Low level logic flaw (Video solution, Audio)

  Рет қаралды 18,827

Michael Sommer

Michael Sommer

Күн бұрын

Пікірлер: 14
@vilislacis3337
@vilislacis3337 Жыл бұрын
I didn't know about "Null payloads", so I used "Numeric Payload", told it to generate random number from 99 to 99 and put it into QTY field:)
@0xfsec
@0xfsec 3 жыл бұрын
Is there anyway I can do this with turbo intruder?
@leghdaf
@leghdaf 9 ай бұрын
We need more explanation in these labs for each step
@techwithshudarsan559
@techwithshudarsan559 3 жыл бұрын
Why did you generate exactly 323 payload?
@durzodhon
@durzodhon 3 жыл бұрын
Coz solution says 😂
@techwithshudarsan559
@techwithshudarsan559 3 жыл бұрын
@@durzodhon 🤣🤣🤣🤣
@mariiatiurina3372
@mariiatiurina3372 2 жыл бұрын
It was needed to overflow the total $ sum. The total sum of $ have to be bigger than max integer, which validates this field. Looks like it's 4-byte Int, but last two signs are dedicated to cents, so the amount of $ you need "to cross over" is more than 42 949 672.95 As each our payloads are worth of $1337*99 = $132 363 to cross the border you need to perform 42 949 672.95/132 363 = 324.48.. attacks. so, he started from he first one and added 323 on top and boom, the total sum overflowed :)
@itsm3dud39
@itsm3dud39 2 жыл бұрын
@@mariiatiurina3372 can you refer a video to understand this concept clearly?
@pickledaardvark1532
@pickledaardvark1532 2 жыл бұрын
@@itsm3dud39 kzbin.info/www/bejne/epPFmZKip8ead7c
@gjsatru3383
@gjsatru3383 2 жыл бұрын
The worst explanation I ever saw
@rohanmadiratta6421
@rohanmadiratta6421 2 жыл бұрын
Nice lab imo
Inconsistent handling of exceptional input (Video solution, Audio)
9:53
Infinite money logic flaw (Video solution, Audio)
9:24
Michael Sommer
Рет қаралды 14 М.
SIZE DOESN’T MATTER @benjaminjiujitsu
00:46
Natan por Aí
Рет қаралды 7 МЛН
Turn Off the Vacum And Sit Back and Laugh 🤣
00:34
SKITSFUL
Рет қаралды 9 МЛН
How Much Tape To Stop A Lamborghini?
00:15
MrBeast
Рет қаралды 252 МЛН
Business Logic 5 | Low-level Logic Flaw #portswigger
15:09
HMCyberAcademy
Рет қаралды 1 М.
Top privilege escalation techniques - bug bounty case study
22:41
Bug Bounty Reports Explained
Рет қаралды 3,9 М.
Username enumeration via response timing (Video solution, Audio)
10:01
Lab: HTTP request smuggling, basic TE.CL vulnerability
14:16
Jarno Timmermans
Рет қаралды 12 М.
Why Agent Frameworks Will Fail (and what to use instead)
19:21
Dave Ebbelaar
Рет қаралды 93 М.
Business Logic 10 | Infinite Money Logic Flaw #portswigger
14:26
HMCyberAcademy
Рет қаралды 1,1 М.
SIZE DOESN’T MATTER @benjaminjiujitsu
00:46
Natan por Aí
Рет қаралды 7 МЛН