ADVANCED BUG BOUNTY TUTORIAL: BUSINESS LOGIC VULNERABILITY | 2023

  Рет қаралды 5,281

BePractical

BePractical

Күн бұрын

Пікірлер: 27
@mnageh-bo1mm
@mnageh-bo1mm Жыл бұрын
but why would the server accept the link from you ? i mean it already have it
@BePracticalTech
@BePracticalTech Жыл бұрын
Thanks for asking this question. Let's try to understand from the developer's perspective. Many times the file will get uploaded at the third party services(like s3 buckets etc). Suppose the user wants to re upload the file, In this case the file needs to be uploaded on the server again and the new link needs to be stored again. To speed up this process, many times developers fetch the link at the client side so that if they want to re upload the file, they can just modify the data at the client side rather than editing the data in db. Once the client is done with their file upload, they can finally click on the submit button and then the final link will be uploaded in the database. Hope you understand
@mnageh-bo1mm
@mnageh-bo1mm Жыл бұрын
@@BePracticalTech thx i got it even that seems untypical behavior
@BePracticalTech
@BePracticalTech Жыл бұрын
Glad you understand! I think every vulnerability is an untypical behavior. 😉
@robinhood3001
@robinhood3001 Жыл бұрын
Thats awesome....pls make a tutorial on how to bypass admin wordpress panel
@srikanth4326
@srikanth4326 Жыл бұрын
Very well explained
@H3xOv3rflow
@H3xOv3rflow Жыл бұрын
Thanks brother ❤
@BePracticalTech
@BePracticalTech Жыл бұрын
You're welcome
@oye_ahmad1657
@oye_ahmad1657 Жыл бұрын
Bro make videos on how to find low hanging fruits using burpsuite🙏🏻🙏🏻🙏🏻Manual Testing....
@BePracticalTech
@BePracticalTech Жыл бұрын
Sure! Will keep this topic in mind
@apple_00
@apple_00 Жыл бұрын
Thanks for you ❤
@BePracticalTech
@BePracticalTech Жыл бұрын
Glad you liked the video!
@imran_hossain123
@imran_hossain123 Жыл бұрын
Great bro
@BePracticalTech
@BePracticalTech Жыл бұрын
Thank you!
@joy3658
@joy3658 Жыл бұрын
So, If I upload a malicious JPG file to the web application then the server can not validate right? like attacker using jpg to exploit or something malicious like that. (in png image cmd command) Then it can be a bug? So, in any application where uploading features going on, and server don't validating the input file then it can be a bug??
@joy3658
@joy3658 Жыл бұрын
But what would be the scenerio or response like if server was validate that?
@BePracticalTech
@BePracticalTech Жыл бұрын
Please read the pinned comment to understand.
@orbitxyz7867
@orbitxyz7867 Жыл бұрын
thanks bro Next video on cve you found
@BePracticalTech
@BePracticalTech Жыл бұрын
Sure!
@r3plican
@r3plican Жыл бұрын
it is same as redirect vuln?
@BePracticalTech
@BePracticalTech Жыл бұрын
Yes, it is kind of similar to open redirection
@imtiajarefin
@imtiajarefin Жыл бұрын
🎉🎉
@BePracticalTech
@BePracticalTech Жыл бұрын
Thank you!
@whateveritis0
@whateveritis0 Жыл бұрын
Haii, watching your videos from the Start, learned a lot., now can you do a video on, where we have to look a particular bug, for example What are the bug we can look in registration, and what are the possible parameter for particular bugs 🫶🏻
@uniq6318
@uniq6318 10 ай бұрын
@canigetyournumber-v6e
@canigetyournumber-v6e 3 ай бұрын
Bhai hindi me banaya kar jyada chalega
BUG BOUNTY: SERVER SIDE REQUEST FORGERY | LIVE WEBSITE | 2023
21:57
Business Logic Vulnerabilities | Complete Guide
18:58
Rana Khalil
Рет қаралды 9 М.
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
人是不能做到吗?#火影忍者 #家人  #佐助
00:20
火影忍者一家
Рет қаралды 20 МЛН
How I Found My First Bug (and earned $1k!) - Business Logic Tips
19:41
Bug Bounty: Content Discovery on Large Scope Like a Pro! | 2024
13:53
Covering The Under Rated Vulnerabilities: CORS Misconfiguration #1
17:19
The MOST common and EASY bug  in Bug Bounty
8:07
Ryan John
Рет қаралды 13 М.
Android App Bug Bounty Secrets
20:14
LiveOverflow
Рет қаралды 108 М.
КОРОЧЕ ГОВОРЯ, НЕДЕЛЯ БЕЗ ТЕЛЕФОНА
3:54
Её автомобиль никто не хотел ремонтировать!
20:12
Гараж Автоэлектрика
Рет қаралды 1,5 МЛН
DESAFIO DOS COPOS #shorts
0:38
Natan por Aí
Рет қаралды 34 МЛН
Down Spout Catch Basin Installation to French Drain
0:58
Komar Project
Рет қаралды 6 МЛН
Pixel 7 и 7 Pro с Face ID - лучше iPhone 14 Pro!
21:12
Rozetked
Рет қаралды 457 М.
Абзал неге келді? 4.10.22
3:53
QosLike fan club
Рет қаралды 31 М.