As I'm a beginner in bug bounty, you have explained this excellent!
@BePracticalTechКүн бұрын
@@BibleOSINT Really happy that you liked it
@BibleOSINTКүн бұрын
@BePracticalTech would you recommend me as beginner in bounty to look for those vulnerabities?
@BePracticalTech6 сағат бұрын
@@BibleOSINT Definitely!
@BibleOSINT6 сағат бұрын
@@BePracticalTech Thank you! ❤️
@Offsec-n4nКүн бұрын
what is the impact of creating multiple dashboards and how it effects to organizations and why they will pay $**** digits of bounty for this ??
@BePracticalTechКүн бұрын
In this example, The local users were only supposed to create 3 dashboards and if they want to create more dashboard they either need to get the premium account or login as admin user. However, we were successfully able to bypass this restriction and able to create more than 3 dashboards so it is an access control issue. Now in real world, If an attacker is able to access premium feature without the need to get the subscription, it will be a financial loss for the organization. Hope you understand!
@victorgomesgomesКүн бұрын
@@BePracticalTech You can also test under Current user limit: 5/5 to do a bypass with this current application: 6/5
@Muby_AjiwaКүн бұрын
I really like the way you teaching. Thanks you so much keep up the good work
@BePracticalTechКүн бұрын
@@Muby_Ajiwa Thank you for the humble words!
@sonamohan6194Күн бұрын
awesome! Really well-explained as well!!
@BePracticalTechКүн бұрын
Thank you kindly!
@the_sandman00Күн бұрын
Great explanation!
@BePracticalTechКүн бұрын
Thank you!
@морс-ф3дКүн бұрын
Brilliant!!!!!!!!!!! Thank you for sharing your great knowledge!!!!!!!
@BePracticalTech16 сағат бұрын
Glad you enjoyed it!
@shivakumarmv4249Күн бұрын
Excellent...Thanks for sharing
@BePracticalTechКүн бұрын
@@shivakumarmv4249 I am really glad you liked it!
@Unknown_feedКүн бұрын
Love from Nepal ❤❤
@BePracticalTechКүн бұрын
@@Unknown_feed Love from 🇮🇳
@Ch4ndan_dasКүн бұрын
thank u so much sir for giving this use full video
@BePracticalTechКүн бұрын
I am really glad that you found this video helpful!
@vijay_sawantКүн бұрын
I have been watching you for a long time, and you are really a great teacher
@BePracticalTechКүн бұрын
Glad to hear that!
@i_am_your_kingКүн бұрын
Thank you for the video I tried to enter the page to try the method, but it gives an error message. Error code 522 Connection timed out
@BePracticalTechКүн бұрын
@@i_am_your_king Try again please
@starlox0Күн бұрын
Awesome Video😀Understood clearly
@BePracticalTechКүн бұрын
Glad it helped
@swagat546816 сағат бұрын
Thanks bhai 🙂❤️
@BePracticalTech6 сағат бұрын
You're welcome!
@a.c.598521 сағат бұрын
Is it possible to see a real example?
@BePracticalTech6 сағат бұрын
Sure! Here you go: corneacristian.medium.com/top-25-race-condition-bug-bounty-reports-84f9073bf9e5
@l00pzwastakenКүн бұрын
Kya hal hai nice video :) good research and explanation bhai
@BePracticalTechКүн бұрын
Thanks a lot :)
@Knownsense_world_Күн бұрын
Thanks ❤
@BePracticalTechКүн бұрын
Glad you liked it!
@HadkerXКүн бұрын
Thanks
@BePracticalTechКүн бұрын
No worries! Glad you liked it
@z3r0X0rКүн бұрын
Thanks for give us this type really good challenge
@BePracticalTechКүн бұрын
My pleasure 😊
@vulncraxКүн бұрын
Keep it up 🎉
@BePracticalTechКүн бұрын
Always
@Yash.Lonewolf12 сағат бұрын
amazing
@BePracticalTech6 сағат бұрын
Glad you liked it!
@harshthakar2207Күн бұрын
Really sir this was the best video till now on race condition plz share me your linkedin❤
@BePracticalTech6 сағат бұрын
I am really glad you liked it! Here's my linkedin: www.linkedin.com/in/faiyaz-ahmad-64457520b/
@newuser2474Күн бұрын
Bro but what will be mitigation for this issue 😮
@BePracticalTech6 сағат бұрын
To fix this issue, we need to focus on handling concurrent request as well instead of handling everything synchronously
@Baban0519 сағат бұрын
Please explain in practical webpage
@BePracticalTech6 сағат бұрын
This lab here replicates the same vulnerability that i found on a pentest. Unfortunately, it is now very difficult to show vulnerabilities on real production website as it is against KZbin Guidelines.
@MubashshirShaikh-hs8oyКүн бұрын
make a video on burp suite full potentail
@한국어의이름이라면강Күн бұрын
i wanna see this app source code
@BePracticalTech6 сағат бұрын
Here's the source code: github.com/faiyazahmad07/rcondition_bepractical_lab/
@한국어의이름이라면강6 сағат бұрын
@ thx alot
@MianHizbКүн бұрын
Bro can you kindly just mention Race conditions in the title...thanks
@mohammadrezafarahani9287Күн бұрын
Please share that code
@BePracticalTech6 сағат бұрын
@@mohammadrezafarahani9287 Sure, Here you go: github.com/faiyazahmad07/rcondition_bepractical_lab/
@mohammadrezafarahani928758 минут бұрын
Bro in this file just have one file so where is the home.ejs and login.ejs ?@@BePracticalTech
@mohammadrezafarahani928753 минут бұрын
@@BePracticalTechdo you share login.ejs and home.ejs ?