Reflected XSS protected by very strict CSP, with dangling markup attack (Video solution, Audio)

  Рет қаралды 14,967

Michael Sommer

Michael Sommer

Күн бұрын

Пікірлер: 15
@vidchan4247
@vidchan4247 2 жыл бұрын
This video would be far more helpful if you actually explained the mechanism (WHY it works), instead of just going through the steps which can be read in the solutions to the lab as well.
@cair0_
@cair0_ 3 жыл бұрын
i can't even imaging how did u think of this solution :(
@mazleens
@mazleens 2 жыл бұрын
instead of assuming that there is an XSS vuln in the email param, why don't you demonstrate it? the challenge does not mention anything (find out yourself).
@chadurdy7555
@chadurdy7555 3 жыл бұрын
Aloha! okay so I've tried every possible (to my limited knowledge) scenerio and can't seem to get the DNS/ HTTP interactions to show in the poll collaborator interactions window. Any insight would be greatly appreciated. Also thank you so much for your videos!! Truely a great and helpful suppliment to the Portswigger labs.
@chadurdy7555
@chadurdy7555 Жыл бұрын
@Simon Hitchens unfortunately no I did not.
@kilohsakul
@kilohsakul 6 ай бұрын
Giving us the solution is nice enough, but I was expecting an exaplanation too.
@camilohurtado4814
@camilohurtado4814 5 ай бұрын
Has anybody been able to solve this lab recently?
@mscreative3262
@mscreative3262 4 ай бұрын
Nooo, have you solved or not ?
@Karmik_bhavya
@Karmik_bhavya 4 ай бұрын
@@mscreative3262 i tried every freaking method even with burp collaborator its just not getting the robot user to click on the link
@defaultbykoyomi4371
@defaultbykoyomi4371 4 ай бұрын
I cannot resolve as well. the burp collaborator is not getting for robot user to click.
@camilohurtado4814
@camilohurtado4814 4 ай бұрын
I wasn't able to either.
@fmworld4219
@fmworld4219 Ай бұрын
Same here
@Nul1Secur1ty
@Nul1Secur1ty 10 ай бұрын
;)
Reflected XSS with some SVG markup allowed (Video solution, Audio)
7:31
Quando A Diferença De Altura É Muito Grande 😲😂
00:12
Mari Maria
Рет қаралды 45 МЛН
1% vs 100% #beatbox #tiktok
01:10
BeatboxJCOP
Рет қаралды 67 МЛН
What is Data? | Data Fundamentals for Beginners
6:56
Alex The Analyst
Рет қаралды 2,5 М.
CSRF where token is tied to non-session cookie (Video solution, Audio)
10:33
How to Crack Software (Reverse Engineering)
16:16
Eric Parker
Рет қаралды 836 М.
Paypal - Live bug bounty hunting on Hackerone  | Live Recon | part 2
34:52
Lab: HTTP request smuggling, basic TE.CL vulnerability
14:16
Jarno Timmermans
Рет қаралды 13 М.