WEB CACHE POISONING FOR BEGINNERS + GIVEAWAY(closed)

  Рет қаралды 25,308

Farah Hawa

Farah Hawa

Күн бұрын

Пікірлер: 155
@FarahHawa
@FarahHawa 4 жыл бұрын
Check the description for the giveaway rules!
@rohitsoni9325
@rohitsoni9325 4 жыл бұрын
Hey, it was a very helpful video for cache poisoning. Can you also make a video on correct working of Autorize tool of Burpsuite? I've watched many videos to automate the IDORs using burp but found none to be clear enough.
@smartcomputring1034
@smartcomputring1034 3 жыл бұрын
ap reply kiyu nahi karti sister
@brijeshpal4039
@brijeshpal4039 3 жыл бұрын
Can you please explain with more examples?
@amanjain91
@amanjain91 4 жыл бұрын
This month I learned about how to bypass profile pic upload functionality whenever server checks the content of the image. This functionality is bypassed by bypassing thr gd-php library which is used by the server for validating
@goodboy8833
@goodboy8833 3 жыл бұрын
Could u share any link for that
@rajanrawal6396
@rajanrawal6396 2 жыл бұрын
amazing, this could be probably one of the biggest information that i have ever been given. we need such playlist more and more in upcoming days. The way how you explain is an amazing.
@collisioadolebitque4148
@collisioadolebitque4148 4 жыл бұрын
This month, I learned the importance of building your own methodology, not copying others as well as the need to dig into the tools we use in order to understand how things can be done better.
@emmanuelafolabi6847
@emmanuelafolabi6847 4 жыл бұрын
I found a web cache poisoning attack as of result of your previous web cache video, will def. look out for this... Your videos are great by the way...short but quite explanatory, exactly what I need.
@deepanshuyadav6745
@deepanshuyadav6745 3 жыл бұрын
I am beginner in bug bounties thanks for sharing, learned a lot keep making these type of videos.
@drwombat
@drwombat 2 жыл бұрын
Another excellent, expertly done video. Thank you. Your uploads are clear, concise, brief and informative. Any time I'm having a problem I always check your videos FIRST to see if you have a demonstration about that topic as I prefer your explanations compared to others
@Jaatranger-f1e
@Jaatranger-f1e 3 жыл бұрын
Very information vedio
@UmairAli
@UmairAli 4 жыл бұрын
Very Informative My Dear :) I'm Really impressed , cuz had been searching for a practical use of cache poisoning and dns hijacking all over the internet for like a lot of time, but what I found was only theory , I did manage to perform Dns hijacking from registrar but not cache poisoning until i saw this video thanks a lot.
@wael_shaikh
@wael_shaikh 4 жыл бұрын
Yaayyy! You're back! I learned a lot this month thanks to your channel.
@i_zamba
@i_zamba 4 жыл бұрын
Farah, video is great, but if the background music volume reduced little bit that will be better to concentrate on the juicy content you offer us. Thanks for all your efforts to our community.
@savirsuda
@savirsuda 4 жыл бұрын
This was the best Cache poisoning video I have ever seen! Thanks Farah :)
@phpdude
@phpdude 4 жыл бұрын
Hey Farah, great video as always! Am learning from them and looking forward to more... And learning about exploiting null byte buffer overflow from one of Sam Currys posts but haven't been able to digest it fully yet. Hope to do so soon... Stay safe and keep making those awesome vids girl... Till then
@Najumulsaqib
@Najumulsaqib 3 жыл бұрын
If you're hitting the cache and the cache is not refreshing. Try replacing GET with PURGE in the request
@mitulfg7115
@mitulfg7115 4 жыл бұрын
Thank you for this video. It cleared my most of the doubts regarding web-cache poisoning.
@yrks1109
@yrks1109 4 жыл бұрын
This Month, I learnt more About SSRFs, how to gain RCE through different parameters, more on Reflected XSS and some sprinkle of XXEs :)
@yrks1109
@yrks1109 4 жыл бұрын
My Twitter Handle : @Neutron__
@gladysorrego6054
@gladysorrego6054 4 жыл бұрын
El próximo video podría ser sobre IPSec y su Anti Replay para concienciar y cambiar a IPv6? Soy un fan de IPv6, dejar atrás NAT y A record. Abrazar los AAAA récord.
@vergil_389
@vergil_389 4 жыл бұрын
Hi 😆 This month I've learned Public key Cryptosystems The RSA ALGORITHM Diffie Hellman Key exchange Comparison of RSA and DES Elliptic curve Cryptography Number theory Concepts
@sureshkumar7753
@sureshkumar7753 4 жыл бұрын
Short and sweet.. Thanks @farah
@jbjb8976
@jbjb8976 4 жыл бұрын
I learn Today web cache poisoning, great video, Thank You.
@manojb1802
@manojb1802 3 жыл бұрын
Interesting..I love this video. It's helpful for my career.
@anisazam8155
@anisazam8155 2 жыл бұрын
A/s as i started web testingas my career so i also always explore types of web vulnerability and you did great job at this time . 👍🏻 keep it up
@MH-tw1qi
@MH-tw1qi 4 жыл бұрын
In this month I learned about redos
@rimbasec9708
@rimbasec9708 4 жыл бұрын
This month I studied many vulnerabilities based on the OWASP top 10. I use Burp suite as a tool for penetration testing, starting with solving several web security academy labs (Portswigger), after that I practice doing (ethical) penetration tests on several web applications where I work for. From there I found quite a number of severity level vulnerabilities from LOW to Critical (SQL Injection). BTW, thanks for uploading this video. That has been a huge help in my journey into cybersecurity. Twitter : @muhandipras
@Arummekarlayung0706
@Arummekarlayung0706 4 жыл бұрын
Long time no see ❤️
@elliot9066
@elliot9066 4 жыл бұрын
I learned some bypass bypassd mfa 403 2f and many more things:P
@rutikhajare1053
@rutikhajare1053 4 жыл бұрын
In this month i have mainly focused on cashe poisoning...I've read about cashe poisoning earlier but those are not easy to understand but your video is too good and easy to understand...I'm definitely gonna apply your tips mentioned in this video..!! And thanks for creating super video ! @HajareRutvik
@jakariaislamshanto1217
@jakariaislamshanto1217 4 жыл бұрын
Hello Farah ! so in this month i've learned Broken access control and privilege escalation .I 've also submitted a bug report related to privilege escalation(finger crossed) . Hope you have a good day .@ShantoJj
@ahmedabdelfadeel2211
@ahmedabdelfadeel2211 4 жыл бұрын
This month i have read 4 chapters (xss - Attacking Access Control - Attacking Application Logic - Attacking Back-End Components ) of The Web Application Hackers Handbook @delox101
@887310954
@887310954 4 жыл бұрын
i learned qualys app scan, it is really very useful for devsecops
@887310954
@887310954 4 жыл бұрын
@Ashutos7ank
@Nothing-lh9hp
@Nothing-lh9hp 4 жыл бұрын
Thanks for your amazing chennal, how we could find blind sqli I know that type of bug but how can find it
@amirhassan1100
@amirhassan1100 3 жыл бұрын
Thanks a lot for this video. I definitely learned a lot of things. Geep up the good work
@FarahHawa
@FarahHawa 3 жыл бұрын
Glad it was helpful!
@jaggedmule14
@jaggedmule14 2 жыл бұрын
Thanks :) it was very helpful
@rakeshnai1287
@rakeshnai1287 4 жыл бұрын
Welcome back
@sarthakmathur7696
@sarthakmathur7696 4 жыл бұрын
This week I read an article about exploiting Regular Expressions , which for me was very amusing because I never thought Regular Expressions can be exploited. Basically we can provide certain string to the RE engine and it will cause it to waste it resources thereby creating a kind of a DOS Attack. Your videos are short and to the point. Thanks for sharing the knowledge with the community. Keep Going Girl!!! Twitter Handle: @Phantom80305095
@aviralgupta9869
@aviralgupta9869 4 жыл бұрын
Who all know me I am one of the first giveaway winners 😎😎
@mukoshmanob9240
@mukoshmanob9240 4 жыл бұрын
can you plzz make a video about IDOR on post request???
@testingx01
@testingx01 4 жыл бұрын
Thank you for the insightful video!
@hax0rl33t2
@hax0rl33t2 3 жыл бұрын
This is actually a good video.
@vijaySingle143
@vijaySingle143 3 жыл бұрын
Thanks Farah. 👍
@vwonwheels5649
@vwonwheels5649 4 жыл бұрын
Nice work......keep sharing information.....🙂
@sekharpoola1396
@sekharpoola1396 4 жыл бұрын
In this month i learned a lot by doing challenges. I think open redirection is occurs in every page if we spider is correctly. I can across a new open redirect bug in between the url. I hoping a certificate for that bug. Thank
@sekharpoola1396
@sekharpoola1396 4 жыл бұрын
@sekharlee twitter
@maurusergio
@maurusergio 4 жыл бұрын
please, could you enable subtitles on the video?
@sivasiva-sh6hl
@sivasiva-sh6hl 4 жыл бұрын
new thing i have discoverd is farah hawa is an indian
@vamsikolati
@vamsikolati 4 жыл бұрын
Hey great video 😀. To poison the cache response, our task is to find a unkeyed input and poison , So we are using param miner to mine headers that can be reflected in response if used in the request ?? Is this correct ??
@MmM-iu1sz
@MmM-iu1sz 3 жыл бұрын
Any idea on the tool using here?
@vaibhavgaikwad4291
@vaibhavgaikwad4291 3 жыл бұрын
How to exploit web cache poisoning with X-timer header?
@debprasadbanerjee5005
@debprasadbanerjee5005 3 жыл бұрын
Great content, neatly presented.
@Rahul_Kumar_EE
@Rahul_Kumar_EE 4 жыл бұрын
In this mounth iam found in glitch in whatsapp. In read receipt function ..👍 I request you please tell me the from where I star the hacking journey. And sorry iam not using Twitter and some one deserve that giveaway not me because I have not master on pentesting
@wadgamer1010
@wadgamer1010 10 ай бұрын
Thank you very much, keep it up ❤
@enpassant7358
@enpassant7358 4 жыл бұрын
The coolest thing I learned this month was to use Python to create a simple web server in order to copy files over the Internet from the directory where I start the server. The command is: python -m SimpleHTTPServer 8080 @cts_technology
@ronykroy5766
@ronykroy5766 4 жыл бұрын
Great presentation
@Thelostblud
@Thelostblud 4 жыл бұрын
I am very new in this field jst read web application hacker handbook 2 @1-6 chapters and learn abbout -Host header attack and 2- bussiness logic vulnerability and at last 3 - web cache poisoning bt nt this 1 lab. I am not able or i am not understanding how to apply can someone help me
@utensilapparatus8692
@utensilapparatus8692 3 жыл бұрын
Awesome
@XDms85
@XDms85 4 жыл бұрын
I have learnt more about Graphql and how to make queries. As always great video! @xdms85
@Mochi-kane
@Mochi-kane 3 жыл бұрын
Thank you.
@MishisFamily
@MishisFamily 4 жыл бұрын
Thank you so much Farah, very useful content, I enjoyed learning about this topic that I didn't know so much. Take care, hope you're doing well in University and keep it up. Well done.
@kaygeesiddharth1592
@kaygeesiddharth1592 4 жыл бұрын
Yeah . This month I learnt bash & RCE via Shell upload . Twitter handle @Kg_siddharth
@kushagraaa
@kushagraaa 4 жыл бұрын
Tried learning some basics of android security and also started solving some ctf's at hackerone. Twitter handle: @psychedelicbyte
@anshusharma5199
@anshusharma5199 4 жыл бұрын
I learnt jwt and web chach poisoning this month. Thanks for those videos And Thanks for your amazing content 😊 @AnshBhardwaj999
@abhimanyumishra8185
@abhimanyumishra8185 3 жыл бұрын
Hey Farah ! can a web cache poisoning vulnerability be used to get cookies of other users ?
@FarahHawa
@FarahHawa 3 жыл бұрын
yes, it could be possible with an XSS
@abhimanyumishra8185
@abhimanyumishra8185 3 жыл бұрын
@@FarahHawa you mean using xss ! 🤔Hmm ok , Farah is there any other way to get cookies (other than web cache and xss)
@becool5483
@becool5483 4 жыл бұрын
madam im complete beginner... basically im a mechanical engineer... i just know computer fundamentals, linux shell... exactly i dont know from where to start.... which programming language should i chose first??? please kindly suggest me!!!
@rajesha8626
@rajesha8626 4 жыл бұрын
start with python. and try practicing hacking skills in tryhackme .. by the way i am a mechanical engineer too
@Malware01
@Malware01 4 жыл бұрын
I learn invest in pentesterlab to get advance stuff otherwise we have lot of "For Begineers" content available. @mt_ins
@danishalvi9731
@danishalvi9731 4 жыл бұрын
App ke video bhot late hain Videos weekly basis pa upload kia karain
@muralidharansubburaman8863
@muralidharansubburaman8863 4 жыл бұрын
I am noob to hackthebox and learning pwk. This week worked my way through legacy box.. kept myself away from the writeups and it was a ton of learning. @muralidharan89 -
@jerrytech1901
@jerrytech1901 4 жыл бұрын
gud one..
@virenjoshi
@virenjoshi 3 жыл бұрын
Very Well Explained
@FarahHawa
@FarahHawa 3 жыл бұрын
Glad it was helpful!
@chiragbablani8325
@chiragbablani8325 4 жыл бұрын
was learning basics about buffer overflow and practiced some forensics tools. Twitter handle: @vuld0
@1secmonk
@1secmonk 3 жыл бұрын
beautiful lady with beautiful video ...
@vitortorres-
@vitortorres- 4 жыл бұрын
This month i learned more about blind ssrf and AD exploitation too, @kr1n1k
@sunilbhamare
@sunilbhamare 4 жыл бұрын
I have learned Nuclei & ffuf tool this month. @sunilb77
@OxOv3rH4uL
@OxOv3rH4uL 4 жыл бұрын
Learnt how to find bugs this month!!! Twitter Handle: @OH4ul
@haydene3802
@haydene3802 3 жыл бұрын
Correct me if I'm wrong. This isn't poisoning a DNS server cache but rather the web servers cache itself?
@FarahHawa
@FarahHawa 3 жыл бұрын
That's right! :)
@secureitmania
@secureitmania 4 жыл бұрын
I learned react native app webview debugging and this cache poisoning @zaheckmania
@ladysecspeare4450
@ladysecspeare4450 4 жыл бұрын
This video gave me the much needed perspective on how to use Param Miner. Thanks a ton. As for the giveaway, I recently learnt about HTTP Request Smuggling Attack this month. My twitter handle is @ladysecspeare. Thanks for providing such useful content for beginners :) You're an inspiration
@pawanchandna3038
@pawanchandna3038 4 жыл бұрын
👍👍
@MuhammadUsman-kw7ks
@MuhammadUsman-kw7ks 4 жыл бұрын
One of the things i learned this month is server side template injection, studied james kettle research on it. If i gets pentesterslab it'll help me a lot. Thanks @UsmanMansha420
@darshanvasu9933
@darshanvasu9933 4 жыл бұрын
I learnt about the attacking on the application server(Encoding and Canonicalization) @darshan33871353
@abhishekkulkarni9250
@abhishekkulkarni9250 4 жыл бұрын
Such a nice video about cache poisoning And I am also in list of competition for pentester academy course Luckily if I won till end of my life remember you for giving a free skill through course This month I learned about advanced manual sql injection and xxe attacks Twitter id : @Abhi_koolkarni
@manideeppuligilla1544
@manideeppuligilla1544 4 жыл бұрын
I have been learning more and more about Burp Extentions, Right now I am unable to use any hope it will help me in the future. My twitter handle is @6manideep
@prathmeshgidde5095
@prathmeshgidde5095 4 жыл бұрын
Can you make video on track phone with phone number
@kaizensky3399
@kaizensky3399 4 жыл бұрын
Thanks for the video. This month I learnt so far, and still learning: JWT based attacks and XXE injection Twitter- @ArseneSky
@sachinmaurya3259
@sachinmaurya3259 4 жыл бұрын
Learning new thing every day thanks to you and this awesome community out there for such content........ I'm glad to have you all ...you people are the one that much us thrive with such great knowledge :) @0x_Mantis
@aadityavishesh3502
@aadityavishesh3502 4 жыл бұрын
I learnt about how to use burp suite!! Twitter handle : akshaynew2011
@toxolarant
@toxolarant 4 жыл бұрын
Hello mam, I learnt to extract stored chrome browser passwords through my python script. @abhijitastlar
@adityarpai4264
@adityarpai4264 4 жыл бұрын
This month I learnt how to hunt for XSS reflective,stored and basics of sast,dast testing of Android app Twitter handle:@adityarpai843
@jawadsaqib1260
@jawadsaqib1260 4 жыл бұрын
Age is the criteria to find whether the page is being cached or not. Am I right? Or is there any other way?
@FarahHawa
@FarahHawa 4 жыл бұрын
Yes, we are using age to figure out whether the page is being cached.
@jawadsaqib1260
@jawadsaqib1260 4 жыл бұрын
@@FarahHawa also is there any specific criteria to check for headers on a specific page or do we hit GUESS HEADERS on each request?
@FarahHawa
@FarahHawa 4 жыл бұрын
If you see the h1 reports in the description, you will see that there's a pattern for which kind of headers are most commonly found in a particular server. For eg: PHP servers allow usage of the X-Forwarded-Host header. But in general, Param Miner is a good tool to discover these because it already has a list of these common headers.
@dheerajr8246
@dheerajr8246 4 жыл бұрын
How can we test this without attacking other users visiting the site ?
@FarahHawa
@FarahHawa 4 жыл бұрын
Add a random parameter in the request line. Check the Portswigger research paper in the description for more info.
@dheerajr8246
@dheerajr8246 4 жыл бұрын
@@FarahHawa Will check it out. Thanks :)
@pavanchow5147
@pavanchow5147 4 жыл бұрын
This month, I have learnt how an user can exploit a web sever and cache so that harmful response is served to other users. Twitter : @pavanchow_ and last week I wanted to scan an address range but it would take forever to do so with nmap. I came across masscan and ZMap. But I liked masscan as I have learnt that it can scan the whole internet under 10 mins. Masscan might really be useful in CTFs.
@sarojdhungana2893
@sarojdhungana2893 4 жыл бұрын
I learned different encryption mode in cryptography. Working to solve labs on ECB and CBC. BTW I like your videos. @roze222_sa
@imuser007
@imuser007 4 жыл бұрын
really explained well. This month I learned python scripting from Coursera & it's more interesting & I'm choose to go for python automation. Twitter -- n4veenx
@mohamedfahim3230
@mohamedfahim3230 4 жыл бұрын
Learnt about big-ip vulnerabilities 2020-3452 2020-3187 cve. @fahimmelethil
@arshiyakhan6789
@arshiyakhan6789 4 жыл бұрын
This month I completed portswiggers challenges and I submitted a bug to bugcrowd which was a duplicate and won't fix as well, Twitter @Hr1chHaxor.
@hacksudo
@hacksudo 4 жыл бұрын
😇😇😇😇😇 super
@binsec01
@binsec01 4 жыл бұрын
I learned about FFUF in depth from codingo. Twitter Handler: @binsec01
@Fuddifadu
@Fuddifadu 4 жыл бұрын
Saw a mind blowing demo on how you can persist and call back a shell in the container environment where lambda/function as a service execute and this demo was applicable to all the current existing cloud vendors. The attack is very sophisticated and requires you to gain access to the cloud environment first. I am preparing the same demo to actually get a hang of it. Handle:- witherer6
@adityaprakashyadav3622
@adityaprakashyadav3622 4 жыл бұрын
This month i learned about xss,host header injection and url redirection and i also completed the web for pentesters from pentester lab from free and i really want to learn more from it it would be so helpfull if you give me one so that i can complete the badges and gain more and more knowledge. And btw thanks for the giveaway💫✨🤗 twitter id- @prakashaditya_
@cyberpirate007
@cyberpirate007 4 жыл бұрын
Noice
@archakpramanik1226
@archakpramanik1226 4 жыл бұрын
I have learned and currently working on Authentication Bypass Attacks and my twitter id is @Archak19 .. Miss I love to see your videos and learns a lot from them Thanks....
@vineet1
@vineet1 4 жыл бұрын
1. i learnt Api pentesting this whole month 2 twitter.com/Vsadawari
Regular Expression DOS FOR BEGINNERS!
9:15
Farah Hawa
Рет қаралды 11 М.
WEB CACHE DECEPTION FOR BEGINNERS!
7:42
Farah Hawa
Рет қаралды 17 М.
The IMPOSSIBLE Puzzle..
00:55
Stokes Twins
Рет қаралды 174 МЛН
If people acted like cats 🙀😹 LeoNata family #shorts
00:22
LeoNata Family
Рет қаралды 17 МЛН
ТВОИ РОДИТЕЛИ И ЧЕЛОВЕК ПАУК 😂#shorts
00:59
BATEK_OFFICIAL
Рет қаралды 6 МЛН
HACKING GraphQL FOR BEGINNERS + GIVEAWAY (closed)
8:58
Farah Hawa
Рет қаралды 36 М.
Exploiting Web Cache Poisoning
16:17
CyberSecurityTV
Рет қаралды 15 М.
ATTACKING JWT FOR BEGINNERS!
7:39
Farah Hawa
Рет қаралды 55 М.
Lab: Web cache poisoning with an unkeyed cookie
7:00
Jarno Timmermans
Рет қаралды 1,7 М.
DNS Cache Poisoning - Computerphile
11:04
Computerphile
Рет қаралды 307 М.
HACKING OAuth 2.0 FOR BEGINNERS!
10:26
Farah Hawa
Рет қаралды 44 М.
$10k+5k Web cache poisoning - Github + Firefox - Bug Bounty Reports Explained
7:33
Bug Bounty Reports Explained
Рет қаралды 21 М.
Cache Poisoning? - Solution to November '22 XSS Challenge
22:02
Intigriti
Рет қаралды 3,9 М.
The IMPOSSIBLE Puzzle..
00:55
Stokes Twins
Рет қаралды 174 МЛН