⌨️(0:00:00) Setting Up Burp Suite ⌨️(0:08:07) Spidering & DVWA ⌨️(0:19:04) Brute Force Attacks With Burp Suite ⌨️(0:32:55) Target Scope And Spidering ⌨️(0:46:32) Discovering Hidden Files With ZAP ⌨️(1:04:24) Web Application Firewall Detection with WAFW00F ⌨️(1:12:28) DirBuster ⌨️(1:25:27) XSS(Reflected, Stored & DOM) ⌨️(1:41:22) CSRF (Cross Site Request Forgery) ⌨️(2:02:42) Cookie Collection & Reverse Engineering ⌨️(2:14:17) HTTP Attributes (Cookie Stealing) ⌨️(2:27:48) SQL Injection
@RavindraKumarSG6 жыл бұрын
thanks
@faithunitedministries2825 жыл бұрын
when I set up proxy, I no longer able to use browser. Error: connection not private. How can I get around this to view the video and use burp suite.
@anonymuser68735 жыл бұрын
@@ammarbinfaisal salamu aleikum brother, good explaination. Thank you!
@gtssenna4 жыл бұрын
The best comment! Thanks!!
@vinayjain3222 жыл бұрын
@@apackalu2718at least he did it for those who don't check description. And it's helpful 😄
@alexh31434 жыл бұрын
I am overwhelmed by the value this channel offers
@shibafundamentado18372 жыл бұрын
this channel is a goldmine of knowledge
@ShahrinRahman2 жыл бұрын
Same here.
@theyellowflash1002 жыл бұрын
This is from hackersploit, search it up
@taharehman64394 жыл бұрын
NOTE: Anyone who is having trouble with connecting metasploitable with browser in kali 1) go to the metasploitable network settings in your hypervisor( virtual machine monitor or VMM) like virtual box 2) change to the adapter from NAT to Bridge thats all like so more people can see it
@nathanielahao2 жыл бұрын
Though bridge gives an easier option to setting the network..but I would prefer you use host network ..it does the same but it has an added advantage..it doesn’t expose your vms to other people on the internet only your host can access them…bridge exposes your vms to other people on the network
@dhananjaykumar687 Жыл бұрын
Thinks bro u are great ❤️
@Fairouznajib11 ай бұрын
@@nathanielahaohello, I’m stuck, can we communicate please?
@PCs4548 ай бұрын
no i dont think opening metasploitable as bridged is safe for your home network
@jerrymartinez42292 жыл бұрын
This guy is not only knowledgeable and a good teacher... he's extremely funny too....
@cryptombt58803 жыл бұрын
3 years later and you're still getting views and comments bro. I absolutely love your content. Helps me out a great deal as a beginner in pentesting. Love the subject a great deal
@vilanstrikegaming51142 жыл бұрын
Yes
@roshanhussain29112 жыл бұрын
yes your right
@EduardoRodrigues-ev7ej Жыл бұрын
That's how KZbin works
@chukwudiudennaka7521 Жыл бұрын
Please i heard in the video you have a special course about web application penetration testing with ZAp not burp suite. As Zap is being touted as a very massive tool, you can hardly find detailed resources on it. Everyone seems to be talking about Burp suite especially the pro version. So please if you could kindly direct me to the course, I would mostly appreciate it
@devendrahyalij57243 жыл бұрын
I'm watching this nearly after 2 years but it is still much more informative 👍
@ck41314 жыл бұрын
This is really amazing to hear hackersploit voice.
@GFG966 жыл бұрын
Thank you a lot for the content, I appreciate a lot you taking the time to pass your knowledge forward Thank you very much
@jessicahsmith48153 жыл бұрын
hackerlouis05 on Instagram is the best when it comes to hacking He's services are fast and legit and he doesn't charge much
@omarifinn99873 жыл бұрын
sorry to be so offtopic but does anybody know of a tool to log back into an Instagram account?? I was stupid lost my login password. I would appreciate any assistance you can give me
@johndemlon23754 жыл бұрын
the best lesson you need to learn in this tutorial 2:12:25
@peanutbutter2914 жыл бұрын
I liked the video as soon as I heard his voice.
@chanbasha68713 жыл бұрын
Excellent teaching man it's very easy to understand ♥️
@emkt36592 жыл бұрын
L
@InSight0r4 жыл бұрын
You can skip (2.)Spidering as it's not present in the burpsuite anymore. I think there is something to do with some new laws about crawling but the team is working on a new method implemented in Pro and Community editions with no ETA for now thou.
@splashkid84104 жыл бұрын
How do I find someone ip using their phone number
@Nick-vd7cg Жыл бұрын
Whats the alternative for spidering then? I'm trying to learn copying this guy as a total beginner.
@frenzyguyz3 жыл бұрын
Wonderful explanation All doubts cleared and feel confident.
@nahinalauddin524810 ай бұрын
is it possible for you to create new playlist of cyber security because course is too old and lot have changed
@shravandhar61696 жыл бұрын
This is so helpful. Thanks a ton!
@antlasgmd14696 жыл бұрын
is that video from hackersploit channel cause i heard hackersploit tag in the begening
@freecodecamp6 жыл бұрын
Yes. We were so excited that Hackersploit gave us permission to post this great course.
@younessihem79794 жыл бұрын
@@freecodecamp a1
@jessicahsmith48153 жыл бұрын
hackerlouis05 on Instagram is the best when it comes to hacking He's services are fast and legit and he doesn't charge much
@εύς4 жыл бұрын
list of tools and applications: dvwa bwapp juice shop owasp zap dirbuster
@fernandoblazin3 жыл бұрын
love this guy no nonsense tutorials thanks bro
@kabandajamir98443 жыл бұрын
So nice explanation sir it's really nice the world's best teacher
@whinrog26465 жыл бұрын
pause at 1:25:27 and shake your screen (if you are on your phone).
@naeem84344 жыл бұрын
Amazing I learn a lot from this video thanks for sharing this knowledge with us on KZbin.
@jayseb3 жыл бұрын
In the business for a while and was just curious. Well explained and presented. Cheers.
@ThisIsAli_Off3 жыл бұрын
As someone in the field, would you advice me to take this course? Is there an important gap between the content of this course and real work or is it very close please? (I am a complete beginner in cybersecurity)
@Dr_Eam9733 жыл бұрын
@@ThisIsAli_Off i would like to know this too
@w花b2 жыл бұрын
@@ThisIsAli_Off I don't think you can simply watch 2 hours of video and suddenly become a professional. Especially not with computer given the huge amount of things to learn
@ThisIsAli_Off2 жыл бұрын
@@w花b Yup, this is especially true for cybersecurity. Every time I think I start "mastering" the basics, I discover a totally new topic that I don't know anything about. It can be very intimidating to start cybersec when you see how large the field is and how hard it is.
@limazmah14284 жыл бұрын
even tho u speak faster but u still one of my best teacher. bless u
@maxsudik5 жыл бұрын
I have 2 questions: 1) What is the purpose of setting the proxy? Why we set the proxy to localhost? Using this proxy I'm not able to reach a web resource. 2) I can't select the checkbox in the App, under the 'Proxy' -> 'Options' -> Running 4:59
@playmaker10115 жыл бұрын
Check settings, you can reach everything, proxy is only intercept the request/response
@ganeshprasad98514 жыл бұрын
Proxy servers act as a firewall and web filter, provide shared network connections, and cache data to speed up common requests. People generally use these proxy servers to make the website thing that this ip address didn't visit their site before.
@guylemay14715 жыл бұрын
You don't really know what penetration is until one day you find out that there is a back-door on your system that won't let you in! Hopefully this video will show the way to a better Internet experience!!!
@lagimmediafiles64785 жыл бұрын
I love this org and youtube channel
@lljw94552 жыл бұрын
Thank you, hackersploit! 💕
@lljw94552 жыл бұрын
Stop*
@TheGeekJourney6 жыл бұрын
omg! this is an awesome video. 3 hours? yep. the longest video i ever seen.
@sul3y5 жыл бұрын
Check out start hacking today
@Muntwash_Wabant8 ай бұрын
Thank you so much Sir !!! You're a great Teacher! Be blessed!
@CodeXND6 жыл бұрын
"really really really really really really really really really really " "all good stuff"
@AP-rv6kk4 жыл бұрын
irregardless
@gauravbisht96223 жыл бұрын
46:32 timestamp for me
@mozart03 жыл бұрын
It's been 6 months ago..how is it going? Was the information in the video outdated?
@TheDaha3 жыл бұрын
@@mozart0 nobody ever rep loss for updates lol
@chukwudiudennaka7521 Жыл бұрын
Please during the course, i heard you had a seperate tutorial on the use of ZAp for web applications testing. I ask this because everyone seems to be leaning towards burp suite pro and there are hardly any tutorials out there except yours at least which cover zap in detail for web app pen testing. Please if you would kindly direct me to that tutorial i would appreciate it.
@MereAYT Жыл бұрын
This covers the material clearly and thoroughly. Thanks!
@ram32523 жыл бұрын
This is really helpfull video for us kindly upload video for ethical hacking on desktops application thanks
@letslearn17122 жыл бұрын
You need to have pro version of burpsuite right, mine doesnt have few of the important options like spider and all.
@tuxmusicman6 жыл бұрын
I am running Kali in VirtualBox. It does not have a button to add an exception. Firefox was probably updated in the newer Kali. Does anyone know how to create the exception a different way?
@ajith18045 жыл бұрын
I had the same problem.But I installed parrot os,and the problem is solved
@zyrox3475 жыл бұрын
You can use an usb for runnig kali linux in your pc :)
@aussieyobbosworld3 жыл бұрын
Thank you from Melbourne Australia
@michaeljumakilongi11462 жыл бұрын
nice and recommended indeed bravo work😍
@r-test36683 жыл бұрын
doing this. been wanting this for a long time
@hashimjaved74164 жыл бұрын
This is amazing stuff for beginners. Thank You
@user-kx1le7yn1k4 жыл бұрын
"really really really really really really really really really really " "all good stuff"
@parmeet84554 жыл бұрын
Hey Hashim! Do I need to learn anything prior for this course? And where can learn it (paid/free). Thanks
@hashimjaved74164 жыл бұрын
@@parmeet8455 depends on your study background.
@LoyaltyIsEverything91 Жыл бұрын
Youre awesome teacher, can you please do a video on how to find the login username and password for a router gateway url? Please and thank you!!
@Dionydejesus4 жыл бұрын
Finally ! Something with PARROT OS, There is no books available about parrot os. 😢
@asmerdam51264 жыл бұрын
Thank you so much for this video! I really appreciate, I was referred by Ted, he helped me throughout the whole process with no extra cost. This is my referral as promised mx076 on wickr or telegram.
@michealsmith91504 жыл бұрын
@@asmerdam5126 thanks alot for sharing this!
@michealjames1664 жыл бұрын
@@asmerdam5126 just contacted him! hoping for the best
@vishnusudheer15814 жыл бұрын
Thank you Tesfay. Such a great video for study purpose.
@zimutes10 ай бұрын
Strong title, great content.
@josh92954 жыл бұрын
So explanatory. Thanks alot. But can one of these methods be used to bypass otp verification code...If you could do a video on that
@abovethehorizon2023Ай бұрын
We would love to have an updated version of this course
@sc08204 жыл бұрын
I am wondering if it is only me who see flashes of image, unknown apps, and curse-like jargons without understanding what is the whole picture and the meanings behind all these??
@theself9993 жыл бұрын
Yeah i was wondrring the same
@thanhvinhnguyento70693 жыл бұрын
@@theself999 youtube alone won't cut it. Get some books and do research on your own. this is just an overview of some tools
@evian66733 жыл бұрын
@@thanhvinhnguyento7069 Yes indeed.
@rockguru66563 жыл бұрын
0:00 hacker sploit here .. legendary name🔥🔥😎
@christoferchan30766 жыл бұрын
Sick cant wait to dive into this!
@itamargolomb85306 жыл бұрын
Hacker Sploit! Love from Israel!
@ghostgil70065 жыл бұрын
This voice i didn't forget.. :D
@noahrodriguez45604 жыл бұрын
I get the idea! 😅
@techgirl11482 жыл бұрын
hi, thanks for the videos. I have a question at bruteforce. When i go to response/render it shows Unable to render response! Why is this happening? any clue anyone?
@hu3m4n903 жыл бұрын
why so nervous? you do a really nice job explaining bro!
@janienreeves2813 Жыл бұрын
Thanks for explaining the difference between the two but I’m new to cyber security I’m wondering which one to do first the pen-testing or vulnerability scanning? Any advise is welcomed as I’m looking for a book camp after I take a couple of online classes
@kalakotibrahmateja5917 Жыл бұрын
vulnerability scanning bro
@croak40464 жыл бұрын
What happened to the spider tab in burp suite? It doesn't seem to exist in burp suite 2020.
@pradipdhakal26656 жыл бұрын
I'm going to quite CSGO and start this tutorial from today....
@aronpop14475 жыл бұрын
I recommend English lesson first
@xitijdesai5 жыл бұрын
@@aronpop1447 hahah..
@Nick-vd7cg Жыл бұрын
Is it legal to use your website to learn along the way with the video ? By letting Burpsuite at it ?
@giancarlocerza9159 Жыл бұрын
thank you so much for this video, makes everything so clear : thank you!
@utkarshraghav66534 жыл бұрын
They have removed spidering option from the community edition now. Any alternatives for this?
@jchristie66324 жыл бұрын
OWASP ZAP has spidering for free. Use this instead
@notholdini27404 жыл бұрын
Yes
@notholdini27404 жыл бұрын
Ok
@laepiphania252 жыл бұрын
Super helpful content...Thanks so much!
@bugr33d0_hunter85 жыл бұрын
The first brute force was admin admin. You were rushing through it. Nice job.
@Powerfulwordsofbible4 жыл бұрын
Bro can u tell me the best websites for learning hacking
@bugr33d0_hunter84 жыл бұрын
@@Powerfulwordsofbible depends on what type of hacking you want to learn. Reverse engineering, binary exploitation, Web_app security, Networking security, Systems admin security, Bug_Bounty. Programming in languages like C, Bash, Python are also needed.
@Powerfulwordsofbible4 жыл бұрын
@@bugr33d0_hunter8 i want to become an ethical hacker
@Powerfulwordsofbible4 жыл бұрын
I'm at beginning stage
@queefstroganoff26434 жыл бұрын
@@Powerfulwordsofbible you need to learn a couple languages before you should do anything else.
@princealeem76525 жыл бұрын
Awesome content and explanation... Got to know so many things
@aalphaas77193 жыл бұрын
Complete TOR anonymity tutorials using TAILS, WHONIX and KODACHI linux kzbin.info/www/bejne/sJjZhp2qpJ19bM0
@diegomartin94842 жыл бұрын
does anyone know what is the url for DVWA??? I know in this video he links it via his IP but i'm not that techy and need to access DVWA using Burp. thanks!
@Noah-px4dp4 жыл бұрын
What's the difference between network penetration testing and web application penetration testing? Do you need to know both to be a bug bounty hunter?
@notholdini27404 жыл бұрын
Network penetration is the network like the database the web app penetrations is the application
@adriankatong39622 жыл бұрын
To me the ZAP is more user-friendly sir, becos I follow your other video finding useful information by doing the ZAP spiders
@charlescena96124 жыл бұрын
how great you are man! i salute you. you make me believe!
@FUFUWO4 жыл бұрын
The first thing you have to do is learn Proxy Chaining before you try to hack anything. Just a thought
@rajarshimaitra53105 жыл бұрын
Hello guys, I was starting with the tutorial and was really psyched, but hit a bump at the very beginning. After setting my proxy in firefox and importing the Burp certificate, no site is loading in the browser. Failure message is : "Proxy server refusing connection". Here is the same error reported by someone in Burp Support: support.portswigger.net/customer/portal/questions/17353034-error-in-browser-and-burp-suite-the-proxy-server-is-refusing-connections But no solution provided. Can anyone shed some light on how i might get it working? Note: I can see HTTP request intercepted in Burp.
@pavelpavlenko98925 жыл бұрын
I had the same problem. Installing the newest version of Firefox helped me
@muhammadadnan14304 жыл бұрын
I am facing the same problem and hoping if you have found any solution.
@muhammadadnan14304 жыл бұрын
It's saying that the proxy server is refusing the connection on firefox. What should I do now?
@Danny-iy5oq6 жыл бұрын
Great video in which you have really given a lot of effort to explain everything in detail. I have a question about the DirBuster is there a way to get a list from a cloud instead of a local computer? regards -- Danny
@ZorlacSkater5 жыл бұрын
First of thank you for the great video! I just don't understand why you are using two script at 2:22:40 ?
@anupamjaiswal77143 жыл бұрын
Take a look in JavaScript and html, you'll get it.
@shivamwagh224 жыл бұрын
Just curious, what are the prerequisites to get into this one?
@slackjaw99634 жыл бұрын
Understanding of how the internet works and linux maybe some python js html and css
@hishaamsummud8586 Жыл бұрын
could one help please, Burp Suite would not open on a new Parrot security 5.3 installation ; also noticed chrome for Linux after freshly installed is behaving the same way and not starting ?
@rourodadi75246 жыл бұрын
i like your tutorials ...continue please.
@jackerol41716 жыл бұрын
I wish you did the video in a better quality, better for our eyes :)
@freecodecamp6 жыл бұрын
KZbin is still processing. Should get better soon.
@jackerol41716 жыл бұрын
@@freecodecamp Thank you! I'll return later to watch it. I look forward to it!
@MB-eq9ew4 жыл бұрын
why there is no spider branch on latest version of burp suite
@buzkings49755 жыл бұрын
Hello, how can i get firewall name and version, tried wawoof, but its giving a wrong name. any other way?
@onen0zednine7532 жыл бұрын
why didn't this start with a thorough explanation or intro to what web penetration is? it seemed to be more about the tools used and not penetration testing as a discipline... Just a little feedback. who is the target audience for this btw?
@Dewdrops_1012 ай бұрын
He's going straight to the point
@arsalanirfan46845 жыл бұрын
When I changes the preferences to local host then I can't access internet in kali Linux due to which I can't send any http request to any site. Any solution?
@bugr33d0_hunter84 жыл бұрын
Shouldn't use kali then yet. Stick to ubuntu for now. Kali is for elites.
@raanonyms79265 жыл бұрын
loving it, very helpful
@notholdini27404 жыл бұрын
So easy to follow thx
@happychannel26165 жыл бұрын
Please make another more advance course for begginers in web pentesting
@Amiralsalem20133 жыл бұрын
Nice work
@PristineAnimation6 жыл бұрын
Thanks Brother .....its very useful to me
@omosoft27194 жыл бұрын
a wesone but knowledge of socket programming in python is a must
@spyrosdev25334 жыл бұрын
If you want to learn to make a port scanner faster than Nmap here it is: kzbin.info/www/bejne/nWiWfZ6saJKAmKM
@t00manyninjas3 жыл бұрын
@@spyrosdev2533 that video was removed, have you any links/other vids on the subject?
@jp-uno Жыл бұрын
Being that Burp no longer offers the spidering functionality, What are some of you out there using as an alternative? ZAP?
@alkixyourlinux91104 жыл бұрын
You rock!! Good stuff right here!!!!!
@smtanvirahammad32195 жыл бұрын
really helpful video for bigginer
@youtubegamer25753 жыл бұрын
this better not be illegal i woke up to this video
@jbntreasure35203 жыл бұрын
Hello sir, I would like to know Which programming language would be beneficial for cyber security?
@anthony-jt2mv3 жыл бұрын
Python is nice
@jbntreasure35203 жыл бұрын
@@anthony-jt2mv thanks a lot 😀😀😀
@kavinshah98802 жыл бұрын
@@anthony-jt2mv after learning python what is the next step and can u pls explain difference between bug bounty , penetrating, and hacking please bro?
@HACKPHILES3 жыл бұрын
Hackersploit😍😍😍
@gamerstune2895 Жыл бұрын
Thanks for this ❤
@mazingerzeta2xx7884 жыл бұрын
Why I am Missing Spider in my version? currently using v2020.7 i don't see the spider tab?
@chundurusriharsha24023 жыл бұрын
How can i do web app testing for any website given?
@arisadrian96102 жыл бұрын
do the proxy settings have to be the same as the video above
@XXH-vd7os4 ай бұрын
'alert("Awesome content man .. love it")
@efchiborinaga20144 жыл бұрын
Good day! What's the name of the next you've made ? cause I couldn't find it .
@backpackofficial73 жыл бұрын
Do video on mobile app testing (android and IOS )
@mazenkhallaf47876 жыл бұрын
How do we set up the proxy (2:02) using Google Chrome?
@scottreynolds35695 жыл бұрын
by ditching chrome and using ff
@mazenkhallaf47875 жыл бұрын
@@scottreynolds3569 Preferably without ditching (arguably) the worlds best browser.
@scottreynolds35695 жыл бұрын
this will get you to the settings customers.trustedproxies.com/knowledgebase.php?action=displayarticle&id=10 @@mazenkhallaf4787