Hey, it was a very helpful video for cache poisoning. Can you also make a video on correct working of Autorize tool of Burpsuite? I've watched many videos to automate the IDORs using burp but found none to be clear enough.
@smartcomputring10343 жыл бұрын
ap reply kiyu nahi karti sister
@brijeshpal40393 жыл бұрын
Can you please explain with more examples?
@amanjain914 жыл бұрын
This month I learned about how to bypass profile pic upload functionality whenever server checks the content of the image. This functionality is bypassed by bypassing thr gd-php library which is used by the server for validating
@goodboy88333 жыл бұрын
Could u share any link for that
@rajanrawal63962 жыл бұрын
amazing, this could be probably one of the biggest information that i have ever been given. we need such playlist more and more in upcoming days. The way how you explain is an amazing.
@collisioadolebitque41484 жыл бұрын
This month, I learned the importance of building your own methodology, not copying others as well as the need to dig into the tools we use in order to understand how things can be done better.
@emmanuelafolabi68474 жыл бұрын
I found a web cache poisoning attack as of result of your previous web cache video, will def. look out for this... Your videos are great by the way...short but quite explanatory, exactly what I need.
@deepanshuyadav67453 жыл бұрын
I am beginner in bug bounties thanks for sharing, learned a lot keep making these type of videos.
@drwombat2 жыл бұрын
Another excellent, expertly done video. Thank you. Your uploads are clear, concise, brief and informative. Any time I'm having a problem I always check your videos FIRST to see if you have a demonstration about that topic as I prefer your explanations compared to others
@Jaatranger-f1e3 жыл бұрын
Very information vedio
@UmairAli4 жыл бұрын
Very Informative My Dear :) I'm Really impressed , cuz had been searching for a practical use of cache poisoning and dns hijacking all over the internet for like a lot of time, but what I found was only theory , I did manage to perform Dns hijacking from registrar but not cache poisoning until i saw this video thanks a lot.
@wael_shaikh4 жыл бұрын
Yaayyy! You're back! I learned a lot this month thanks to your channel.
@i_zamba4 жыл бұрын
Farah, video is great, but if the background music volume reduced little bit that will be better to concentrate on the juicy content you offer us. Thanks for all your efforts to our community.
@savirsuda4 жыл бұрын
This was the best Cache poisoning video I have ever seen! Thanks Farah :)
@phpdude4 жыл бұрын
Hey Farah, great video as always! Am learning from them and looking forward to more... And learning about exploiting null byte buffer overflow from one of Sam Currys posts but haven't been able to digest it fully yet. Hope to do so soon... Stay safe and keep making those awesome vids girl... Till then
@Najumulsaqib3 жыл бұрын
If you're hitting the cache and the cache is not refreshing. Try replacing GET with PURGE in the request
@mitulfg71154 жыл бұрын
Thank you for this video. It cleared my most of the doubts regarding web-cache poisoning.
@yrks11094 жыл бұрын
This Month, I learnt more About SSRFs, how to gain RCE through different parameters, more on Reflected XSS and some sprinkle of XXEs :)
@yrks11094 жыл бұрын
My Twitter Handle : @Neutron__
@gladysorrego60544 жыл бұрын
El próximo video podría ser sobre IPSec y su Anti Replay para concienciar y cambiar a IPv6? Soy un fan de IPv6, dejar atrás NAT y A record. Abrazar los AAAA récord.
@vergil_3894 жыл бұрын
Hi 😆 This month I've learned Public key Cryptosystems The RSA ALGORITHM Diffie Hellman Key exchange Comparison of RSA and DES Elliptic curve Cryptography Number theory Concepts
@sureshkumar77534 жыл бұрын
Short and sweet.. Thanks @farah
@jbjb89764 жыл бұрын
I learn Today web cache poisoning, great video, Thank You.
@manojb18023 жыл бұрын
Interesting..I love this video. It's helpful for my career.
@anisazam81552 жыл бұрын
A/s as i started web testingas my career so i also always explore types of web vulnerability and you did great job at this time . 👍🏻 keep it up
@MH-tw1qi4 жыл бұрын
In this month I learned about redos
@rimbasec97084 жыл бұрын
This month I studied many vulnerabilities based on the OWASP top 10. I use Burp suite as a tool for penetration testing, starting with solving several web security academy labs (Portswigger), after that I practice doing (ethical) penetration tests on several web applications where I work for. From there I found quite a number of severity level vulnerabilities from LOW to Critical (SQL Injection). BTW, thanks for uploading this video. That has been a huge help in my journey into cybersecurity. Twitter : @muhandipras
@Arummekarlayung07064 жыл бұрын
Long time no see ❤️
@elliot90664 жыл бұрын
I learned some bypass bypassd mfa 403 2f and many more things:P
@rutikhajare10534 жыл бұрын
In this month i have mainly focused on cashe poisoning...I've read about cashe poisoning earlier but those are not easy to understand but your video is too good and easy to understand...I'm definitely gonna apply your tips mentioned in this video..!! And thanks for creating super video ! @HajareRutvik
@jakariaislamshanto12174 жыл бұрын
Hello Farah ! so in this month i've learned Broken access control and privilege escalation .I 've also submitted a bug report related to privilege escalation(finger crossed) . Hope you have a good day .@ShantoJj
@ahmedabdelfadeel22114 жыл бұрын
This month i have read 4 chapters (xss - Attacking Access Control - Attacking Application Logic - Attacking Back-End Components ) of The Web Application Hackers Handbook @delox101
@8873109544 жыл бұрын
i learned qualys app scan, it is really very useful for devsecops
@8873109544 жыл бұрын
@Ashutos7ank
@Nothing-lh9hp4 жыл бұрын
Thanks for your amazing chennal, how we could find blind sqli I know that type of bug but how can find it
@amirhassan11003 жыл бұрын
Thanks a lot for this video. I definitely learned a lot of things. Geep up the good work
@FarahHawa3 жыл бұрын
Glad it was helpful!
@jaggedmule142 жыл бұрын
Thanks :) it was very helpful
@rakeshnai12874 жыл бұрын
Welcome back
@sarthakmathur76964 жыл бұрын
This week I read an article about exploiting Regular Expressions , which for me was very amusing because I never thought Regular Expressions can be exploited. Basically we can provide certain string to the RE engine and it will cause it to waste it resources thereby creating a kind of a DOS Attack. Your videos are short and to the point. Thanks for sharing the knowledge with the community. Keep Going Girl!!! Twitter Handle: @Phantom80305095
@aviralgupta98694 жыл бұрын
Who all know me I am one of the first giveaway winners 😎😎
@mukoshmanob92404 жыл бұрын
can you plzz make a video about IDOR on post request???
@testingx014 жыл бұрын
Thank you for the insightful video!
@hax0rl33t23 жыл бұрын
This is actually a good video.
@vijaySingle1433 жыл бұрын
Thanks Farah. 👍
@vwonwheels56494 жыл бұрын
Nice work......keep sharing information.....🙂
@sekharpoola13964 жыл бұрын
In this month i learned a lot by doing challenges. I think open redirection is occurs in every page if we spider is correctly. I can across a new open redirect bug in between the url. I hoping a certificate for that bug. Thank
@sekharpoola13964 жыл бұрын
@sekharlee twitter
@maurusergio4 жыл бұрын
please, could you enable subtitles on the video?
@sivasiva-sh6hl4 жыл бұрын
new thing i have discoverd is farah hawa is an indian
@vamsikolati4 жыл бұрын
Hey great video 😀. To poison the cache response, our task is to find a unkeyed input and poison , So we are using param miner to mine headers that can be reflected in response if used in the request ?? Is this correct ??
@MmM-iu1sz3 жыл бұрын
Any idea on the tool using here?
@vaibhavgaikwad42913 жыл бұрын
How to exploit web cache poisoning with X-timer header?
@debprasadbanerjee50053 жыл бұрын
Great content, neatly presented.
@Rahul_Kumar_EE4 жыл бұрын
In this mounth iam found in glitch in whatsapp. In read receipt function ..👍 I request you please tell me the from where I star the hacking journey. And sorry iam not using Twitter and some one deserve that giveaway not me because I have not master on pentesting
@wadgamer101010 ай бұрын
Thank you very much, keep it up ❤
@enpassant73584 жыл бұрын
The coolest thing I learned this month was to use Python to create a simple web server in order to copy files over the Internet from the directory where I start the server. The command is: python -m SimpleHTTPServer 8080 @cts_technology
@ronykroy57664 жыл бұрын
Great presentation
@Thelostblud4 жыл бұрын
I am very new in this field jst read web application hacker handbook 2 @1-6 chapters and learn abbout -Host header attack and 2- bussiness logic vulnerability and at last 3 - web cache poisoning bt nt this 1 lab. I am not able or i am not understanding how to apply can someone help me
@utensilapparatus86923 жыл бұрын
Awesome
@XDms854 жыл бұрын
I have learnt more about Graphql and how to make queries. As always great video! @xdms85
@Mochi-kane3 жыл бұрын
Thank you.
@MishisFamily4 жыл бұрын
Thank you so much Farah, very useful content, I enjoyed learning about this topic that I didn't know so much. Take care, hope you're doing well in University and keep it up. Well done.
@kaygeesiddharth15924 жыл бұрын
Yeah . This month I learnt bash & RCE via Shell upload . Twitter handle @Kg_siddharth
@kushagraaa4 жыл бұрын
Tried learning some basics of android security and also started solving some ctf's at hackerone. Twitter handle: @psychedelicbyte
@anshusharma51994 жыл бұрын
I learnt jwt and web chach poisoning this month. Thanks for those videos And Thanks for your amazing content 😊 @AnshBhardwaj999
@abhimanyumishra81853 жыл бұрын
Hey Farah ! can a web cache poisoning vulnerability be used to get cookies of other users ?
@FarahHawa3 жыл бұрын
yes, it could be possible with an XSS
@abhimanyumishra81853 жыл бұрын
@@FarahHawa you mean using xss ! 🤔Hmm ok , Farah is there any other way to get cookies (other than web cache and xss)
@becool54834 жыл бұрын
madam im complete beginner... basically im a mechanical engineer... i just know computer fundamentals, linux shell... exactly i dont know from where to start.... which programming language should i chose first??? please kindly suggest me!!!
@rajesha86264 жыл бұрын
start with python. and try practicing hacking skills in tryhackme .. by the way i am a mechanical engineer too
@Malware014 жыл бұрын
I learn invest in pentesterlab to get advance stuff otherwise we have lot of "For Begineers" content available. @mt_ins
@danishalvi97314 жыл бұрын
App ke video bhot late hain Videos weekly basis pa upload kia karain
@muralidharansubburaman88634 жыл бұрын
I am noob to hackthebox and learning pwk. This week worked my way through legacy box.. kept myself away from the writeups and it was a ton of learning. @muralidharan89 -
@jerrytech19014 жыл бұрын
gud one..
@virenjoshi3 жыл бұрын
Very Well Explained
@FarahHawa3 жыл бұрын
Glad it was helpful!
@chiragbablani83254 жыл бұрын
was learning basics about buffer overflow and practiced some forensics tools. Twitter handle: @vuld0
@1secmonk3 жыл бұрын
beautiful lady with beautiful video ...
@vitortorres-4 жыл бұрын
This month i learned more about blind ssrf and AD exploitation too, @kr1n1k
@sunilbhamare4 жыл бұрын
I have learned Nuclei & ffuf tool this month. @sunilb77
@OxOv3rH4uL4 жыл бұрын
Learnt how to find bugs this month!!! Twitter Handle: @OH4ul
@haydene38023 жыл бұрын
Correct me if I'm wrong. This isn't poisoning a DNS server cache but rather the web servers cache itself?
@FarahHawa3 жыл бұрын
That's right! :)
@secureitmania4 жыл бұрын
I learned react native app webview debugging and this cache poisoning @zaheckmania
@ladysecspeare44504 жыл бұрын
This video gave me the much needed perspective on how to use Param Miner. Thanks a ton. As for the giveaway, I recently learnt about HTTP Request Smuggling Attack this month. My twitter handle is @ladysecspeare. Thanks for providing such useful content for beginners :) You're an inspiration
@pawanchandna30384 жыл бұрын
👍👍
@MuhammadUsman-kw7ks4 жыл бұрын
One of the things i learned this month is server side template injection, studied james kettle research on it. If i gets pentesterslab it'll help me a lot. Thanks @UsmanMansha420
@darshanvasu99334 жыл бұрын
I learnt about the attacking on the application server(Encoding and Canonicalization) @darshan33871353
@abhishekkulkarni92504 жыл бұрын
Such a nice video about cache poisoning And I am also in list of competition for pentester academy course Luckily if I won till end of my life remember you for giving a free skill through course This month I learned about advanced manual sql injection and xxe attacks Twitter id : @Abhi_koolkarni
@manideeppuligilla15444 жыл бұрын
I have been learning more and more about Burp Extentions, Right now I am unable to use any hope it will help me in the future. My twitter handle is @6manideep
@prathmeshgidde50954 жыл бұрын
Can you make video on track phone with phone number
@kaizensky33994 жыл бұрын
Thanks for the video. This month I learnt so far, and still learning: JWT based attacks and XXE injection Twitter- @ArseneSky
@sachinmaurya32594 жыл бұрын
Learning new thing every day thanks to you and this awesome community out there for such content........ I'm glad to have you all ...you people are the one that much us thrive with such great knowledge :) @0x_Mantis
@aadityavishesh35024 жыл бұрын
I learnt about how to use burp suite!! Twitter handle : akshaynew2011
@toxolarant4 жыл бұрын
Hello mam, I learnt to extract stored chrome browser passwords through my python script. @abhijitastlar
@adityarpai42644 жыл бұрын
This month I learnt how to hunt for XSS reflective,stored and basics of sast,dast testing of Android app Twitter handle:@adityarpai843
@jawadsaqib12604 жыл бұрын
Age is the criteria to find whether the page is being cached or not. Am I right? Or is there any other way?
@FarahHawa4 жыл бұрын
Yes, we are using age to figure out whether the page is being cached.
@jawadsaqib12604 жыл бұрын
@@FarahHawa also is there any specific criteria to check for headers on a specific page or do we hit GUESS HEADERS on each request?
@FarahHawa4 жыл бұрын
If you see the h1 reports in the description, you will see that there's a pattern for which kind of headers are most commonly found in a particular server. For eg: PHP servers allow usage of the X-Forwarded-Host header. But in general, Param Miner is a good tool to discover these because it already has a list of these common headers.
@dheerajr82464 жыл бұрын
How can we test this without attacking other users visiting the site ?
@FarahHawa4 жыл бұрын
Add a random parameter in the request line. Check the Portswigger research paper in the description for more info.
@dheerajr82464 жыл бұрын
@@FarahHawa Will check it out. Thanks :)
@pavanchow51474 жыл бұрын
This month, I have learnt how an user can exploit a web sever and cache so that harmful response is served to other users. Twitter : @pavanchow_ and last week I wanted to scan an address range but it would take forever to do so with nmap. I came across masscan and ZMap. But I liked masscan as I have learnt that it can scan the whole internet under 10 mins. Masscan might really be useful in CTFs.
@sarojdhungana28934 жыл бұрын
I learned different encryption mode in cryptography. Working to solve labs on ECB and CBC. BTW I like your videos. @roze222_sa
@imuser0074 жыл бұрын
really explained well. This month I learned python scripting from Coursera & it's more interesting & I'm choose to go for python automation. Twitter -- n4veenx
@mohamedfahim32304 жыл бұрын
Learnt about big-ip vulnerabilities 2020-3452 2020-3187 cve. @fahimmelethil
@arshiyakhan67894 жыл бұрын
This month I completed portswiggers challenges and I submitted a bug to bugcrowd which was a duplicate and won't fix as well, Twitter @Hr1chHaxor.
@hacksudo4 жыл бұрын
😇😇😇😇😇 super
@binsec014 жыл бұрын
I learned about FFUF in depth from codingo. Twitter Handler: @binsec01
@Fuddifadu4 жыл бұрын
Saw a mind blowing demo on how you can persist and call back a shell in the container environment where lambda/function as a service execute and this demo was applicable to all the current existing cloud vendors. The attack is very sophisticated and requires you to gain access to the cloud environment first. I am preparing the same demo to actually get a hang of it. Handle:- witherer6
@adityaprakashyadav36224 жыл бұрын
This month i learned about xss,host header injection and url redirection and i also completed the web for pentesters from pentester lab from free and i really want to learn more from it it would be so helpfull if you give me one so that i can complete the badges and gain more and more knowledge. And btw thanks for the giveaway💫✨🤗 twitter id- @prakashaditya_
@cyberpirate0074 жыл бұрын
Noice
@archakpramanik12264 жыл бұрын
I have learned and currently working on Authentication Bypass Attacks and my twitter id is @Archak19 .. Miss I love to see your videos and learns a lot from them Thanks....
@vineet14 жыл бұрын
1. i learnt Api pentesting this whole month 2 twitter.com/Vsadawari