Scan Websites for Potential Vulnerabilities Using Vega in Kali Linux [Tutorial]

Поділитися
Вставка
  • Опубліковано 24 лис 2020
  • Our Premium Ethical Hacking Bundle Is 90% Off: nulb.app/cwlshop
    How to Scan Web Apps for Vulnerabilities in Kali Linux
    Full Tutorial: nulb.app/z48gr
    Subscribe to Null Byte: goo.gl/J6wEnH
    Tim's Twitter: / tim51092
    Cyber Weapons Lab, Episode 201
    Vega Vulnerability Scanner can be used by both attackers and by site administrators to detect XSS (cross-site scripting), SQL injection, and other vulnerabilities on public websites. Setting it up can be quite the chore, though. But in this episode of Cyber Weapons Lab, we'll show how to install and configure Vega on Kali Linux, as well as go over a few examples of detected vulnerabilities and what they mean.
    To learn more, check out the article on Null Byte: nulb.app/z48gr
    Follow Null Byte on:
    Twitter: / nullbyte
    Flipboard: flip.it/3.Gf_0
    Website: null-byte.com
    Weekly newsletter: eepurl.com/dE3Ovb
    Vimeo: vimeo.com/channels/nullbyte
  • Навчання та стиль

КОМЕНТАРІ • 145

  • @zayanalrashdr3948
    @zayanalrashdr3948 3 роки тому +27

    Still the best UA-cam channel for ethical hackers students
    But I hope someday you make course about one topic instead of random video about different subjects

  • @wintorez6649
    @wintorez6649 3 роки тому +25

    Hlw sir big fan love from India 🇮🇳❤️❤️🇮🇳🇮🇳❤️

  • @hridaybhatia5643
    @hridaybhatia5643 3 роки тому +2

    Love your videos too informative ❤️
    Thanks for sharing such knowledge love from India ❤️

  • @shashank.s1492
    @shashank.s1492 3 роки тому +1

    You are my favourite teachers
    KEEP GOING!!!❤️❤️❤️❤️

  • @francescopresta9570
    @francescopresta9570 3 роки тому

    Very good job, thanks to Tim and tokyoneon

  • @rodricbr
    @rodricbr 3 роки тому

    this is gonna be very useful, thanks for the video

  • @Faizy_Ahmad
    @Faizy_Ahmad 3 роки тому +1

    Brilliant app...even more brilliant tutorials.

  • @outlaw8379
    @outlaw8379 3 роки тому +42

    awesome video! But I always wondered who owns the channel, my no blinky friend or the other 2 guys?

    • @MrSpiderballs
      @MrSpiderballs 3 роки тому +7

      No blinky friend. Gotta love em they very talented

    • @outlaw8379
      @outlaw8379 3 роки тому +2

      @@MrSpiderballs ahh good to know

    • @NullByteWHT
      @NullByteWHT  3 роки тому +8

      None of the above, it's owned by WonderHowTo. You can find no blink's (Kody's) content at hack.gay

    • @outlaw8379
      @outlaw8379 3 роки тому +1

      @@NullByteWHT ohh that makes sense, thank you!

    • @Yorak404
      @Yorak404 3 роки тому +1

      @@NullByteWHT oh wow ok I never knew I love kody No homo but we all thought he owned the channel rip

  • @7zark785
    @7zark785 3 роки тому +29

    Probably took so long because you left the proxy selected after telling us it will slow it down.

  • @abhijithk.namboothiry2046
    @abhijithk.namboothiry2046 3 роки тому +8

    libwebkit is not available, as it is deprecated...

  • @1981bbrad
    @1981bbrad 3 роки тому

    Great video / extremely well delivered, Question re OSINT Tools though is it more "US Centric"? or could other countries make solid use of it? Greets to all the Nullbyte crew from Perth Australia keep up the awesome work

  • @brayaneduardomarroquin5063
    @brayaneduardomarroquin5063 3 роки тому

    Nice tool, thanks for shared

  • @melquiadeszeempeda9142
    @melquiadeszeempeda9142 3 роки тому

    Ready for de lesson

  • @realhomy
    @realhomy 3 роки тому +1

    Another video let’s go

  • @f9dupo652
    @f9dupo652 3 роки тому

    Great tut, btw can we generate reports on this? thanks

  • @sujalsingh46f
    @sujalsingh46f 3 роки тому

    Love you...you are real!👍

  • @darklawtivity6831
    @darklawtivity6831 11 місяців тому

    Bruh I found an optical illusion with those LED lights,
    specifically the diagonal one on the top left tip of the laptop.
    You can either make it look like they are slowly moving or moving really fast depending on how you look at it.
    Shifting your eyes back and forth can help replicate this. Crazy...

  • @jameshowlett2729
    @jameshowlett2729 3 роки тому

    How can I acquire the skills and knowledge to verify the information provided by the tool if its legit or not? Same with all other tools, thats been my weakness when it comes to web scanning. Like how do I know its a possible XXS based from the GET info.

  • @YashKumar-it5fr
    @YashKumar-it5fr 3 роки тому

    Awesome 👍👍👍😊👍

  • @patriciam8105
    @patriciam8105 Рік тому

    I would like to ask if the site under test has no effect on that website. and the website owner doesn't know it. Thanks

  • @raymonddavid5749
    @raymonddavid5749 2 роки тому

    Please how can I solve this issues when I wanna check my web application with Vega , it’s showing network problem while retrieving url

  • @4n0nmann5
    @4n0nmann5 3 роки тому +5

    can you compare it with ZAP and OpenVAS please?

  • @bartas7261
    @bartas7261 3 роки тому +1

    Nice.

  • @AEURRR
    @AEURRR Рік тому

    There is no 2. alternative option for java and it still gives error cuz i cant select that 2. one please help
    what do i do

  • @saturnphp
    @saturnphp 3 роки тому +1

    how this performs against Metasploit

  • @benbua3462
    @benbua3462 4 місяці тому

    hey does it work on every website? i want to start ethical hacking

  • @Zer0nuke
    @Zer0nuke Рік тому

    Thank you but when I try to open the vega executable I got an error message "vega scanner failed to load the jni library ................................. jvm.dll

  • @habib0810
    @habib0810 3 роки тому +22

    wait havent watched this channel in ages where is the no blink guy?

    • @cedurick
      @cedurick 3 роки тому +9

      He's been letting his buddies get some screen time.

    • @NullByteWHT
      @NullByteWHT  3 роки тому +29

      That "no blink guy" was just in the last video - the 200th one. Check it out!

    • @hyperdragon1013
      @hyperdragon1013 3 роки тому +4

      @@NullByteWHT yeah but is everything ok with him?

    • @hyperdragon1013
      @hyperdragon1013 3 роки тому

      @Bernd Lauert point taken

    • @zainulabedin7311
      @zainulabedin7311 3 роки тому +4

      Unfortunately he blinked in one of his videos . i dont know if he was short on ritalin or adderal

  • @nelsontovars
    @nelsontovars 3 роки тому

    Amazing

  • @commandroid9336
    @commandroid9336 3 роки тому

    How to exploit these vulnerabilities if we get any

  • @harze6818
    @harze6818 2 роки тому

    why do i get "Network Problem while retrieving URI" when trying to scan a url?

  • @techwarrior1608
    @techwarrior1608 3 роки тому

    sir how we can find the number of pages scanned ?

  • @omairtech6711
    @omairtech6711 3 роки тому

    Is Vega better then burpsuite and Zap?

  • @melquiadeszeempeda9142
    @melquiadeszeempeda9142 3 роки тому

    Just on time

  • @tangducbao7309
    @tangducbao7309 3 роки тому

    Vega has lacked of support for few years, I don't know that will the owner maintain it any more

  • @mrgasmask7584
    @mrgasmask7584 3 роки тому

    does it work on the newest verision

  • @bo55-jsr
    @bo55-jsr 3 роки тому +2

    Yessir

  • @jayden__lee
    @jayden__lee 3 роки тому +1

    sir,can you teach me dns hijack and network penetration?

  • @sus-it5tr
    @sus-it5tr 3 роки тому

    Hey you have splunk my dad uses that I don't understand much also I brute force the password on my grandma's Google account cuz I learned how to do it. Also what do you do with splunk

  • @gokulcloud9698
    @gokulcloud9698 8 місяців тому

    Failed to connect to Target:
    Network problem while retrieving URI **************
    I'm getting this error while installing in windows 11

  • @prethivivs6392
    @prethivivs6392 3 роки тому

    What laptop model your using

  • @rohitdas490
    @rohitdas490 5 місяців тому

    I think it is not available for Kali ARM64 installed on a MacBook m1 pro

  • @CG_25_Riders
    @CG_25_Riders 3 роки тому

    Ham apka bahut bahut abhari hai from india

  • @Fadedfrost1
    @Fadedfrost1 3 роки тому

    💯 NoiCE 👌🏼

  • @viniciusbruno2340
    @viniciusbruno2340 3 роки тому

    I could make a video by downloading Bluetooth adapter drivers for Kali Linux, I've tried several ways and it didn't work.

  • @Ok-pk2ir
    @Ok-pk2ir 3 роки тому +1

    How to inject SQL script

  • @calamitist
    @calamitist 3 роки тому

    libwebkitgtk wont download , i trid libwebkitgtk-1.0-0 and it said its absoleted and it has no candidate
    im i missing something?

  • @hackerstech4025
    @hackerstech4025 3 роки тому

    Bring video on malware and how go mke

  • @wolfdecode5208
    @wolfdecode5208 2 роки тому +2

    Getting an error" An error has occurred. See the log file
    /home/kali/vega/vega/configuration/1641307382767.log. " Also not able to install libwebkitgtk, it shows unable to locate package
    even getting this error for libwebkitgtk. tried the source list thing as u mentioned but wasn't of any use,it shows no installation candidate. please help

    • @kemo_963
      @kemo_963 Місяць тому

      bro, u solve it?

  • @saravindsamy4228
    @saravindsamy4228 3 роки тому

    Hlo sir kindly explain finding theft mobile phones using imei number.

  • @NinjaHempKnight
    @NinjaHempKnight 3 роки тому +1

    Cody started the channel

  • @tonybeasley3044
    @tonybeasley3044 Рік тому

    you should teach how to make to build our own firewall to protect our selfies

  • @kachahaan1660
    @kachahaan1660 3 роки тому

    But is it not a bit outdated. It checks for vulnerabilities from 2014. How can we use nowadays vulnerabilities?

  • @dolalord4929
    @dolalord4929 3 роки тому

    sir can you demonstrate a video on how SCL-2052 wifi interceptor works

  • @elle52
    @elle52 3 роки тому

    possible on windows?

  • @xzeroxvan0726
    @xzeroxvan0726 3 роки тому +2

    Termux?

  • @mrgasmask7584
    @mrgasmask7584 3 роки тому

    it is libwebkitgtk-1.0 right?

  • @rizkiadisaputra5971
    @rizkiadisaputra5971 3 роки тому

    from Indonesia 🇮🇩

  • @johnsmithking6646
    @johnsmithking6646 3 роки тому

    “ I hope you guys are able to use it in a constructive way “ lol

  • @kachahaan1660
    @kachahaan1660 2 роки тому

    sudo apt install libwebkitgtk-1.0 default-jdk unzip does not work in current kali

  • @nkrak1650
    @nkrak1650 3 роки тому

    So is this tool and OWASP ZAP commonly used by bug bountys?

    • @xamael1989
      @xamael1989 2 роки тому

      @@outlaw8379 Thanks for the insight I really looking into writing custom exploits how do people get started.

  • @Balooni24
    @Balooni24 3 роки тому

    Please help with this error .. Error >> "/root/.vega/workspaces/00/model.db' closed by ShutdownHook"

    • @nakomputer3716
      @nakomputer3716 3 роки тому

      You mtust have java 8

    • @Balooni24
      @Balooni24 3 роки тому

      @@nakomputer3716 I have already mentioned that it is not working in Java 8?

  • @akim5030
    @akim5030 2 роки тому

    What's the difference between Vega and burpsuite active scan?

    • @shantanubharadwaj1849
      @shantanubharadwaj1849 5 місяців тому

      yea , same question cauz the interference looks almost the same

  • @endlessVoiid
    @endlessVoiid 3 роки тому +1

    are we allowed to scan your website?? nullbyte

  • @HarmoniSiagian_
    @HarmoniSiagian_ Рік тому

    Did you have video how to install kali linux on virtual box?

  • @vincent70able
    @vincent70able 8 місяців тому

    sorry friend when can i install vega scanner on any distro linux with these step by step .TANHK'S

  • @gomblade5677
    @gomblade5677 3 роки тому

    What to do if when you paste the link it says command not found?

  • @tommmgreco
    @tommmgreco 3 роки тому

    /root/.vega/workspaces/00/model.db' closed by shutdown hook

  • @enigma9445
    @enigma9445 3 роки тому

    Мой второй компьютер, хорошая наклейка

  • @michaelsmith5672
    @michaelsmith5672 3 роки тому +1

    sudo apt install libwebkitgtk-1.0-0 default-jdk unzip
    E: Package 'libwebkitgtk-1.0-0' has no installation candidate.

  • @mackydomz1474
    @mackydomz1474 3 роки тому

    It's like burp suite.

  • @savirsuda
    @savirsuda 3 роки тому

    Skid method

  • @ten101337
    @ten101337 3 роки тому +6

    installs zip so he can use wget and unzip in console. just click the damn link and extract in gui...

    • @hydroxder75
      @hydroxder75 3 роки тому

      Is that schechy or dangerous i don't understand sorry.

  • @rift9891
    @rift9891 3 роки тому

    💪👍

  • @violetto7769
    @violetto7769 3 роки тому

    Latest kali doesn't include vega as build in. Now i can't run this program. Arghh too lazy to fix.

    • @gerard8203
      @gerard8203 3 роки тому

      sudo apt-get install libwebkitgtk-1.0

  • @Somedifflove
    @Somedifflove Рік тому

    I'm aware this video is old but if anyone can help me that would be nice, when I try to download libwebkitgtk it would give me an error like "Package libwebkitgtk-1.0(I also tried libwebkitgtk-1.0-0) is not available but is referred to by another package" I am new to downloading things with linux so if anyone can help me I would like that, thank you.

  • @sivasiva-sh6hl
    @sivasiva-sh6hl 3 роки тому

    Love from tamilians

  • @dohnjoe4907
    @dohnjoe4907 3 роки тому +2

    Cross-site Script include is not Cross-site scripting.....

  • @anonp2958
    @anonp2958 3 роки тому +1

    Sadly, web app tools generally find low hanging fruit.

  • @nazrayayas8924
    @nazrayayas8924 3 роки тому

    how to tap a pc via sending a link

  • @hackerism8069
    @hackerism8069 4 місяці тому

    vega site is dead the ports are fine but sever its not maintained

  • @kickassvideos5469
    @kickassvideos5469 3 роки тому

    PLS HELP!!! I NEED THE SONG FROM THE INTRO!!!

  • @sdafasfF
    @sdafasfF 3 роки тому +1

    who tf r u broskie what happened to my boy the OG my friend with the german haircut also like your cut G and your content

  • @mahmutivanov1204
    @mahmutivanov1204 3 роки тому +1

    Send me more

  • @zeus-x0722
    @zeus-x0722 3 роки тому

    Hello, Freind, I have an error message: Unable to locate package libwebitgtk-1.0

    • @NullByteWHT
      @NullByteWHT  3 роки тому +1

      Try libwebkitgtk-1.0-0 instead.

    • @mover1002
      @mover1002 3 роки тому +3

      @@NullByteWHT Reading package lists... Done
      Building dependency tree
      Reading state information... Done
      Package libwebkitgtk-1.0-0 is not available, but is referred to by another package.
      This may mean that the package is missing, has been obsoleted, or
      is only available from another source
      E: Package 'libwebkitgtk-1.0-0' has no installation candidate

    • @rodricbr
      @rodricbr 3 роки тому +1

      ​@@mover1002 same
      edit: it might be already installed in your system, but it's not showing up, like with me

    • @NullByteWHT
      @NullByteWHT  3 роки тому +2

      @@mover1002 Add this to your sources.list and try again, see if that does anything: github.com/subgraph/Vega/issues/177#issuecomment-583778551

    • @TechyMedico
      @TechyMedico 3 роки тому +1

      @@NullByteWHT Thanks, this solution worked for me.

  • @cybercode7482
    @cybercode7482 3 роки тому

    Brother can you help me please please

  • @JoseHernandez-pg3ml
    @JoseHernandez-pg3ml 3 роки тому

    What UP

  • @vitamine1844
    @vitamine1844 2 роки тому

    error workspace/.metadata/.log.

  • @swapnilshinde9868
    @swapnilshinde9868 3 роки тому

    I thought he's missing *Right Hand* for first 10 seconds? WTF... Why?

  • @kristanrodrigues7705
    @kristanrodrigues7705 3 роки тому +3

    Is it just me or does his constant eye movement show his lack of confidence in the script

  • @jasonmoore4429
    @jasonmoore4429 3 роки тому

    Hello algorithm

  • @johnoneill8178
    @johnoneill8178 2 роки тому

    does not work anymore

  • @asasdasd-ms6qx
    @asasdasd-ms6qx 2 роки тому

    Hello

  • @eyeinthesky1050
    @eyeinthesky1050 3 роки тому +1

    everything is Linux, it would be nice if you could explain how to use some of your amazing works in Windows too ifpossible! Not everyone use Linux!

    • @moldybubbles6543
      @moldybubbles6543 3 роки тому +1

      You can get a virtual machine for kali linux for free. There are many guides online that should help set you up with a linux machine inside a windows computer.

    • @cedurick
      @cedurick 3 роки тому +2

      your attitude is going to have to change if you want to do this kind of stuff seriously. most of the computers on earth run Linux. you have to learn.
      get virtualbox and make a kali VM. there are a trillion tutorials for this, you can do it!

    • @rodricbr
      @rodricbr 3 роки тому +2

      you can easily download a vm and get a kali linux from offensive security website

    • @eyeinthesky1050
      @eyeinthesky1050 3 роки тому +1

      @@moldybubbles6543 thanks bro, Linux is good for those who are already kind of good with these stuff and for newbies it takes even more time! But i will creat a VM and dl Linux! thanks again

    • @aishwarygupta3729
      @aishwarygupta3729 3 роки тому

      Buy a raspberry pi and run the Linux OS of your choice. It's a bit expensive though but runs smoothly

  • @baskaran.mbaskaran.m5578
    @baskaran.mbaskaran.m5578 3 роки тому

    Hey Kody where r u??? 👀🧐🧐

  • @robinsingh9260
    @robinsingh9260 3 роки тому

    Where is Kody kinzie

  • @abhilashp1308
    @abhilashp1308 3 роки тому

    it's showing this "/root/.vega/workspaces/00/model.db' closed by ShutdownHook"

  • @mlx4548
    @mlx4548 3 роки тому

    helo

  • @anonymous-rq2dp
    @anonymous-rq2dp 3 роки тому

    Error >> "/root/.vega/workspaces/00/model.db' closed by ShutdownHook"

  • @YOUCEFPAIN
    @YOUCEFPAIN 3 роки тому +1

    that very different from what we study in Africa , press 🖱 start to start