Hacking websites with great demos! (XXE Hacks)

  Рет қаралды 23,711

David Bombal

David Bombal

Күн бұрын

Пікірлер: 58
@davidbombal
@davidbombal 4 күн бұрын
Big thank you to Brilliant for sponsoring this video! To try Brilliant for free (for 30 days) and to get a 20% discount, visit: Brilliant.org/davidbombal // Tib3rius’ SOCIAL // KZbin: kzbin.info Website: tib3rius.com/ Twitch: www.twitch.tv/0xTib3rius GitHub: github.com/Tib3rius LinkedIn: www.linkedin.com/in/tib3rius/ X: x.com/0xtib3rius Bluesky: bsky.app/profile/tib3rius.bsky.social // Links REFERENCE // XXE Demo Repo: github.com/Tib3rius/XXE-Demos Dynamic Tool-DTD Repo: github.com/Tib3rius/Dynamic-DTD // Specific Webpage REFERENCE // en.wikipedia.org/wiki/Billion_laughs_attack tib3rius.com/robots.txt // David's SOCIAL // Discord: discord.com/invite/usKSyzb X: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal KZbin: www.youtube.com/@davidbombal // MY STUFF // www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up0:33 - Intro 03:07 - Brilliant Advert 04:22 - What is XXE 06:24 - XXE Demo Intro 08:54 - XML Spec Defined Entities 13:27 - XML Billion Laughs Attack 15:07 - XML Exploits 16:27 - XXE Demo Basic Example 1 22:33 - XXE Demo Basic Example 2 23:33 - Error-Based XXE Demo 30:11 - Dynamic DTD Demo 34:45 - The Community 35:33 - Out-Of-Band XXE Demo 40:12 - XML Tips & Tricks 41:25 - Outro xxe xss xml http https website xml external entities cross site scripting portswigger ajax jscript lol lol attack billion laughts billion lol javascript xss attack xxe attack xxe video tutorial xxs attack tutorial xxe explained xss explained xxe attack example xxe bug bounty xxe tutorial xxe vulnerability xxe vs csrf attack xe example kali linux penetration testing ethical hacking bug bounty cross site scripting cross-site scripting red teaming cyber security kali linux install kali linux 2025 ethical hacker course ethical hacker javascript ajax jquery node js node js hacking portswigger Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #xxe #xss #hacking
@rishiraj2548
@rishiraj2548 4 күн бұрын
🎉
@Tib3rius
@Tib3rius 4 күн бұрын
Thanks for having me on the show David! Glad I can share these fun / crazy exploit techniques with a wider community!
@sp99nz3
@sp99nz3 Күн бұрын
I liked the video where can i start when it comes to ethical hacking should i consider programming and networking just needed an advise on where to start
@GajendraMahat
@GajendraMahat 19 сағат бұрын
Happy to you see here, sir 🥰🥰
@Whydidyouusemyname
@Whydidyouusemyname 4 күн бұрын
The second X is a play on Ex just like XML is for extensible. This is why it is XXE instead of XEE.
@gamereditor59ner22
@gamereditor59ner22 4 күн бұрын
Cool! Thank you, David, for the video, and thank you, Tib3ius, for the demo!
@davidbombal
@davidbombal 4 күн бұрын
Glad you liked it!
@rubenrodenascebrian3855
@rubenrodenascebrian3855 4 күн бұрын
In the CBBH, I found this much more advanced vulnerability with DTD and I tried to bypass the image file, the SVG.
@xu83r
@xu83r 4 күн бұрын
I was unable to upload a svg?
@ByteBite101
@ByteBite101 4 күн бұрын
While making animated explainers.. I use your video for refresher 🔥
@jessie17650
@jessie17650 4 күн бұрын
I love your explainers
@ByteBite101
@ByteBite101 4 күн бұрын
@@jessie17650 My man
@NextGenSellPOS
@NextGenSellPOS 4 күн бұрын
I just watched whole video. Great content
@davidbombal
@davidbombal 4 күн бұрын
Glad you enjoyed the video!
@TheCodeNinjas
@TheCodeNinjas 3 күн бұрын
Thanks David and Tib3rius, very interesting content.
@hellamean
@hellamean 4 күн бұрын
Interesting, tryna learn XXE to help enhance my Bug Bounty Skills.
@davidbombal
@davidbombal 4 күн бұрын
Tib3rius does an amazing job teaching us XXE!
@hellamean
@hellamean 4 күн бұрын
@ Yes, I can tell from the video… I was thinking if we could collaborate on a podcast? I added you on LinkedIn.
@hellamean
@hellamean 4 күн бұрын
@@davidbombal Yes, I can tell from the video.
@Kwayjaye
@Kwayjaye 4 күн бұрын
Great job explaining xxe
@majiddehbi9186
@majiddehbi9186 4 күн бұрын
Good video as it's very helpfull that any network engineer need to know something about websites good initiative from uou David thx as always
@davidbombal
@davidbombal 4 күн бұрын
Than you! And you're welcome!
@Lykos-i2m
@Lykos-i2m 2 күн бұрын
The error based XXE looks like a robbery...ha ha ha
@payloadhack
@payloadhack 4 күн бұрын
Not many people know these types of web attack, so they are actually a good way to hunt a bug
@adekojoadeyemi2596
@adekojoadeyemi2596 4 күн бұрын
First time I see my like count. Very happy 😁
@MG-bm5oj
@MG-bm5oj 3 күн бұрын
It’s a kind of hard to find a video with a guest. Would be great if you add in the description the video with Rana
@janekmachnicki2593
@janekmachnicki2593 4 күн бұрын
Thanks Mr Bombal .Thanks for brilliant stuff you upload .It's been a few years since I've been follow your YT and Udemy content .Thanks a lots !!!!!
@davidbombal
@davidbombal 4 күн бұрын
Thank you!
@Mecagothits
@Mecagothits Күн бұрын
I thought hack only happen with Linux
@TheRealVegapunk
@TheRealVegapunk 4 күн бұрын
Tib3rius my man 🥳
@Crusaderon
@Crusaderon 4 күн бұрын
THX David! What's about LinkedIn?
@davidbombal
@davidbombal 4 күн бұрын
Thank you for your support! Much appreciated! Not sure I understand what do you mean about LinkedIn?
@Crusaderon
@Crusaderon 3 күн бұрын
@@davidbombal It's me Sascha!
@BellaSteery
@BellaSteery 4 күн бұрын
Can you do a video on how a person can force their phone to only run on 5G standalone to enable their phones identifier information to have the highest level of protection please? 5G SA IS the only way to stop an IMSI ATTACK. Please look that up and teach us :)
@oneloveafrica8860
@oneloveafrica8860 Күн бұрын
error based XXE is very cool .. tanks sir
@BunnyShark-q8z
@BunnyShark-q8z 4 күн бұрын
Make a video about local AIs e.g: Dolphin Mixtral 8x7b
@ادمزروق-ق6ج
@ادمزروق-ق6ج 4 күн бұрын
Please kali linux series
@Fabian-d6n
@Fabian-d6n 4 күн бұрын
We need master otw please 🙏🙏❤
@Kigenyi_Rahman
@Kigenyi_Rahman 4 күн бұрын
David can you create a Tutorial about configuring Linux for White hat hacking as in checking database vulnerabilities, please
@davidbombal
@davidbombal 4 күн бұрын
Great suggestion!
@funcool3451
@funcool3451 4 күн бұрын
No comments?
@davidbombal
@davidbombal 4 күн бұрын
Lots of comments on the video already...
@funcool3451
@funcool3451 4 күн бұрын
@davidbombal well I have a crappy internet connection and really love stuff you do and I particularly remember the video on Kali Linux about wifi where you were using Virtual box and was a requirement to own a adaptor type of thing but for same Problem we could easily use live boot usb which is easily available on any country ( especially for least developing countries where there is hard to find new techs) love your videos
@EthicalByteExplorers
@EthicalByteExplorers 4 күн бұрын
Bro how to use esp 288 chip vedio plz❤
@Joe-gl8sr
@Joe-gl8sr 4 күн бұрын
Wow interesting stuff here!!!
@marshall1693
@marshall1693 4 күн бұрын
I love xxe
@davidbombal
@davidbombal 4 күн бұрын
Happy to hear that!
@GamerX_Gaming5515
@GamerX_Gaming5515 4 күн бұрын
@BruceLeaak
@BruceLeaak Күн бұрын
Great ! DONE.
@00Jimmy00
@00Jimmy00 Күн бұрын
i am java dev :D
@BellaSteery
@BellaSteery 4 күн бұрын
Can you do an updated video on how a regular person with no computer program literacy can run MVT- Mobile Verification Toolkit and IMazing on iPhones to check for high level threats? I believe this is much needed
@asifthelion9280
@asifthelion9280 4 күн бұрын
Sir you are great😊
@awais0x1
@awais0x1 10 сағат бұрын
I love @Tib3rius content ❤ And CTF 🎉
How to be Invisible Online (and the hard truth about it)...
53:16
David Bombal
Рет қаралды 2,1 МЛН
Will this even work today?
20:24
David Bombal
Рет қаралды 28 М.
UFC 310 : Рахмонов VS Мачадо Гэрри
05:00
Setanta Sports UFC
Рет қаралды 1,2 МЛН
Ex-NSA hacker tools for real world pentesting
1:16:40
David Bombal
Рет қаралды 1,1 МЛН
This Video is AI Generated! SORA Review
16:41
Marques Brownlee
Рет қаралды 3 МЛН
Trolling Hackers with a Honeypot and how you can too
20:08
Gnar Coding
Рет қаралды 6 М.
Bootkitty - The First UEFI Bootkit That Targets Linux
8:08
Mental Outlaw
Рет қаралды 120 М.
Hacking Tools (with demos) that you need to learn in 2024
1:27:34
David Bombal
Рет қаралды 759 М.
FREE Malware Removal Tools That Actually Work!
27:21
Ask Your Computer Guy
Рет қаралды 75 М.
Albanian Hacking Tool (ALHacking Tool)!
6:10
Hacker Joe
Рет қаралды 25 М.
Be Invisible Online and Hack like a Ghost
54:09
David Bombal
Рет қаралды 364 М.
Finally a Mac for This Economy - Mac Mini M4
13:44
Linus Tech Tips
Рет қаралды 1,2 МЛН