Web App Testing: Episode 2 - Enumeration, XSS, and UI Bypassing

Поделиться
HTML-код
  • Опубликовано: 29 сен 2024

Комментарии • 61

  • @TCMSecurityAcademy
    @TCMSecurityAcademy  3 года назад +2

    I hope you enjoyed this video! If so, please consider dropping a like and subscribing.

  • @afsarriyan7395
    @afsarriyan7395 5 лет назад +28

    You are doing God's work !!!! Great stream

  • @superman9300
    @superman9300 4 года назад

    My head is on overload. Awesome video.

  • @hellobro495
    @hellobro495 4 года назад

    Respect earned!!!!

  • @Creative.Ferments
    @Creative.Ferments 4 года назад

    Than you! MVP.

  • @stromreckson2370
    @stromreckson2370 2 года назад

    Building on this would really help ..thank you!

  • @m_k6383
    @m_k6383 5 лет назад

    Great content Senpai !! Please I have a question concerning the Repetitive registration (DRY principal) challenge :
    How is it possible for a "mean" hacker to use this flaw to exploit the web app because it didn't seem to me that it is a big of a deal especially that the "Confirm Password Field " is no longer used in the newest web app
    Thanks alot !

  • @renarsdilevka6573
    @renarsdilevka6573 4 года назад

    How to build Websites? Acedemind, Traversy Media, Florin Pop etc. :)

  • @vardhannegi677
    @vardhannegi677 5 лет назад

    hey if anyone have PortSwigger CA certificate file or if u have download link please send me. i'm unable to download

  • @michaelmutter9974
    @michaelmutter9974 4 года назад +5

    This is the type of information I've been searching for. Thank you!

  • @عبداللهمحمدالمطوع-ض6ن

    وعليكم السلام
    Thank you For this

  • @andretorresbr
    @andretorresbr 4 года назад +3

    Great video, as always. BTW, can you post the link to the DOM based XSS website?

  • @peterblack1174
    @peterblack1174 5 лет назад +4

    I actually like listening to the Q&A...
    I guess I'll just go watch it on twitch :(

    • @TCMSecurityAcademy
      @TCMSecurityAcademy  5 лет назад +2

      The video was constantly skipping frames, so it was mostly audio.

  • @redasebti7570
    @redasebti7570 3 года назад +1

    Scan in burp is a pro version feature

  • @aniketmund7222
    @aniketmund7222 4 года назад +1

    I started like everyone starts...you know by searching on google....😂😂😂🤣🤣🤣🤣

  • @scuffedcomedy4819
    @scuffedcomedy4819 5 лет назад +2

    cant wait for the 100k subs than the 1 mil :) great stuff as always!

  • @th3ndktn
    @th3ndktn 5 лет назад +3

    Lol you speak hebrew? Shalom ahi

  • @shreyashhire7527
    @shreyashhire7527 3 года назад +1

    can start doing bug bounty after this course?????? pls reply and thank you so much for these videos !!!

    • @adityakiddo6554
      @adityakiddo6554 10 месяцев назад

      Depends on your approach methods too , though this is fantastic video , your own methodologies to approach might differ , and bug bounty requires also your own set of ideas .... vigorous practice along wid this video will make it.... all the best

  • @textprogram6283
    @textprogram6283 3 года назад +1

    check your discord invite link

  • @midvayner7411
    @midvayner7411 5 лет назад +1

    you are the best my friend.. You are good person.. Really.. I want something from you. Can you teach us C Language for Network Penetration Testing.. again thnx for everything , because you give us education and free.. YOU ARE THE BEST MY FRIEND 🙏😊

    • @TCMSecurityAcademy
      @TCMSecurityAcademy  5 лет назад

      If only I knew C :(

    • @midvayner7411
      @midvayner7411 5 лет назад

      @@TCMSecurityAcademy okey , if you want to teach other language for network hacking.. We can wait 😄🙌

  • @kahoonalagona7123
    @kahoonalagona7123 Год назад

    guys im not really sure what is this but the video is 1h 2min, but in the playlist the video is showing as 1h 32min for some reason

  • @GoBzi
    @GoBzi 5 лет назад +1

    Secure flag doesn't allow the cookie to be transmitted over HTTP. What you're describing is the HTTPOnly flag. Anyway, thanks for the video, keep up the good work!

    • @TCMSecurityAcademy
      @TCMSecurityAcademy  5 лет назад

      Yep. Clarified this mistake in the beginning of the next episode :). Thank you!

    • @GoBzi
      @GoBzi 5 лет назад +1

      @@TCMSecurityAcademy didn't start with episode 3 yet! :)

  • @liulshewaye6174
    @liulshewaye6174 4 года назад +2

    i wish i could subscribe you for the second time

  • @mohammadyasein7105
    @mohammadyasein7105 4 года назад

    Nice stream , can you make video to bypass " i found xss in site.com but i face problem the code between double quots"" and filter encode any html and url encoding

  • @Ariesgod1998
    @Ariesgod1998 4 года назад

    Hey i installed juice box using docker now i am not able to get the request in burp proxy need help , it is running on port 3000

  • @supratickdey7125
    @supratickdey7125 4 года назад

    option for scanning a particular site is only in pro version..i have the community version ..what to do?

  • @renarsdilevka6573
    @renarsdilevka6573 4 года назад

    About long links especially when you can bitly or tiny urlify it today, true?

  • @deepaksingh-qd7xm
    @deepaksingh-qd7xm Год назад

    32:40 ->>

  • @TheCyberWarriorGuy
    @TheCyberWarriorGuy Год назад

    :)

  • @roycreativedesigner4608
    @roycreativedesigner4608 4 месяца назад

    That was so amazing when u said Salam Walikum

  • @MP-mo5eq
    @MP-mo5eq 5 лет назад

    @51.42 you say "It never hit the server". Would you please explain how do you infer that it never hit the server?
    Thank you.

  • @fabricelegrand4747
    @fabricelegrand4747 5 лет назад +1

    Thank you!!! :)

  • @ajaidx
    @ajaidx 4 года назад +1

    Thanks, bro learnt a lot from you.

  • @faique2995
    @faique2995 4 года назад

    /*fabulous */

  • @Роберт-и8х
    @Роберт-и8х 5 лет назад +1

    Love you!!

  • @turbosardar39
    @turbosardar39 4 года назад

    There is no scan option in free version!!

  • @bananaburek3160
    @bananaburek3160 5 лет назад +1

    Keep up the great work!!!

  • @fabiog
    @fabiog 4 года назад

    Is the 'Scan' option shown at 12:51 still available in Burp Suite Community Edition? It's always grayed out for me on Burp Suite Community Edition v2020.2

    • @JohnSmith-my5hb
      @JohnSmith-my5hb 4 года назад

      The "Scan" option is payed version only.

    • @fabiog
      @fabiog 4 года назад

      @@JohnSmith-my5hb Thanks! In the video he selects that "Scan" option in the free edition (12:51). Was the scan option recently removed from the Community Edition?

    • @sankyification
      @sankyification 4 года назад

      @@fabiog He clearly said at (7.04) now this burp suite in my pro edition, (pro) means its a paid version of burp suite

  • @JuanCruz-uk3qi
    @JuanCruz-uk3qi 5 лет назад +1

    Niceeeeeeeee! Ty.

  • @SecurityTalent
    @SecurityTalent 3 года назад

    Thanks

  • @goddiemang5792
    @goddiemang5792 5 лет назад +2

    Miss the Livestream, but still this is Awesome....

  • @mrjamesprince
    @mrjamesprince 5 лет назад +2

    Shalom 🙏

  • @brahma411
    @brahma411 5 лет назад +1

    video on AWS security testing

  • @kenGPT
    @kenGPT 5 лет назад +1

    Uhhh I think your upload failed lol. It's the very end of your lesson unless this was supposed to be a quick q & a unless my YT app is breaking. It's only giving me the last 9 minutes of the stream