Super awesome methodology. It's like automating CVE discovery! Genius!
@alociousco.6 ай бұрын
I would love to learn all this stuff, please keep making this content!! Subscribed!
@cocplayer95113 жыл бұрын
You deserve more subscribers, great job
@firstgrandmasterx3 ай бұрын
Great video
@crash4o42 жыл бұрын
Good video doing oswe now and gives me a insight on how to document my steps.
@adalbertoguerra84023 жыл бұрын
Great content.!!! Very educational.!!! I am wondering if you can make a video explaining what are the steps to learn zero-day vulnerabilities.
@000t93 жыл бұрын
Oh thank you bro! Nice tools!
@mahdimix54682 жыл бұрын
You have amazing voice 😍, I have a feeling that telling me that you should be famous in this field, work hard as much as you can
@MygenteTV Жыл бұрын
So basically a zero day is any cve before you make it a cve?
@cwinfosec Жыл бұрын
Sorta but not exactly. Definitions vary, but generally the term "zero-day" comes from the fact that once a vulnerability has been discovered and an exploit developed for it, the vendor has had zero days to patch or fix it before attackers are able take advantage of it. If the developer knows about a vulnerability, but hasn't released a patch yet we typically refer to them as "N-day"
@MygenteTV Жыл бұрын
@@cwinfosec I see, Thank you. So to put it in a very simplistic way. Let's say I find a RCE/sqli in a software(SuperFive) many companies around the world use SuperFive. Now I can just hack any SuperFive user because they don't know about my discovery, unless I tell the world about and to make it more effective, I made a python script that will do my manual steps in auto
@CustomDabber3603 жыл бұрын
Do you talk to your mother with that voice?
@snailsec2 жыл бұрын
great info :D can you tell me how much time on avg does it take for you to discover a zero day like you've shown in the video???? also do you have any tips when starting to hunt 0day in the wild?
@cwinfosec Жыл бұрын
I'm sorry for taking so long to respond. It really depends on the app, sometimes I've found them within an hour, sometimes it took me a day or so after initially investigating. Especially when you consider the skill requirement for certain binary vulnerabilities, it can really take a lot of time to develop a working POC. The important part is hunting for bugs, whether you ultimately find one or not isn't important, just looking for them in the first place is IMO. Best of luck to you my friend!
@audiobook8903 жыл бұрын
Hmm awesome.
@taiquangong9912 Жыл бұрын
Long time
@samsepi01013 жыл бұрын
Great Content, but why was your voice shaking?
@user-dw9tx5sp2z7 Жыл бұрын
Throwaway your backspace man. It is making your life so sad