload list??

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram bro check out

  • @travel..editor
    @travel..editor Месяц назад

    Bro how to bypass filters.

    • @lostsecc
      @lostsecc  Месяц назад

      learn some waf evasion technique

  • @pranjalibhatkar145
    @pranjalibhatkar145 Месяц назад

    Aap reply karte hai jo apko dusro se bahut alag banaati hai

    • @lostsecc
      @lostsecc  Месяц назад

      my pleasure ❤️😇

  • @khalidelgazzar4601
    @khalidelgazzar4601 Месяц назад

    Could you share your payloads

    • @lostsecc
      @lostsecc  Месяц назад +1

      check telegram

  • @rajivshrestha6972
    @rajivshrestha6972 Месяц назад

    can you provide that bypass payload

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram must check

  • @redmi9-t3n
    @redmi9-t3n Месяц назад

    can you please make a video about sql injection

    • @lostsecc
      @lostsecc  Месяц назад

      sqlinjection not allowed in yt they give strike for such video

  • @shahriar0x013
    @shahriar0x013 Месяц назад

    Can we get that different payloads list?

    • @lostsecc
      @lostsecc  Месяц назад

      check telegram bro

  • @im_szaby9190
    @im_szaby9190 Месяц назад

    Is there any way to bypass html entities?

  • @Sakuraigi
    @Sakuraigi Месяц назад

    How did you find the target?

    • @lostsecc
      @lostsecc  Месяц назад

      just passion to explore things..

  • @user-gc6gp7cm9c
    @user-gc6gp7cm9c Месяц назад

    Or yeh b kindly bta den k konsa payload kahan apply krna hy please sir

    • @lostsecc
      @lostsecc  Месяц назад +1

      check sourcecode and check what payload encoding there or bypass and try according to that..

  • @IBO.ATTACKS
    @IBO.ATTACKS Месяц назад

    my bro where i found their bug bounty program cause i found a vulnerability😇

    • @lostsecc
      @lostsecc  Месяц назад

      use google dork if there is any bbp and if not use hunter.io extension and extract email id and send to them..

    • @IBO.ATTACKS
      @IBO.ATTACKS Месяц назад

      @@lostsecc I found 2 Emails only
      ok I will send to them Thnnx🙂

  • @HelloWorld-hv5gx
    @HelloWorld-hv5gx Месяц назад

    can i get the payload list

  • @Amitte424
    @Amitte424 Месяц назад

    Bro isn’t this a self xss?? And they paid you for this😮

  • @Sidharthas89
    @Sidharthas89 Месяц назад

    Love you content brother❤❤❤❤

  • @mirpurpigeons1777
    @mirpurpigeons1777 Месяц назад

    Pls Share these payload 😢

    • @lostsecc
      @lostsecc  Месяц назад +1

      check telegram channel

  • @theinformer4421
    @theinformer4421 Месяц назад

    How do you find website for bbp ? I

    • @lostsecc
      @lostsecc  Месяц назад

      i just test when i have time and try something..

  • @mangaldeeppaul6541
    @mangaldeeppaul6541 Месяц назад

    wo jitney bhi payloads hey..channel mey dijiye na

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram check out ❤️

  • @RAS02023
    @RAS02023 Месяц назад

    Music name❤❤❤????

    • @lostsecc
      @lostsecc  Месяц назад

      dark beach slowed

  • @codewithyuvi24
    @codewithyuvi24 14 дней назад +1

    Bhai mai kasam kha ka such bol rha hu aaj sa 5-6 mahina pahila ya vernability meko mil gai thi is site pai mai email kiya call kiya kcuh reply nhi aya inka at the end maina ignore kar diya tah self xss samjh ka

    • @lostsecc
      @lostsecc  13 дней назад +1

      yeah its still self xss

    • @codewithyuvi24
      @codewithyuvi24 13 дней назад

      @@lostsecc to fir bhai tumna titel mai bunty likha ha ??

  • @yahai_
    @yahai_ Месяц назад

    Your videos are amazing, keep it up, can you share the payload? ❤❤

    • @lostsecc
      @lostsecc  Месяц назад +1

      in shared in telegram check out ❤️

    • @yahai_
      @yahai_ Месяц назад

      @@lostsecc nothing there

    • @lostsecc
      @lostsecc  Месяц назад +1

      @@yahai_ check media and check files and xss.txt

  • @ramshortseditz
    @ramshortseditz Месяц назад

    Bro sent their xss payload file.txt please...😊

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in tg channel bro check in media ❤️

    • @ramshortseditz
      @ramshortseditz Месяц назад

      @@lostsecc what is the channel

  • @jaywandery9269
    @jaywandery9269 Месяц назад

    could you share your payload

    • @lostsecc
      @lostsecc  Месяц назад +1

      i shared in telegram bro

    • @jaywandery9269
      @jaywandery9269 Месяц назад

      @@lostsecc okay, let me check. thanks

  • @Bizonlive
    @Bizonlive Месяц назад +1

    Self xss hai syad ??

    • @lostsecc
      @lostsecc  Месяц назад

      yes;)

    • @Bizonlive
      @Bizonlive Месяц назад +1

      @@lostsecc pkka self xss hai bro ???

  • @CyberSecHemmars
    @CyberSecHemmars Месяц назад

    Is this windows a VM?

  • @shanugupta9612
    @shanugupta9612 Месяц назад

    can i get that payloads

    • @lostsecc
      @lostsecc  Месяц назад

      check telegram channel

  • @bountyvitcim
    @bountyvitcim Месяц назад

    i need test payloads

    • @lostsecc
      @lostsecc  Месяц назад

      check my telegram brother ❤️

  • @eaglecyber
    @eaglecyber Месяц назад

    i need the payload : )

    • @lostsecc
      @lostsecc  Месяц назад

      i shared in telegram must check

  • @user-ju6fi7vh7n
    @user-ju6fi7vh7n Месяц назад

    Awesome

  • @cyber_india
    @cyber_india Месяц назад

    Bro its reflected xss or self xss?

  • @srirampavankumar4924
    @srirampavankumar4924 Месяц назад

    Please share that payloads bro

    • @lostsecc
      @lostsecc  Месяц назад +1

      check telegram brother

  • @radhesearch
    @radhesearch Месяц назад

    Bro Sub Duplicate hoo raha hai

  • @naho534
    @naho534 Месяц назад

    song name ?

  • @comedywala2102
    @comedywala2102 Месяц назад

    Can u send payload files

  • @__CJ.__
    @__CJ.__ Месяц назад

    Crazy🎉

  • @noelpjetri
    @noelpjetri Месяц назад

    Yo u leaked ur ip address when u alerted you cookies

    • @lostsecc
      @lostsecc  Месяц назад

      aah i see,its not mine bro i use inbuilt proxy..

    • @noelpjetri
      @noelpjetri Месяц назад

      @@lostsecc hahaha u got good opsec then

  • @anupamjha5272
    @anupamjha5272 Месяц назад

    Can i have your payloads?

    • @lostsecc
      @lostsecc  Месяц назад

      check tg brother

  • @mauth6744
    @mauth6744 Месяц назад

    This is Blind or Reflected ؟

    • @lostsecc
      @lostsecc  Месяц назад

      reflected

    • @mauth6744
      @mauth6744 Месяц назад

      @@lostsecc There are programs that they do not accept, and they tell me that there is no danger to the user

    • @lostsecc
      @lostsecc  Месяц назад

      yeah bcz its self so

  • @aatankbadboy3941
    @aatankbadboy3941 Месяц назад

    Bro I think it's not fixed till now 🎉

  • @KawsarAhmed-jb4jn
    @KawsarAhmed-jb4jn Месяц назад

    bro need this all payload

  • @user-gc6gp7cm9c
    @user-gc6gp7cm9c Месяц назад

    Appreciated

  • @user-gc6gp7cm9c
    @user-gc6gp7cm9c Месяц назад

    Your sharing is looking awesome but😢😢 i cant understand yet

  • @Prince-zu5uj
    @Prince-zu5uj Месяц назад

    Bhai report kaha pr kiya...??

  • @pizzaphillic
    @pizzaphillic Месяц назад

    Can you please share this payload.txt file 🥺

    • @lostsecc
      @lostsecc  Месяц назад +1

      check telegram ❤️

    • @pizzaphillic
      @pizzaphillic Месяц назад

      @@gowtham8774 it's there, I found it recheck

    • @walterwhite-du4rn
      @walterwhite-du4rn Месяц назад

      @@lostsecc brother provide telegram channel

  • @hari_S246
    @hari_S246 Месяц назад

    please send this payload link i checked ur telegram not avail this payload

    • @lostsecc
      @lostsecc  Месяц назад

      ok sure i send u and find more payloads in channel media tab

    • @hari_S246
      @hari_S246 Месяц назад

      Ok, please send

    • @ramshortseditz
      @ramshortseditz Месяц назад

      ​@@lostsecc I also need this

  • @aejazzzz2298
    @aejazzzz2298 Месяц назад

    Bro share ur private nuclei templates it's not there in ur telegram

    • @lostsecc
      @lostsecc  Месяц назад

      uploading soon..

    • @aejazzzz2298
      @aejazzzz2298 Месяц назад

      @@lostsecc u didn't replys on telegram I MSG u lots of time

    • @aejazzzz2298
      @aejazzzz2298 Месяц назад

      Tell me command of ssrf map while we hunting on mass urls

  • @0RIPPER0
    @0RIPPER0 Месяц назад

    sach mein La pino'z 500 usd diyea hein ? ya fir majak hein 🥲

  • @curiousmunchkins1769
    @curiousmunchkins1769 Месяц назад

    how to join the telegram group. i want to know about the cheatsheet used