Testing XSS Tools On Target Protected By WAF | 2024

  Рет қаралды 10,505

BePractical

BePractical

Күн бұрын

Пікірлер: 55
@BePracticalTech
@BePracticalTech 3 ай бұрын
For those who are saying this video is sponsored, Let me tell you all that it is not. It is just that i liked the tool and thought to share it with you all. Whether you are planning to buy it or not is completely up to you. Thanks
@aatankbadboy3941
@aatankbadboy3941 3 ай бұрын
@@BePracticalTech it's okay but mention that this is sponsored... not only you are promoting it there are lots of other creators also...
@BePracticalTech
@BePracticalTech 3 ай бұрын
This video is not sponsored by anyone nor I got paid to promote any of the tools. I even said in the video that if you don't want to buy the tool then it is completely fine..
@c_war
@c_war 3 ай бұрын
This is overhyped tool
@kittoh_
@kittoh_ 3 ай бұрын
Not sponsored but you have a discount code. 😅
@ishoeb0x1
@ishoeb0x1 2 ай бұрын
Hello., Tested the same target endpoint in Knoxss. This tool was also able to found xss
@yesireact
@yesireact 2 ай бұрын
U r saying knoxss not able to find ?
@aatankbadboy3941
@aatankbadboy3941 3 ай бұрын
Love you bro I want ibrahim xss
@PrashantSingh-jg3jd
@PrashantSingh-jg3jd 3 ай бұрын
So I assume this is how the ibrahimxss tool works: The tool requires binding with google chrome where the tool tracks for any kind of popups in real time within the browser may be possible with that specific chrome driver. The tool then use payload file to send the request by appending the payload with in the browser. If any pop ups comes then, the tool picks a screenshot and include that url in the final generated report. This may be the reason why ibrahimxss got false positive as seen in your video. It simply tracks the popups in real time against the list of payloads. I am be wrong though! Let me know if anyone else think the other way. cheers!
@BePracticalTech
@BePracticalTech 3 ай бұрын
You are right!
@SevenHeavenlyig
@SevenHeavenlyig 3 ай бұрын
Bro made a promotional video without saying it's Sponsored by Ibrahimxss 😂😂
@abdulx01
@abdulx01 3 ай бұрын
😂
@swapnilade2612
@swapnilade2612 3 ай бұрын
Why not you doing ibrahim xss vs knoxss?
@syeddaniyal1273
@syeddaniyal1273 3 ай бұрын
because it is a promotion of ibrahimXSS
@darkmix4192
@darkmix4192 3 ай бұрын
How is this knoxss tool work and it give positive results?
@abdulx01
@abdulx01 3 ай бұрын
I have same... Tool that exactly work like ibrahimxss but different is payload file.. If you have good payload list then..good. Same headless detection tool. No false posstie. And it's cost nothing free of cost. Thanks
@krrishogx
@krrishogx 3 ай бұрын
name?
@ahmed_bembo
@ahmed_bembo 3 ай бұрын
Can you share with us
@couragelotsu8153
@couragelotsu8153 3 ай бұрын
Can you share it pls?😢
@couragelotsu8153
@couragelotsu8153 3 ай бұрын
Can you share it pls?😢
@ZeroOne-wooh
@ZeroOne-wooh 3 ай бұрын
sponsored or not, im just disappointed by the fact that despite knowing the truth, you didn't let your audience know whats going on. its not the tool, its just the list of the payloads which any tool could use it and find same shit. Dalfox can do it if you pass those payloads. sponsoring is not bad, trying to cheat is. just be careful. you've worked hard to build your legacy. don't let cheap tricks get you or don't try to do cheap tricks on new bug bounty hunters. cuz sooner or later you will be called out. hope you don't repeat this in the future. and good luck
@yeahboy2389
@yeahboy2389 12 күн бұрын
Literally bro, I was also thinking the same. But, I believe that only script kiddies would fall for this.
@pawankandu914
@pawankandu914 3 ай бұрын
Sir if u can then please give us that payoad lists used by the paid tool in this video.....
@SuzuneMyQueen
@SuzuneMyQueen 3 ай бұрын
many payload are available on public github repo such as coffinxp's github (in the payloads repo)
@Gladiator-zh9od
@Gladiator-zh9od 3 ай бұрын
Brother make video on how to configure Firefox for burp on windows
@eyezikandexploits
@eyezikandexploits 3 ай бұрын
could you post the payload list of the last tool? you have github?
@sarans119
@sarans119 3 ай бұрын
Bro it is asking API but I not received it
@earningoffers1
@earningoffers1 3 ай бұрын
I have api key
@Heeraheera-ox8gm
@Heeraheera-ox8gm 3 ай бұрын
​@@earningoffers1 bro api key
@DheerajMadhukar
@DheerajMadhukar 3 ай бұрын
Which UI tool you are using to manage VPS(s) ?
@BePracticalTech
@BePracticalTech 3 ай бұрын
@@DheerajMadhukar termius
@gg-mr4qr
@gg-mr4qr 3 ай бұрын
can if you share the payload file that is very very helpful for us.
@rushangshah6308
@rushangshah6308 3 ай бұрын
Why not knoxss
@aatankbadboy3941
@aatankbadboy3941 3 ай бұрын
Mention that this is sponsored 🎉
@songsxmashup
@songsxmashup 3 ай бұрын
some people are getting tool free at all by doing this and that
@nishantrmagar517
@nishantrmagar517 3 ай бұрын
is this tool also run in mac ?
@Prince-zu5uj
@Prince-zu5uj 2 ай бұрын
Akamai waf bypass?
@uttarkhandcooltech1237
@uttarkhandcooltech1237 3 ай бұрын
Hello bhaiya windows theme bto apka jo h
@mrwaahmed9897
@mrwaahmed9897 3 ай бұрын
lol i tested it and it's not bypass any wafs and u didn't try knoxss because it's the best
@ferryirawan1575
@ferryirawan1575 2 ай бұрын
API KEY
@SecureByBhavesh
@SecureByBhavesh 3 ай бұрын
First !!!
@monKeman495
@monKeman495 3 ай бұрын
dalfox can't even find a single shit , what a shame god knows what they r doing !
@eyezikandexploits
@eyezikandexploits 3 ай бұрын
that second payload in dalfox triggered if you would have checked the dom
@exploreThe_
@exploreThe_ 3 ай бұрын
Its only the game of payload... not tool...
@taralnawal5333
@taralnawal5333 2 ай бұрын
Bro only give this payload.txt file😂
@l00pzwastaken
@l00pzwastaken 3 ай бұрын
Use tag as sponsored. Let me tell you why the tool owner is giving everyone to promote his tool i have seen many tweets which are bullshit
@Ironhide234
@Ironhide234 3 ай бұрын
First 😂
@vijayanarasimhamarella
@vijayanarasimhamarella 6 күн бұрын
Don't trust him it's a promotion of his channel and users. He is playing cheap tricks.
@WebWonders1
@WebWonders1 3 ай бұрын
Faking 😅
@tushargurav3987
@tushargurav3987 2 ай бұрын
Disappointed :[
@rootxgod1086
@rootxgod1086 3 ай бұрын
promotion
@4Re5_Xm
@4Re5_Xm 2 ай бұрын
Disappointed
@d3crypt_m3
@d3crypt_m3 3 ай бұрын
Why paid promotion 🥲
Live XSS Exploit: Using XSSFuzz to Break CSP on a Real Target!
19:26
龟兔赛跑:好可爱的小乌龟#short #angel #clown
01:00
Super Beauty team
Рет қаралды 30 МЛН
1 сквиш тебе или 2 другому? 😌 #шортс #виола
00:36
小丑家的感情危机!#小丑#天使#家庭
00:15
家庭搞笑日记
Рет қаралды 32 МЛН
黑的奸计得逞 #古风
00:24
Black and white double fury
Рет қаралды 16 МЛН
Taking over a website with JWT Tokens!
14:27
Tech Raj
Рет қаралды 29 М.
Three Ways to Hack Mobile Apps
43:41
John Hammond
Рет қаралды 61 М.
I used AI to hack this website...
23:23
Tech Raj
Рет қаралды 97 М.
Turning unexploitable XSS into an account takeover with Matan Berson
23:46
Bug Bounty Reports Explained
Рет қаралды 12 М.
Bug Bounty: Content Discovery on Large Scope Like a Pro! | 2024
13:53
BUG BOUNTY: SERVER SIDE REQUEST FORGERY | LIVE WEBSITE | 2023
21:57
This Bug Got Me A $30,000 Bounty
12:41
NahamSec
Рет қаралды 13 М.
龟兔赛跑:好可爱的小乌龟#short #angel #clown
01:00
Super Beauty team
Рет қаралды 30 МЛН