This bug might change how you see eCommerce websites

  Рет қаралды 2,311

DeadOverflow

DeadOverflow

Күн бұрын

Пікірлер: 36
@hanhao263
@hanhao263 2 күн бұрын
Race conditions sound like what an American would say.
@deadoverflow
@deadoverflow 2 күн бұрын
🦅🦅🦅🇺🇲🇺🇲🇺🇲
@swatejdesai7621
@swatejdesai7621 Күн бұрын
Rahhhhhh😂
@and_rotate69
@and_rotate69 Күн бұрын
unfortunately race conditions are realllyy edge cases, and u can barely do 1 especially with nowadays frameworks which offer a better security and code execution
@deadoverflow
@deadoverflow Күн бұрын
I do agree but race conditions aren't always what I explained. These vulnerabilities occur in a lot of different parts of a website, that's why they are so destructive. One good example is bypassing 2fa.
@LK272si
@LK272si 19 сағат бұрын
Absolutely love this kind of content!!! I hope you keep making more such content🙀
@deadoverflow
@deadoverflow 19 сағат бұрын
Aww thanks man, really appreciate this. One way to motivate me in making more content is to subscribe, it costs you nothing but means a lot to me for each number I get
@someoneunknown6894
@someoneunknown6894 Күн бұрын
Hey, great video! Would love to see more videos like this going over the labs
@deadoverflow
@deadoverflow Күн бұрын
Thanks a lot man, I got another video coming out today regarding broken reset password functionality so you might want to subscribe to check that out!
@someoneunknown6894
@someoneunknown6894 Күн бұрын
@deadoverflow Subscribed right now :D
@lightninghunterCR
@lightninghunterCR Күн бұрын
Damn, that was good stuff!
@deadoverflow
@deadoverflow Күн бұрын
Thanks a lot man, I really appreciate your insight!
@pieTone
@pieTone Күн бұрын
Here before you become a decillionare.
@deadoverflow
@deadoverflow Күн бұрын
HAHAHHA
@ramonbastos6232
@ramonbastos6232 Күн бұрын
Amazing video man, I would just like to know which tool you used to intercept the requests
@deadoverflow
@deadoverflow Күн бұрын
Oh man I could get in trouble if I tell you so please promise me you won't use it for anything shady 😭
@OplikZPrahy
@OplikZPrahy Күн бұрын
​@@deadoverflow I would like to know aswell. I have a huge interest in coding, cybersecurity etc. I promise not to do shady stuff, I actually already got rewarded for a few incredibly easy bounties.
@deadoverflow
@deadoverflow Күн бұрын
@@OplikZPrahy Okay then, software I used is called Burp Suite standard edition, there is a pro version but I rarely use it. You can just google and download it. Set up is very easy as well!
@RodDiaz
@RodDiaz Күн бұрын
Can you explain, which is the best way to notify the owner of the website that there is a "bug"
@deadoverflow
@deadoverflow Күн бұрын
If they have a bug bounty program then that is one way, if they just have a contact form that is another and if you cannot contact them, then maybe look up the owner of a website and contact them directly.
@Bebop79
@Bebop79 Күн бұрын
Assuming the company is being proactive they might have this set up en.wikipedia.org/wiki/Security.txt
@deadoverflow
@deadoverflow Күн бұрын
Great point
@TheDenixChannel
@TheDenixChannel 2 күн бұрын
you got yourself a like and follow
@deadoverflow
@deadoverflow Күн бұрын
That's awesome, thanks a lot man ❤️
@yolbulucu
@yolbulucu Күн бұрын
wait how do they prevent this ?
@deadoverflow
@deadoverflow Күн бұрын
Well I guess making the functionality different on the backend. Maybe firstly setting the coupon to be invalid and then remove the -20%
@jisangain
@jisangain Күн бұрын
Maybe you can use mutexes/locks
@yolbulucu
@yolbulucu Күн бұрын
@@deadoverflow lol or simply use transactions
@deadoverflow
@deadoverflow Күн бұрын
or once you start making a purchase, backend detects that you entered a coupon and only then takes 20% off
@rvn8552
@rvn8552 Күн бұрын
option A/B is as dead mentioned, invalidate first or check if coupon was already entered, option C is to use something called atomic locking which in short terms makes sure that things happen in sequence i.e. first coupon processed fully, then second coupon processed, not both simultaneously
@AnukiranGhosh
@AnukiranGhosh 2 күн бұрын
Race conditions? (I didn't watch the full vid yet, I solved the lab a few weeks ago).
@deadoverflow
@deadoverflow 2 күн бұрын
It's a great type of vulnerability to hunt for, honestly it's underrated but you can find these almost everywhere
@AnukiranGhosh
@AnukiranGhosh 2 күн бұрын
@@deadoverflow right. I keep moving away from cybersecurity & then some video pops up on my yt feed & I want to get back again 😂
@deadoverflow
@deadoverflow 2 күн бұрын
lmao had exactly the same experience few years ago. Don't give up is the best advice to give
@MrJloa
@MrJloa Күн бұрын
Lawl who da hell applies the coupon async and then mark it used 😂 Probably some Indian interns wrote that estore code man
@deadoverflow
@deadoverflow Күн бұрын
Lmao, well given the fact that indians charge $2 an hour, so they are cheap labor, you can see this more and more lmaoo
Why Are Open Source Alternatives So Bad?
13:06
Eric Murphy
Рет қаралды 667 М.
7 Cybersecurity Tips NOBODY Tells You (but are EASY to do)
13:49
All Things Secured
Рет қаралды 759 М.
This dad wins Halloween! 🎃💀
01:00
Justin Flom
Рет қаралды 60 МЛН
Osman Kalyoncu Sonu Üzücü Saddest Videos Dream Engine 275 #shorts
00:29
The Truth About Bug Bounties
11:31
NahamSec
Рет қаралды 40 М.
The Vim Experience
45:19
Bog
Рет қаралды 109 М.
Bug that gets you INFINITE followers on Instagram...
3:51
DeadOverflow
Рет қаралды 2,8 М.
What Happened to Pop-up Selfie Cameras?
8:15
punkwave
Рет қаралды 86 М.
The Better Way to Manage React State
7:38
Josh tried coding
Рет қаралды 25 М.
The Browser War is Getting WORSE
10:42
Giodev
Рет қаралды 41 М.
How I promote my app (without big following)
12:11
Mykola Harmash
Рет қаралды 1,9 М.
How Hackers Ruined Among Us
5:03
DeadOverflow
Рет қаралды 1,1 М.
Linux YouTubers I'm Watching In 2024
13:13
DistroTube
Рет қаралды 20 М.