Hacking Websites by Uploading files (With symlinks)

  Рет қаралды 19,544

Tech Raj

Tech Raj

Күн бұрын

Пікірлер: 62
@SteveBClark
@SteveBClark Жыл бұрын
The GOAT is back....❤
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
:3 I wonder if this can be used on my bug bounty targets. Also, I'm wondering how many Iranian, Lebanon, Saudi Arabian, North Korea, China, and other sites of terrorist, and dictatorship nations I get can into. 😅🥰🤑😋🤤 Great Indian hacker video. English. :3 😅 Shalom. Namaste.
@schooldropout1337
@schooldropout1337 Жыл бұрын
Is finding a way to upload files without following the usual restrictions considered a security problem? Yes, bypassing file upload restrictions is a security vulnerability because it can potentially allow malicious files to be uploaded to a system, which can lead to various security risks and issues.
@ANKUR--xoxo
@ANKUR--xoxo Жыл бұрын
How to do that
@schooldropout1337
@schooldropout1337 Жыл бұрын
@@ANKUR--xoxo bro raj will provide an exclusive demo for that scenario 🤠
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
Thanks for the donation, and question, brother! 🤝🤑☺️
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
:3 I wonder if this can be used on my bug bounty targets. Also, I'm wondering how many Iranian, Lebanon, Saudi Arabian, North Korea, China, and other sites of terrorist, and dictatorship nations I get can into. 😅🥰🤑😋🤤 Great Indian hacker video. English. :3 😅 Shalom. Namaste.
@raoulduke8064
@raoulduke8064 Жыл бұрын
yeees new video! GOAT is back
@divyam847
@divyam847 Жыл бұрын
glad that you're back :)
@anudeepkalyadapu1657
@anudeepkalyadapu1657 Жыл бұрын
What a video ! Looking forward for such videos man! Keep it up
@TejaRavipudi
@TejaRavipudi Жыл бұрын
big fan. happy that you are back.
@mindlesstelevision3213
@mindlesstelevision3213 Жыл бұрын
Good to see you Back ❤️♥️
@_SebJ1000
@_SebJ1000 Жыл бұрын
It's intresting to learn that they place the password in an environment variable, wonder if most devs encrypt it as well. As that might be the slightest bit more secure.
@dishusharma7881
@dishusharma7881 Жыл бұрын
Where did you learn to pronounce environment as enveeronment? I am curious.
@HackingBinaries-dt2fh
@HackingBinaries-dt2fh Жыл бұрын
Love you man, just subscribed
@TechnicalHeavenSM
@TechnicalHeavenSM Жыл бұрын
😍😍😍.. You are back❤❤
@Nin_Cada
@Nin_Cada Жыл бұрын
So what is the counter of it? How to not let the hackers get access to the filesystem using symlincks?
@ClashWithHuzefa
@ClashWithHuzefa Жыл бұрын
Check whether if it is a symlink file or not, and don't let the Web server read, access directories, or file outside the Web root. If you are using php, there is a function is_link() to check whether its a symbolic link file or not
@Nin_Cada
@Nin_Cada Жыл бұрын
@@ClashWithHuzefa i see.. So, couple of rules for the webserver should do the trick. Thanks ✨
@ClashWithHuzefa
@ClashWithHuzefa Жыл бұрын
@AkeaNine welcome buddy
@SankalpaBaral1337
@SankalpaBaral1337 Жыл бұрын
Brother do you remember you used to create challenges (like CTF)? Please make those types of videos again.
@pinged69
@pinged69 Жыл бұрын
Does this affect sites that do not do anything with the file, just purely serve it? I have a pretty basic file hosting service thats public, do I need to somehow worry about this? Symlinks are not something that can be POSTed over HTTPS, right?
@prudhvikonakalla9605
@prudhvikonakalla9605 Жыл бұрын
Raj-"kingu kingu"
@TheAKAnonymous
@TheAKAnonymous Жыл бұрын
a suggestion, maybe you should try different titles something special surprising to be able to get more views adding curiosity to new students i mean we are technical student we understand your titles but new students might not and last thing as always this was a awesome video your's TheAKAnonymous
@anuzravat
@anuzravat Жыл бұрын
is there some related article for this symlink vuln, u would like to recommend
@jesusdacoast872
@jesusdacoast872 5 ай бұрын
Very informative, thanks.
@manishneupane6070
@manishneupane6070 Жыл бұрын
Wow, great video. Thank you for making
@NateSec-d2d
@NateSec-d2d 6 ай бұрын
Good content Man.
@montala3380
@montala3380 10 ай бұрын
Hi brother, the symlink is only work when target site use ZIP/ TAR. How about normal upload file? can I upload that symlink file to retrieve the content?
@ANKUR--xoxo
@ANKUR--xoxo Жыл бұрын
THAT WAS CRAZYYYYYY BRUHHHHH 🔥🔥🔥🔥🔥❤❤❤❤
@sagarhp2350
@sagarhp2350 Жыл бұрын
He's back.. 🤩
@monsterzero6928
@monsterzero6928 Жыл бұрын
Can you please make a video on burpsuite how to inject files on servers by changing the file extension and injecting a backdoor with that
@SwineTech
@SwineTech Жыл бұрын
Daemon, a program that runs in the background, anyone noticed the daemon
@Si6n9ne
@Si6n9ne Жыл бұрын
where to get this source file of the one you doing right now,
@Tankbuild-t2i
@Tankbuild-t2i Ай бұрын
you can also direct it make a zip file that contains backdoor shell (shell.php)
@st.john_one
@st.john_one Жыл бұрын
pretty informative and cool, thanks
@Si6n9ne
@Si6n9ne Жыл бұрын
Is there any way to recreate this vulnerability, I wanna try and test it out If yes someone point me to it please
@rajeevpuri8319
@rajeevpuri8319 Жыл бұрын
thank you Sir , for this easy to understandable video for a noob like me.🙏🙏
@scorpionisready
@scorpionisready 5 ай бұрын
Informative ❤️
@lnstagrarm
@lnstagrarm Жыл бұрын
More unique python projects please
@gowthamreddysomala
@gowthamreddysomala Жыл бұрын
Anna nee Videos Kosam Wait Chastunnam ..
@mahesharyatech
@mahesharyatech Жыл бұрын
Any Issues With Users ?
@usningame5177
@usningame5177 Жыл бұрын
Do you provide. Course
@evilspidy6924
@evilspidy6924 Жыл бұрын
Is this exploit have any number like cve-#####
@Topfive_realestate
@Topfive_realestate Жыл бұрын
Love you bro 💪💪
@rishi8413
@rishi8413 Жыл бұрын
love the explaination
@jimmlmao
@jimmlmao Жыл бұрын
thats actually genius
@khushipardeshi3114
@khushipardeshi3114 8 ай бұрын
Hua kisi se actually hack??
@TheAKAnonymous
@TheAKAnonymous Жыл бұрын
so late to watch your video
@byte01-h1z
@byte01-h1z 2 ай бұрын
Nice !
@Faysalauchan
@Faysalauchan 7 ай бұрын
😮😮 so amazing
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
:3 I wonder if this can be used on my bug bounty targets. Also, I'm wondering how many Iranian, Lebanon, Saudi Arabian, North Korea, China, and other sites of terrorist, and dictatorship nations I get can into. 😅🥰🤑😋🤤 Great Indian hacker video. English. :3 😅 Shalom. Namaste.
@ClashWithHuzefa
@ClashWithHuzefa Жыл бұрын
Amazing
@JohnDoe-xp9rd
@JohnDoe-xp9rd Жыл бұрын
Cool
@pavansasank
@pavansasank Жыл бұрын
@vicmacarra
@vicmacarra Жыл бұрын
Lel, interesting
@IDK_911
@IDK_911 Жыл бұрын
just upload webshell
@PlayerOne69
@PlayerOne69 Жыл бұрын
@localh0ste
@localh0ste Жыл бұрын
@shahzansid
@shahzansid Жыл бұрын
@sbh3612
@sbh3612 Жыл бұрын
I used AI to hack this website...
23:23
Tech Raj
Рет қаралды 146 М.
Мен атып көрмегенмін ! | Qalam | 5 серия
25:41
Can you get Hacked by just clicking a Link?
10:46
Eric Parker
Рет қаралды 158 М.
Watch how Hackers deface websites...
8:39
Tech Raj
Рет қаралды 20 М.
How Hackers Spy on you from your own WiFi!
12:23
Tech Raj
Рет қаралды 756 М.
Web Application Hacking - File Upload Attacks Explained
17:24
The Cyber Mentor
Рет қаралды 29 М.
I Hacked & Exposed This Fake Website for Educational Purposes - CTF
11:26
Hacking Websites With A Zip File (Zip Slip)
13:19
NahamSec
Рет қаралды 17 М.
I legally defaced this website.
25:48
thehackerish
Рет қаралды 531 М.