Finding Zero-days With Github

  Рет қаралды 7,981

cwinfosec

cwinfosec

Күн бұрын

Пікірлер: 19
@TalsonHacks
@TalsonHacks 3 жыл бұрын
A comment for YT algo :D
@InfiniteLogins
@InfiniteLogins 3 жыл бұрын
Super awesome methodology. It's like automating CVE discovery! Genius!
@alociousco.
@alociousco. 6 ай бұрын
I would love to learn all this stuff, please keep making this content!! Subscribed!
@cocplayer9511
@cocplayer9511 3 жыл бұрын
You deserve more subscribers, great job
@firstgrandmasterx
@firstgrandmasterx 3 ай бұрын
Great video
@crash4o4
@crash4o4 2 жыл бұрын
Good video doing oswe now and gives me a insight on how to document my steps.
@adalbertoguerra8402
@adalbertoguerra8402 3 жыл бұрын
Great content.!!! Very educational.!!! I am wondering if you can make a video explaining what are the steps to learn zero-day vulnerabilities.
@000t9
@000t9 3 жыл бұрын
Oh thank you bro! Nice tools!
@mahdimix5468
@mahdimix5468 2 жыл бұрын
You have amazing voice 😍, I have a feeling that telling me that you should be famous in this field, work hard as much as you can
@MygenteTV
@MygenteTV Жыл бұрын
So basically a zero day is any cve before you make it a cve?
@cwinfosec
@cwinfosec Жыл бұрын
Sorta but not exactly. Definitions vary, but generally the term "zero-day" comes from the fact that once a vulnerability has been discovered and an exploit developed for it, the vendor has had zero days to patch or fix it before attackers are able take advantage of it. If the developer knows about a vulnerability, but hasn't released a patch yet we typically refer to them as "N-day"
@MygenteTV
@MygenteTV Жыл бұрын
@@cwinfosec I see, Thank you. So to put it in a very simplistic way. Let's say I find a RCE/sqli in a software(SuperFive) many companies around the world use SuperFive. Now I can just hack any SuperFive user because they don't know about my discovery, unless I tell the world about and to make it more effective, I made a python script that will do my manual steps in auto
@CustomDabber360
@CustomDabber360 3 жыл бұрын
Do you talk to your mother with that voice?
@snailsec
@snailsec 2 жыл бұрын
great info :D can you tell me how much time on avg does it take for you to discover a zero day like you've shown in the video???? also do you have any tips when starting to hunt 0day in the wild?
@cwinfosec
@cwinfosec Жыл бұрын
I'm sorry for taking so long to respond. It really depends on the app, sometimes I've found them within an hour, sometimes it took me a day or so after initially investigating. Especially when you consider the skill requirement for certain binary vulnerabilities, it can really take a lot of time to develop a working POC. The important part is hunting for bugs, whether you ultimately find one or not isn't important, just looking for them in the first place is IMO. Best of luck to you my friend!
@audiobook890
@audiobook890 3 жыл бұрын
Hmm awesome.
@taiquangong9912
@taiquangong9912 Жыл бұрын
Long time
@samsepi0101
@samsepi0101 3 жыл бұрын
Great Content, but why was your voice shaking?
@user-dw9tx5sp2z7
@user-dw9tx5sp2z7 Жыл бұрын
Throwaway your backspace man. It is making your life so sad
Exploit Development for Dummies
1:02:49
Florian Bogner
Рет қаралды 23 М.
Where People Go When They Want to Hack You
34:40
Cybernews
Рет қаралды 2,5 МЛН
Andro, ELMAN, TONI, MONA - Зари (Official Audio)
2:53
RAAVA MUSIC
Рет қаралды 8 МЛН
Caleb Pressley Shows TSA How It’s Done
0:28
Barstool Sports
Рет қаралды 60 МЛН
GIANT Gummy Worm #shorts
0:42
Mr DegrEE
Рет қаралды 152 МЛН
Chat GPT for Dummies
13:29
Liz Pevytoe
Рет қаралды 1,2 М.
35C3 -  The Layman's Guide to Zero-Day Engineering
57:04
media.ccc.de
Рет қаралды 40 М.
Is this the best OSINT tool out there?!
17:10
stuffy24
Рет қаралды 379 М.
let’s play with a ZERO-DAY vulnerability “follina”
21:21
NetworkChuck
Рет қаралды 514 М.
What is a Zero Day Threat?
13:45
IBM Technology
Рет қаралды 21 М.
Where to start with exploit development
13:59
David Bombal Clips
Рет қаралды 18 М.
Finding 0day in Apache APISIX During CTF (CVE-2022-24112)
12:41
LiveOverflow
Рет қаралды 87 М.
how is this hacking tool legal?
11:42
Low Level
Рет қаралды 469 М.
Zero Click Exploits Explained: Technical
10:23
RealTime Cyber
Рет қаралды 45 М.