Server-Side Request Forgery (SSRF) Explained

  Рет қаралды 27,396

NahamSec

NahamSec

Күн бұрын

Пікірлер: 102
@francoischaer
@francoischaer Жыл бұрын
hey Ben, we surely already love your content, but, for those like me, who are new to the industry, trying to learn and move forward, we need the technical, very basic content, this will help us understand more in depth how things goes. thank you again for the great content you are delivering, and for the amount of dedication you are putting in
@alechernandez5506
@alechernandez5506 3 ай бұрын
When there is an issue or something you understand you should go down the rabbit hole and” master “ it. I’m sure you’re doing well now, this comment was a year ago! But this comment is for people just learning 😁
@bashiqali2142
@bashiqali2142 Жыл бұрын
Content + real vulnerability example would be great 🔥
@baraamansi7637
@baraamansi7637 Жыл бұрын
OFC it would be truly helpful to see more content like this
@khalidmeister
@khalidmeister Жыл бұрын
Never thought I could learn SSRF in a more comprehensive way by under 15 minutes! Thanks man!
@NahamSec
@NahamSec Жыл бұрын
Thanks! I'm glad it helped!
@justice8476
@justice8476 16 күн бұрын
​@NahamSec دمت گرم مهندس، ارادت
@SanketUppalwar
@SanketUppalwar 9 ай бұрын
More content is needed like this along with real life examples that you experienced during bug bounty or other testing application
@Free.Education786
@Free.Education786 Жыл бұрын
Please, if possible, cover these advanced topics like How to bypass Drupal CMS or other secured CMS? How to bypass HARD WAF protection that stops HTML, SQL, and XSS injection payloads? Payload single-double-triple encoding using Cyber-Chef? How to find the real origin IP of secured websites behind Cloudflare, Akamai, ModSecurity, AWS CDN, etc.,? How to bypass Hard WAF using SQLMAP or Burpsuite? How to find hidden vulnerable parameters and endpoints inside the .js and .jason files? How to find hidden admin pages, cPanel pages, and WHM pages ? Please cover these important topics. Thanks
@andrewsan2998
@andrewsan2998 Жыл бұрын
East or West, naham is the best.
@JPwnage
@JPwnage Жыл бұрын
Man, keep both coming.!! maybe pick a day to post technical and assign another day for the mentorship aspects or something... Either way ... BOTH ARE EQUALLY IMPORTANT FOR SUCCESS!! ...Also i would love a video on how to transfer from labs /ctf into hacking real world apps. As the fundamentals are the same or close but also very different in alot of ways.
@supritpandurangi5647
@supritpandurangi5647 Жыл бұрын
Waiting for this type of content ; please Continue Ben :)
@billelghezal7855
@billelghezal7855 Жыл бұрын
Thank you very much, I hope you'll continue doing these kind of videos 😊
@yourinatestrn3436
@yourinatestrn3436 Жыл бұрын
Yea would love this type of content plz part 2
@Jarling-so4oi
@Jarling-so4oi 14 күн бұрын
Make more technical content
@GrimComix
@GrimComix Жыл бұрын
Yes, more content like this please 😁
@איתיאיתי-צ4ט
@איתיאיתי-צ4ט Жыл бұрын
Hi man, I would like to hear you how to do bug bounties exactly and maybe if you can show on live all the necessary steps to do it
@vaibhavsangwan996
@vaibhavsangwan996 Жыл бұрын
Hey I absolutely love this, I would love to learn from more technical videos like this.
@tehlan6340
@tehlan6340 Жыл бұрын
You are great bro
@CYBER_BLUE4
@CYBER_BLUE4 4 ай бұрын
Part two
@amoh96
@amoh96 Жыл бұрын
We really want this explain bugs for beginners and give us some advice about the bug i really wish u make playlist for this !! thank u alot
@citywitt3202
@citywitt3202 11 ай бұрын
As CEO of a startup please keep this stuff coming. It took a lot to convince the dev team that exploits weren’t just down to weak passwords so I arranged an in house demo. Jaws dropped. This stuff builds so much awareness. Thank you!
@tabysh_s5016
@tabysh_s5016 Жыл бұрын
Ben One Suggestio | Make a precise playlist of OWASP TOP 10 2021 | Like a 10 min video / on each critical vulnerability
@augustvansickle1
@augustvansickle1 Жыл бұрын
Would love to see more technical content! TIA
@andrewlentz1205
@andrewlentz1205 Жыл бұрын
I think you should pivot to doing Unboxing Videos. If that's not in the cards then please keep the technical videos coming!
@sveneFX
@sveneFX Жыл бұрын
Fully in with technical vids, especially when you chain these with Real life vulns you have found 👌
@AnonymousWolf-r6d
@AnonymousWolf-r6d 7 ай бұрын
more vcontent like this cover all top 10 owasp vulnerability please...
@AdarshThakur-Official
@AdarshThakur-Official 2 ай бұрын
Please create similar content to this and please add Hindi subtitles for a better understanding
@djrozh5438
@djrozh5438 Жыл бұрын
Creat a playlist content like the types of vulnerabilities and bugs that are common or rate easy to hard like xss or account takover
@imosolar
@imosolar Жыл бұрын
More real bugbouty tech work
@raghvendrachouhan3433
@raghvendrachouhan3433 Жыл бұрын
theory is all good but when it comes to practical i'm hopeless.
@tchalla109
@tchalla109 Жыл бұрын
Drop video with all of the topic you mentioned in the video.
@Tergaurav
@Tergaurav Жыл бұрын
Vulnerability content or owasp top 10 pls
@BulbulBigbossbd
@BulbulBigbossbd Жыл бұрын
Hi NahamSec, I'm a regular viewer of your content.can you make video on business logic in dept!! waiting for it
@gokul5582
@gokul5582 Жыл бұрын
What to do if we don't have burp collaboraor ?
@Aashishsec
@Aashishsec Жыл бұрын
more content on web attacks
@Asadneon
@Asadneon 7 ай бұрын
web hacking content more please
@suryaroja03
@suryaroja03 Жыл бұрын
please post content like this...thank you
@tehlan6340
@tehlan6340 Жыл бұрын
I make hacking videos
@ogbooker4538
@ogbooker4538 Жыл бұрын
both content is fine and some free tutorials
@SecurityVaultYt
@SecurityVaultYt Жыл бұрын
Epic, Part 2 please.
@rafekhen4263
@rafekhen4263 5 ай бұрын
more content like this please
@mahdihasan42
@mahdihasan42 Жыл бұрын
we need location traking tutorial
@RnVjayBZb3V0dWJl
@RnVjayBZb3V0dWJl Жыл бұрын
Haya! I have quite a lot of experience in pentesting webapps, but i do not have any experience in hosting an instance of a webserver, securing it or being able to load an insecure server, but in a secure way cause we don't want a creepy scanner rooting it and being malicious when i want to test it :P So my question, could you make a lill tutorial in how to, for example, use a docker or maybe host a site in different means through a Digital Ocean instance? :P Would be fun to learn a little bit about it and then being able to pentest towards it. By learning this, one can use your knowledge to host a file hosting instance to make an RFI etc, which is a bit difficult without an outwards facing host ^^ Stay safe and happy late Easter!
@onsiyammalembe1546
@onsiyammalembe1546 Жыл бұрын
I love this content make more please
@jeremyg737
@jeremyg737 Жыл бұрын
part 2? more content like this!
@fadelafanmahendra653
@fadelafanmahendra653 Жыл бұрын
more content like THIS!
@MUHAMMADHASNAATARSHAD
@MUHAMMADHASNAATARSHAD Жыл бұрын
Part 2 ,,4,5,6,7,8,9,-----,99999
@bugs-lk3jf
@bugs-lk3jf Жыл бұрын
Great Content; More Please 🤑
@Boondog-hv4wy
@Boondog-hv4wy Ай бұрын
You have helped me a lot as I am stepping into Bug Bounties. I have loved connecting with the people in your discord and have learned so much! I am 1 semester away from getting my bachelor's in computer science and your content as well as the people I found through your community have been invaluable to my success. Thank you so much!
@SunilTiwari-ez9lj
@SunilTiwari-ez9lj Жыл бұрын
More parts on this topic ..
@taqiuddinismail9542
@taqiuddinismail9542 Жыл бұрын
more content like thiss
@CookingCooking77
@CookingCooking77 5 ай бұрын
MORE CONTENT !!!
@braaemad2745
@braaemad2745 Жыл бұрын
more and more plz
@dtchallohfranc3360
@dtchallohfranc3360 Жыл бұрын
Part 2 please 😍
@Drakan1990
@Drakan1990 10 ай бұрын
More please!
@weniweedeewiki.6237
@weniweedeewiki.6237 Жыл бұрын
PART 2 BRO DEFO
@srcybersec1736
@srcybersec1736 Жыл бұрын
Want more vdo
@mahdihasan42
@mahdihasan42 Жыл бұрын
location hack
@entertainment_in_blood
@entertainment_in_blood Жыл бұрын
PART-2
@BlancoBox
@BlancoBox 11 ай бұрын
While I may not have commented before, I've been an avid admirer of your work. As an aspiring pentester, I find your technical content to be precisely what I seek. While your other content is commendable, it's ultimately the expertise you bring that I look up to for learning. Your contributions are truly appreciated.
@aavezsheikh5781
@aavezsheikh5781 Жыл бұрын
More content
@samadafridi1059
@samadafridi1059 6 ай бұрын
part 2 or complete playlist on the web Vuln
@navidof5
@navidof5 Жыл бұрын
part 2
@handle_my_handle
@handle_my_handle Жыл бұрын
Part 2
@irvingirving6275
@irvingirving6275 Жыл бұрын
Preach!
@yourmove9993
@yourmove9993 Жыл бұрын
part 2
@SalimShaikh-ip7gi
@SalimShaikh-ip7gi Жыл бұрын
Part2
@firosiam7786
@firosiam7786 Жыл бұрын
Is Bola and idor the same type of vulnerability with different names
@stevejones371
@stevejones371 Жыл бұрын
More, more more real world how to once we have done recon. We need to know the steps on how to find bugs.
@long2330
@long2330 Жыл бұрын
Thanks for helpful content! It would be great if u could do more specific showcases about blind SSRF. For example there is a case that I only receive the DNS queries back to the collab. I guess because of outbound restriction but it seems like the server was trying to reach to that domain. Any way in this case that you can prove the ssrf is there with just DNS? Or do you have any suggestion on setting up things in internal network to prove the vulnerability is there? Was a long comment but hope u could imagine the case 😂 thanks
@noureldinehab2686
@noureldinehab2686 Жыл бұрын
💙
@shiewhun1772
@shiewhun1772 Жыл бұрын
Yes, this is great. From a web developer perspective. I'm trying to under how my server side applications could be hacked and this is great content. Please, continue.
@rllan006
@rllan006 Жыл бұрын
100% both. I like the nuance you teach here. For example login page and SSRF. This is fantastic content.
@ss-rc1gy
@ss-rc1gy Жыл бұрын
fantastic :o , i would like to see a full and advanced recon video from you :)
@ethyhack
@ethyhack Жыл бұрын
yes please, give us more content of this kind.
@volatileobj3cts
@volatileobj3cts Жыл бұрын
Super down with more technical content!
@janekmachnicki2593
@janekmachnicki2593 Жыл бұрын
Content + real+technical aspect of pen testing and bug hunting .Thanks
@Arian-e7t
@Arian-e7t Жыл бұрын
I would like to see basic contents like this.
@heli_9
@heli_9 Жыл бұрын
I’d love more technical videos
@akeelw084
@akeelw084 6 ай бұрын
part 7 we want
@ZarakKhanNiazi
@ZarakKhanNiazi Жыл бұрын
I love you naham
@NahamSec
@NahamSec Жыл бұрын
@TrecXsec
@TrecXsec Жыл бұрын
More part 2. Need more technical vids
@zak6820
@zak6820 Жыл бұрын
Yes more content like this pls
@NathanielMitchellnm
@NathanielMitchellnm Жыл бұрын
Part 2!
@soulvideos7834
@soulvideos7834 Жыл бұрын
More content like this 🙂🙏❤️🔥
@ogbooker4538
@ogbooker4538 Жыл бұрын
stay consistent big bro
@The_capitol
@The_capitol Жыл бұрын
I would like to see one of the vulnerabilities you have found and walk through the info gathering stage all the way to the post exploit while explaining the mindset/methodology
@NahamSec
@NahamSec Жыл бұрын
Soon :)
@alihussainzada3392
@alihussainzada3392 Жыл бұрын
It was awesome Next xxe plz
@lovedaysmart9183
@lovedaysmart9183 Жыл бұрын
Just what we need Ben 😊 thank you 👏🏻
@devanshuthanvi731
@devanshuthanvi731 Жыл бұрын
Perfect type of content 😃👍
@loneliestwolf4228
@loneliestwolf4228 Жыл бұрын
Part 2 please....
@LulzWalker
@LulzWalker Жыл бұрын
Love this!
@NexInfernis
@NexInfernis Жыл бұрын
we need more part of this
@mindf4rt
@mindf4rt Жыл бұрын
More pls =)
@0xbeven462
@0xbeven462 Жыл бұрын
I reported my browser 😂
@husamgameel1489
@husamgameel1489 Жыл бұрын
yup yup more tutorials for hacking and IT stuff how to do ore bypass
@bashiqali2142
@bashiqali2142 Жыл бұрын
😊
@JD-wj1bf
@JD-wj1bf Жыл бұрын
Part 2
@Haxr-dq6wt
@Haxr-dq6wt Жыл бұрын
Bad explanation with a lot or wrong info
Server-Side Request Forgery (SSRF) | Complete Guide
47:04
Rana Khalil
Рет қаралды 68 М.
pumpkins #shorts
00:39
Mr DegrEE
Рет қаралды 55 МЛН
From Small To Giant Pop Corn #katebrush #funny #shorts
00:17
Kate Brush
Рет қаралды 71 МЛН
What functionalities are vulnerable to SSRFs? Case study of 124 bug bounty reports
19:58
Bug Bounty Reports Explained
Рет қаралды 15 М.
WHY YOU SUCK AT HACKING // How To Bug Bounty
10:05
NahamSec
Рет қаралды 22 М.
Cross Site Request Forgery vs Server Side Request Forgery Explained
12:23
Cloud Hacking: Common Attacks & Vulnerabilities
22:59
NahamSec
Рет қаралды 8 М.
What is Fuzzing (using ffuf)
12:54
NahamSec
Рет қаралды 19 М.
Server Side Request Forgery | Junior Penetration Tester TryHackMe SSRF
20:51
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 26 М.
Hacking Websites With A Zip File (Zip Slip)
13:19
NahamSec
Рет қаралды 6 М.
SSRF Bug Bounty | Server Side Request Forgery | Ethical Hacking
11:43
Find and Exploit Server-Side Request Forgery (SSRF)
8:56
The Cyber Mentor
Рет қаралды 41 М.