Bugcrowd University - Cross Site Scripting (XSS)

  Рет қаралды 106,751

Bugcrowd

Bugcrowd

Күн бұрын

Пікірлер: 32
@domaincontroller
@domaincontroller 4 жыл бұрын
00:44 overview 01:22 Module reading 02:18 history =================================== DIFFERENT CLASSES OF XSS =================================== 05:38 reflective XSS 06:09 stored XSS 06:36 Flash-based XSS 07:03 self-XSS =================================== CLASSIC EXAMPLES OF XSS =================================== 07:37 MySpace worm, stored XSS 08:10 Tweetdeck worm, stored XSS =================================== BEST EXAMPLES OF XSS =================================== 08:27 start slow [...], don't get discouraged, keep a list of common payload =================================== DOM XSS =================================== 11:07 Advances of XSS 11:24 DOM XSS is one of the hardest variation of XSS to find because it requires a little bit more advanced knowledge 11:40 and within that function is a call to a variable that can be injected into via query string or post body parameter 11:46 DOM XSS is notoriously hard to find for many beginners and intermediate-level testers 11:53 sources and sinks 12:23 sources 12:59 what does it look like 13:46 example, XSS Polyglot 1 14:40 polyglot 2 14:55 polyglot 3 =================================== BLIND XSS =================================== 15:07 Blind XSS =================================== tooling =================================== 16:09 XSS hunter
@edgob9910
@edgob9910 4 жыл бұрын
Patrice Kenmoé damm you wrote all this 👍🏼
@assistedpropertysale4629
@assistedpropertysale4629 6 жыл бұрын
Thanks to Bugcrowd for giving you the opportunity to present this as well as thank you very much, Jason, as well as everyone that contributed to this presentation. Best Regards
@BearMeOut
@BearMeOut 2 жыл бұрын
Interesting point 8:57 start slowly 13:50 what's a polyglot 17:21 recommend mind map
@medi7573
@medi7573 6 жыл бұрын
we are REALLY enjoying and learning what the channel is providing ,and please more of this amazing content.
@SuperMarkusparkus
@SuperMarkusparkus 6 жыл бұрын
There are two definitions of self-xss. The other is that the user can impose xss on his own user account. If combined with login-csrf it can have the same impact as a regular xss.
@namenone8387
@namenone8387 5 жыл бұрын
Thank you so much for this content, Please keep it coming. :D
@DrKeineL
@DrKeineL 6 жыл бұрын
I am so enjoying this! Thank you thank you so much. Btw I used to check for "hello" to see if its reflecting or not but from now on "swagneto" is my thing lol hope it brings luck!!!
@deanramos9728
@deanramos9728 Жыл бұрын
Thank you for this! Thus made my life easier
@jackgaming7643
@jackgaming7643 4 жыл бұрын
Amazing explanation sir..
@Sebavalya
@Sebavalya 6 жыл бұрын
What's about universal xss ?
@Ajay-kz6zw
@Ajay-kz6zw Жыл бұрын
Super explanation 👍
@Warlock1515
@Warlock1515 5 жыл бұрын
Best video I've seen!
@danz5760
@danz5760 6 жыл бұрын
Do u have to be good at reading JavaScript to find this bug?
@ELREY1979
@ELREY1979 5 жыл бұрын
Hi Guys its there a problem with your Video University Tutorials, future updates ? Thanks for you beautifull explanation
@shubhamwaghmare6550
@shubhamwaghmare6550 5 жыл бұрын
Thank you so much for tutorial this is really helpful 😄
@sanjay010i
@sanjay010i 6 жыл бұрын
@Bugcrowd Tutorials are execellent. Please make more videos on other topics.
@royaljaguar9933
@royaljaguar9933 3 жыл бұрын
No
@rpsulli
@rpsulli 5 жыл бұрын
In the lab, why do you have to go slow when adding tags, etc ??? why not just start with ?
@SwainCountry
@SwainCountry 5 жыл бұрын
Ryan Sullivan - You start with a > to cut off the last value, e.g. an input tag. Some will change it internally to different symbols, you want to test what they block out.
@root_Mohit30
@root_Mohit30 3 жыл бұрын
amazing content✌️✌️
@shrirangkahale
@shrirangkahale 4 жыл бұрын
But most of all, Samy is our hero
@Tekionemission
@Tekionemission 2 жыл бұрын
(17:20)-XSS MindMap
@ashutoshraval3255
@ashutoshraval3255 5 жыл бұрын
Thanks sir pls make more videos 🙏👌
@sail3sh703
@sail3sh703 5 жыл бұрын
today someone just reported the xss bug in google translate
@malikubi1337
@malikubi1337 6 жыл бұрын
Great thanks for sharing.
@derelictmanchester8745
@derelictmanchester8745 4 жыл бұрын
Excellent!!!
@SuperMarkusparkus
@SuperMarkusparkus 6 жыл бұрын
I would never recommend to use KnoXSS. It's a substandard tool that promises too much.
@cyberwarrior9403
@cyberwarrior9403 4 жыл бұрын
very good
@blazedank100
@blazedank100 5 жыл бұрын
Swagneto!
@nainab9329
@nainab9329 4 жыл бұрын
Voice is very low. I had to twice check my volume...
Bugcrowd University - Introduction to Burp Suite
1:38:03
Bugcrowd
Рет қаралды 175 М.
Cross-Site Scripting: A 25-Year Threat That Is Still Going Strong
9:33
“Don’t stop the chances.”
00:44
ISSEI / いっせい
Рет қаралды 62 МЛН
Каха и дочка
00:28
К-Media
Рет қаралды 3,4 МЛН
BAYGUYSTAN | 1 СЕРИЯ | bayGUYS
36:55
bayGUYS
Рет қаралды 1,9 МЛН
DO NOT USE alert(1) for XSS
12:16
LiveOverflow
Рет қаралды 166 М.
Cross-Site Scripting (XSS) Explained! // How to Bug Bounty
14:43
Cross-Site Scripting (XSS) Explained
11:27
PwnFunction
Рет қаралды 465 М.
Uncle Rat's Ultimate XSS Beginner Guide (Free course in description)
1:00:06
Cross-Site Scripting (XSS) Explained And Demonstrated By A Pro Hacker!
9:31
XML External Entity Injection
19:29
Bugcrowd
Рет қаралды 45 М.
The Beginner's Guide to Blind XSS (Cross-Site Scripting)
21:21
Cross Site Scripting (XSS) | Real World
6:17
Ryan John
Рет қаралды 55 М.
Open Redirect Vulnerabilities Explained: Security Weekly
43:17
Security Weekly - A CRA Resource
Рет қаралды 7 М.