as a guy used to Burp community I would have used python to prepare word list all hashed up like that... it takes me forever but it's nice to see the way the smart kids do it.
@markthorson27133 жыл бұрын
Could ya use the "intruder" battering ram attack with payload processors... Intruder Works in community edition just rate limited IIRC 🤔 but Zap is dam good too (i prefer their proxy workflow over burp CE).
@stuxed3 жыл бұрын
Lol, I had the same issue with Burp licence! Good timing, thanks.
@RickyBana3 жыл бұрын
Great video, please do more of this with ZAP
@SpragginsDesigns2 жыл бұрын
I used this for a pentest last weekend. I only used two websites, and one is quite popular. I got someone's Visa card from the second one. The first one was flagged like it was built to be hacked. I also had to dig deep into their policies to figure out there's no explanation for FaceBook, Stripe, Serio and 4 other APIs doing GET and more destroying any way of making what our company needed compliant to use. They also have no nothing about security for Q1 2022. And I sent them my pentest report, and with the shocking details of being able to literally browse each users database they haven't reached back in 6 days! I usually use this to scan, but I took a deep dive into the extra add-ons while putting Ubuntu on my Microsoft Surface 😂
@ericneo23 жыл бұрын
Thank you for the tutorial and you gave the links to the resources. 👍
@stefanivanov82742 жыл бұрын
It will be great if there is comparison between the speed of brute-force with Burp CE, Burp Pro, ZAP and Python script. May be with other languages too ;]
@lityoshii10863 жыл бұрын
Stay consistent bro
@harshamannewton3 жыл бұрын
nice video ...but where this can be useful? in only bruteforcing ?
@MefiMaxi3 жыл бұрын
Love this stuff ^^
@bluecreature393 жыл бұрын
Montana represent
@funkymonk22543 жыл бұрын
Thanks Kody.
@dahuynguyenphuc658610 ай бұрын
The first time I security scanned a website with OWASP ZAP, a bunch of data appeared in the "alert" section , The next day when I continued to scan that website, but " alert " item appeared nothing ? Is the data I scanned the first time still saved? how to get it??
@damnson28062 жыл бұрын
Hi! I have a question, would it be possible to use pinephone pro instead of nethunter? They say it has root privileges by default, and also comes with linux terminal, but idk if its apt to do the same thing as a rooted android phone
@7barney9142 жыл бұрын
is this guy the same guy in null byte? Something pretty similar both guys don't blink at all
@curtisjones19876 ай бұрын
😂 same guy
@ovskihouse52712 жыл бұрын
I wana ask you i wish that you respond me very soon .. i opened a session in udemy with cookies and after minites i'd close a session .. but when i would reopened again with same cookies it failed.. how to login again and again?
@AdeelAnsariUS2 жыл бұрын
Great video.
@Elsag_GeliNakh3 жыл бұрын
Fantastic 🤣👍✔️
@TheClubPlazma2 жыл бұрын
Nice one thank you
@ChrisSamsonUSA2 ай бұрын
is it possible to find the actual source of the API url? For example, if there is an API /POST/SERVE/12345, but it's getting the object from the GCS and serving, how to you see the actual URL?
@SecurityTalent3 жыл бұрын
Thanks
@salhilahcene86982 жыл бұрын
I love it
@VituralHwang2 жыл бұрын
does this work with gmail ?
@denverm790910 ай бұрын
how to get rid of this virus cookies?
@abrahamnorada68153 жыл бұрын
amazing :o
@hvgaming23473 жыл бұрын
Does he even blink ????
@5ql1562 жыл бұрын
Using Owasp Zap on Burpsuits labs lol
@abdikanifaysal20023 жыл бұрын
First from somalia
@chrisw14623 жыл бұрын
You have the 3-4 kHz band filtered too hard - much harder than the last Hak5 video you did. Makes it very hard to listen to. As soon as I heard it I knew, but I brought up my audio spectrum analyzer to verify it. There's almost zero energy at those frequencies. Do you know how important this band is for human speech comprehension? I'd like to believe it's a mistake, but more and more KZbin people are doing this, supposedly to try to 'add bass' to your voice. Okay, if you wanna add bass, ADD BASS. Stop nerfing 4 kHz into the ground.
@lazycreater13022 жыл бұрын
Plz make video on bypassing android 12 google account
@cian0r2 жыл бұрын
this method good but my Priority open bullet
@sterlinwright41732 жыл бұрын
You don't start off with a whole bunch of words on the screen your scaring the children