Lab: Exploiting HTTP request smuggling to perform web cache poisoning

  Рет қаралды 1,682

Jarno Timmermans

Jarno Timmermans

Күн бұрын

Пікірлер: 7
@netletic
@netletic Жыл бұрын
Hey everyone! Check out this playlist for all my solutions to the HTTP Request Smuggling labs from PortSwigger - 👀 kzbin.info/aero/PLGb2cDlBWRUX1_7RAIjRkZDYgAB3VbUSw Here are the timestamps for this video - ⏱ 00:00 - Intro 00:38 - Detect the CL.TE vulnerability 02:02 - Confirm the CL.TE vulnerability 03:54 - Find & turn onsite redirect into offsite redirect 05:37 - Find static asset cached by frontend 06:42 - Poison the frontend server's cached asset
@cowid
@cowid 3 ай бұрын
Jarno, you really have a knack for breaking down complicated steps into something easier to digest. The effort you put in shows, and the quality is top-notch! Most content creators out there solely click around or paraphrase the solution out loud without much explanation, but you stand out by breaking everything down piece by piece. Your understanding of the topic really shines through. I hope you will continue adding content, you save me hours of headache !
@bolbolinfosec1376
@bolbolinfosec1376 6 ай бұрын
I am sincerely grateful to you , Thanks Bro ❤❤❤ you excel as an educator!
@huyhuynh5575
@huyhuynh5575 3 ай бұрын
Thank you! I really enjoyed the video, especially how you made everything seem so simple. I particularly liked the backend part where every 30 seconds, it takes a JS file. By injecting our JS payload, anyone accessing the page triggers the payload.
@aow6813
@aow6813 3 ай бұрын
yeh this lab is so good i like it
@amrzaki850
@amrzaki850 Жыл бұрын
This is so great; thank you keep up the good work.
@netletic
@netletic Жыл бұрын
thank you @amrzaki850, really nice to hear! ☺️
Lab: Exploiting HTTP request smuggling to perform web cache deception
6:08
Lab: Web cache poisoning via HTTP/2 request tunnelling
10:34
Jarno Timmermans
Рет қаралды 1,3 М.
Из какого города смотришь? 😃
00:34
МЯТНАЯ ФАНТА
Рет қаралды 1,4 МЛН
Which team will win? Team Joy or Team Gumball?! 🤔
00:29
BigSchool
Рет қаралды 15 МЛН
Web Cache Deception Attack
23:02
Black Hat
Рет қаралды 21 М.
Lab: Exploiting HTTP request smuggling to capture other users' requests
13:05
Lab: CL.0 request smuggling
5:40
Jarno Timmermans
Рет қаралды 1,7 М.
WEB CACHE POISONING - BRIEF
21:34
Mohd Badrudduja
Рет қаралды 1,2 М.
HTTP/2: The Sequel is Always Worse
38:14
Black Hat
Рет қаралды 7 М.
Lab: Web cache poisoning with multiple headers
11:02
Jarno Timmermans
Рет қаралды 1,8 М.
Из какого города смотришь? 😃
00:34
МЯТНАЯ ФАНТА
Рет қаралды 1,4 МЛН