Stored, Blind, Reflected and DOM - Everything Cross--Site Scripting (XSS)

  Рет қаралды 9,357

InsiderPhD

InsiderPhD

Жыл бұрын

I'll be honest, XSS are not my favourite kinds of bugs to hunt for, even now and I don't think they are great for beginners. BUT I have been outvoted by the community on this one so here's how to find your first bug, XSS edition. I'm going to talk about each type of XSS and show you how I actually approach a target when I'm looking for XSS bugs. I will be the first to admit I've found 1 XSS in the wild and it was a DOM based XSS!
This series couldn't happen without the support of our sponsor Bugcrowd, Bugcrowd is the best place to start hacking with a wide range of public and private programs from APIs to Desktop Applications and everything in between. Not ready to jump into a public program yet? Fill out your platform CV and sign up for a waitlisted program. Tell Bugcrowd a bit about your skills, previous certifications or experience and they’ll match you up with the right program using their industry-leading CrowdMatch technology. Whatever your level, there’s a place for you in the crowd. You can sign up with my link here: bugcrowd.com/user/sign_up.
- Social Media -
Discord: insiderphd.dev/discord
Patreon: / insiderphd
Twitter: / insiderphd

Пікірлер: 18
@bradnaylor35
@bradnaylor35 Ай бұрын
Great video! You have a serious aptitude for teaching. Enjoying all the bug bounty basics lessons
@Makingmoneyonli
@Makingmoneyonli 5 ай бұрын
Great content Learned a lot of new things after only doing CTFs for a long time going into the real world to capture real world bugs and seems really overwhelming.
@LearnTermux
@LearnTermux Жыл бұрын
waited for this video for a long time
@ferdusalam7260
@ferdusalam7260 Жыл бұрын
I AM JUST WONDERING THE SAME TOPIC VIDEO AND DIDN'T UNDERSTAND WHERE TO LERAN AND I JUST OPEN KZbin AND I GET YOUR VIDEO! :)
@InsiderPhD
@InsiderPhD Жыл бұрын
I read your mind 🤔
@eyephpmyadmin6988
@eyephpmyadmin6988 11 ай бұрын
I was 13 and found a reflected xss on NASA's main website and if I only knew that was a valuable vulnerability and that bug bounties where a thing(I think they were back then) I think about it often
@user-hf9bh7pg1q
@user-hf9bh7pg1q 5 ай бұрын
When I was 13 I found corn 🌽. And subsequently discovered some of my own vulnerabilities. 😊
@jub0bs
@jub0bs Жыл бұрын
Thanks for the video, Katie! I particularly enjoyed the history intro. What resources did you rely on for that bit? Also, what's that infographic you mention at 18:43? I didn't quite catch the name, and the video transcript isn't very useful...
@InsiderPhD
@InsiderPhD Жыл бұрын
Oops completely forgot to include it! twitter.com/s0md3v/status/981465370736320513 S0md3v has done a ton of these twitter.com/s0md3v/status/1057985696193888256 History comes via the tangled web and and thehistoryoftheweb.com/
@jub0bs
@jub0bs Жыл бұрын
@@InsiderPhD Excellent! Thanks!
@Shadabkhan-sn7hw
@Shadabkhan-sn7hw Жыл бұрын
Glad first view. I like the @InsiderPhD content. Always has something new to learn.
@amoh96
@amoh96 11 ай бұрын
Hello thank you about impact alot of people say CSRF is die :( and im just starting learning about CSRF what u think ! ?
@orbitxyz7867
@orbitxyz7867 Жыл бұрын
🎉🎉❤
@learn-with-noob-007
@learn-with-noob-007 Жыл бұрын
I'm fast 😂❤ love your content ❤❤🎉
@firosiam7786
@firosiam7786 Жыл бұрын
It's been a while 2 weeks since last post hope u are OK after the hospital issues and all that came up
@InsiderPhD
@InsiderPhD Жыл бұрын
Recovering still but doing better!
@techslugz
@techslugz Жыл бұрын
Yaaay I was first to like! Whoop whoop 🎉🎉😊🙃
@cris305bleach
@cris305bleach Жыл бұрын
I'm so happy to see that you are making videos again, I hope you are feeling great Katie! sending good vibes form Latin America. 4th xD
Why does DNS always break the internet?
17:26
InsiderPhD
Рет қаралды 10 М.
Revealing Secrets with Information Disclosure Bugs
19:07
InsiderPhD
Рет қаралды 7 М.
EVOLUTION OF ICE CREAM 😱 #shorts
00:11
Savage Vlogs
Рет қаралды 12 МЛН
Learn Bug Bounty Hunting with These Resources!
35:22
InsiderPhD
Рет қаралды 13 М.
Cross-Site Scripting (XSS) Explained
11:27
PwnFunction
Рет қаралды 437 М.
Hacking Tinder - Live bug bounty hunting on Hackerone (Part 1)
11:42
Clint & Si The Hackers
Рет қаралды 2 М.
My Hacking Setup and How to Use It (Firefox/Burp Community)
28:28
"Easiest" Beginner Bugs? Access Control and IDORs
31:46
InsiderPhD
Рет қаралды 19 М.
Hacking when all the bugs have been found?
18:53
InsiderPhD
Рет қаралды 5 М.
Every Type of XSS Attack, Explained
16:23
InsiderPhD
Рет қаралды 26 М.
Cracking Websites with Cross Site Scripting - Computerphile
8:34
Computerphile
Рет қаралды 1,5 МЛН
Updated Beginners Guide to API Bug Bounty
30:05
InsiderPhD
Рет қаралды 12 М.