#NahamCon2024

  Рет қаралды 8,577

NahamSec

NahamSec

Күн бұрын

Пікірлер
@joy3658
@joy3658 7 ай бұрын
IT's 3.55 I am on now. Just Awesome and great talk. Keep up the great work, Ben! You are giving gems to the community. Thanks man.
@detecht
@detecht 7 ай бұрын
That was super cool. Amazing work, Lupin. And the presentation was awesome. Thank you, Nahamsec!
@alientec258
@alientec258 7 ай бұрын
Thank you so mutch Lupin for this awesome presentation . Ben thx for sharing , grateful for it my Friend
@harshil.
@harshil. 7 ай бұрын
Amazing presentation, whoever does the marketing/graphic design for Lupin is the 🐐
@1ko9
@1ko9 7 ай бұрын
Thank you Lupin for this great presentation and Ben for sharing these great presantations with us!
@EnglishItalian1
@EnglishItalian1 6 ай бұрын
Amazing presentation, thank you Lupin ;-)
@zzzzzzzzZzZZzzzaZzz
@zzzzzzzzZzZZzzzaZzz 7 ай бұрын
that was a pretty cool Finding! especially the widespread vuln sounds interesting
@123454321pavel
@123454321pavel 7 ай бұрын
What was the impact of the last vulnerability? Attacker could bruteforce secrets of users via csrf?
@KarahannAe
@KarahannAe 7 ай бұрын
11:06 this tool sounds really useful. Is there a link for it?
@bugbountythings-y8y
@bugbountythings-y8y Ай бұрын
You can use graphql-path-enum, it's very similar to what he show there
@crusader_
@crusader_ 7 ай бұрын
The slides are very fun to watch
@MarkFoudy
@MarkFoudy 7 ай бұрын
Thank you, Ben!
@breakoutgaffe4027
@breakoutgaffe4027 7 ай бұрын
Great talk!
@jannmoon
@jannmoon 6 ай бұрын
This is a good dude 🥂
@normalitee0os
@normalitee0os 6 ай бұрын
How exactly is the SOP bypassed in the last vulnerability?
@DewamJayasooriya
@DewamJayasooriya 7 ай бұрын
Nice bro...@Nahamsec keep it up
@crusader_
@crusader_ 7 ай бұрын
Hell yeah
@Test-ny6uh
@Test-ny6uh 7 ай бұрын
#NahamCon2024
@cowid
@cowid 6 ай бұрын
SOP doesnt allow you to send requests cross-sites. In SOP there is the letter O, which stands for Origin. An origin is not a site, those are two different concepts. And by definition, SOP does not protect from CSRF. It protects from COW (Cross Origin Writes). I like the energy and the enthusiasm, we need that in the field, but if you want to present something and don't want to sound like you dont know what you're talking about, I would suggest you do your homework before. Thank you for sharing anyway.
@baraamansi7637
@baraamansi7637 6 ай бұрын
Actually he is right , If the content-type was application/json this would be considered as not-simple request for the browser and would require a preflight request which would block the XS-search(Get based CSRF) request because its not a trusted origin
@cowid
@cowid 6 ай бұрын
@@baraamansi7637 Re-read my comment, thank you.
@baraamansi7637
@baraamansi7637 6 ай бұрын
@@cowid I'm aware of my comment bro, If there is anything wrong with his concepts then you can mention the timeline and explain your opinion ,otherwise I'm not seeing what are you pointing for
@cowid
@cowid 6 ай бұрын
@@baraamansi7637 I'm not your bro son, for one thing. Secondly, it's not a coNcEpT problem. It's a terminology problem. Words and acronyms have meaning. Throwing a bunch of acronyms around without understanding what they entail makes you sound like someone who does't fucking know what you're talking about. For the timeline, you can refer to the entire video that is pretty much glib the entire time. To answer specifically your question, 20 mins mark: "...authorized by the same origin policy to be sent cross-site". SOP doesnt allow or prevent from accessing resources cross sites. Again, re-read my first comment. Sites and origins are two different things. We can go on all day like that, bro.
@baraamansi7637
@baraamansi7637 6 ай бұрын
@@cowid Take it easy man,It's not that massive problem if he did a little mistake, As long as the concepts are valid and there is benefit it's totally fine to share we are not perfect .Secondly,There is no need for the agressive attitude brooo, LOL
@trustedsecurity6039
@trustedsecurity6039 7 ай бұрын
With all the ads around i've vomited... After a few minutes go full screen... I dont even understand why sponsor are needed on a Twitch stream but meh
@mohadjermohamed4668
@mohadjermohamed4668 5 ай бұрын
Bro stop telling « n’importe quoi » Graphql is a data structure where php is web programming language 😅
#NahamCon2024: .js Files Are Your Friends | @zseano
24:04
NahamSec
Рет қаралды 11 М.
#NahamCon2024: OAuth Secret | @BugBountyReportsExplained
20:44
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН
Cheerleader Transformation That Left Everyone Speechless! #shorts
00:27
Fabiosa Best Lifehacks
Рет қаралды 16 МЛН
DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
32:30
DEFCONConference
Рет қаралды 54 М.
Learn Nuclei in 30 minutes - DEF CON Nuclei Demo
35:48
ProjectDiscovery
Рет қаралды 12 М.
3 Real API Bugs I got a bounty for
17:43
InsiderPhD
Рет қаралды 10 М.
What is OSINT? (With Examples)
18:56
NahamSec
Рет қаралды 12 М.
$20,000 Hackerone data leakage via GraphQL
6:33
Bug Bounty Reports Explained
Рет қаралды 22 М.
Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99)
1:42:55
Critical Thinking - Bug Bounty Podcast
Рет қаралды 9 М.
How to Stalk People Effectively and Legally Through OSINT
18:34
How to exploit GraphQL | GraphQL for Beginners
14:46
CyberSecurityTV
Рет қаралды 7 М.
$20,000 In Bounties From Hacking Into A Prison
35:14
NahamSec
Рет қаралды 12 М.
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН