WEB CACHE DECEPTION FOR BEGINNERS!

Поділитися
Вставка
  • Опубліковано 25 лис 2024

КОМЕНТАРІ • 98

  • @sivakumar-id3he
    @sivakumar-id3he 4 роки тому +10

    Your way of explaining things with an example using labs is amazing........

  • @ZaidKhan-nk7xr
    @ZaidKhan-nk7xr 3 роки тому +2

    This video proves that a single video is enough to understand the concept. Great Work.😀

  • @MokshitKalRa
    @MokshitKalRa 3 роки тому +1

    Di, I thought Web Cache poisning is So hard to understand because It is a P1 Vulnerability and P1 are difficult to learn but You Made My Day Today, Thanksssssss a Lot Farah Di!
    ❤️

  • @rohitsoni9325
    @rohitsoni9325 4 роки тому +3

    Awesome!
    Just to add a bit more to it:
    Whether a page should be cached or not, also depends on a response header Vary. Do check that out to know exactly what is being used to cache the pages of the website. (Cookies, Accept-Encoding, Extensions etc.).

    • @FarahHawa
      @FarahHawa  4 роки тому +1

      This doesn’t really matter for this attack but thank you for the info! :)

    • @FarahHawa
      @FarahHawa  4 роки тому

      They don't matter for this particular attack. They are important for other cache-related attacks though.

  • @mehrabhasan5773
    @mehrabhasan5773 4 роки тому

    Your method of teaching is really helpful for beginners like me

  • @sanghadiyasunil3489
    @sanghadiyasunil3489 4 роки тому +2

    Its amazing teaching stayle. Thank you Ma'am.

  • @VikasSingh-eu4gb
    @VikasSingh-eu4gb 4 роки тому

    Your explanation is so good please continued for other topics

  • @darshanjogi5781
    @darshanjogi5781 4 роки тому +1

    Love your videos . Please make practical video on idor bug .

  • @samsingh7025
    @samsingh7025 4 роки тому +1

    Content getting better and better 👍👍👌👌

  • @donhasan4690
    @donhasan4690 3 роки тому

    Just wow learned many things from your video

  • @RogueSMG
    @RogueSMG 4 роки тому +2

    All the basic relevant info and technical explanations in

  • @prazolbista
    @prazolbista 4 роки тому

    Mo Farah and Farah are my favorite 🥳

  • @ashrafulalim1272
    @ashrafulalim1272 4 роки тому

    you've included some good resources in the description. It's amazing :)

  • @mayureshatole
    @mayureshatole 3 роки тому

    Well Explanied! Thank you

  • @basantkumar-im9gq
    @basantkumar-im9gq 4 роки тому

    The procedure Of Decode is very interesting

  • @15494063y
    @15494063y 4 роки тому

    wonderful farah

  • @arjayhferrer7836
    @arjayhferrer7836 4 роки тому +2

    hey farah your video is really helpful even though i've already been 3 years in bug bounty community, i still find your videos very helpful especially the most basics one i tend to forget it , do you plan creating your udemy tutorials soon?

  • @xnl-h4ck3r
    @xnl-h4ck3r 4 роки тому

    Really well explained and very helpful. Thanks!

  • @theprateekmahajan
    @theprateekmahajan 4 роки тому

    Demos were awesome...

  • @shekharpopatmahadik8106
    @shekharpopatmahadik8106 4 роки тому

    Hello Madam we all like your way of teaching. We are requesting please make a video on the bugcrowed bug bounty where we get how to choose program , initial steps to any bug bounty and how to perform and which tools are used and os is useful for bug bounty and most important report writing for anyone of program in bugcrowed.
    Waiting for your reply.
    Thank you.

  • @pixelstudios6763
    @pixelstudios6763 4 роки тому

    Great Content Farah ! Keep it up !

  • @sandeepjadam4220
    @sandeepjadam4220 4 роки тому

    Great explanation👍

  • @gopalsinghr.
    @gopalsinghr. 4 роки тому

    Super useful information thanks for sharing

  • @kiwinesss
    @kiwinesss 4 роки тому

    Excellent. You have yourself another subscriber :)

  • @mscor4ever139
    @mscor4ever139 3 роки тому

    amazing work , keep it up !

  • @benjaminmunoz9136
    @benjaminmunoz9136 Рік тому

    Thanks!

  • @gf384
    @gf384 4 роки тому

    Good Thanks!

  • @cheffysunnythakkkar7614
    @cheffysunnythakkkar7614 4 роки тому

    You are a rockstar

  • @hordeumvulgare7195
    @hordeumvulgare7195 4 роки тому

    Good work!well explained.

  • @XDms85
    @XDms85 4 роки тому

    Great video thank you, and the lab is very nice :D

    • @FarahHawa
      @FarahHawa  4 роки тому

      Thank you! It took 2 days to figure out all the configurations 😅

  • @Nothing-lh9hp
    @Nothing-lh9hp 4 роки тому

    thanks farah so much for amazing content

    • @FarahHawa
      @FarahHawa  4 роки тому

      Thank you for watching ☺️

  • @zeuscybersec659
    @zeuscybersec659 4 роки тому

    Great content as always✌🏻

  • @amithc9429
    @amithc9429 4 роки тому

    Thank you Farah

  • @sureshkumar7753
    @sureshkumar7753 4 роки тому

    Nice Explanation farah.

  • @AkshayKumar-nm4ci
    @AkshayKumar-nm4ci 4 роки тому

    Nice video, Farah

  • @sail6114
    @sail6114 4 роки тому

    Thanks for the video good work 😎🔥👍

  • @amolgangurde5714
    @amolgangurde5714 4 роки тому

    Excellent 👌 videos

  • @TheDiscourseDen-rr
    @TheDiscourseDen-rr 4 роки тому

    Very well explained

  • @vahabbalouchzahi707
    @vahabbalouchzahi707 3 роки тому

    goood farah

  • @saugat55
    @saugat55 4 роки тому

    awesome explanation. thanks!

  • @Rajsharma-6969
    @Rajsharma-6969 4 роки тому

    Farah mam, awesome content 🔥 thanks for this

    • @FarahHawa
      @FarahHawa  4 роки тому

      Thank you for watching! Glad you liked it☺️

  • @abhishekrajak5481
    @abhishekrajak5481 4 роки тому

    @Farah Hawa. can you make a video on Reflected file download

  • @chandan1980-s8z
    @chandan1980-s8z 4 роки тому

    Please make a video on aws Pentesting. It's my earnest request to you🙏🙏🙏

  • @dronpatel6552
    @dronpatel6552 4 роки тому

    Great explanation keep it up 😇

  • @koushikkarank8875
    @koushikkarank8875 4 роки тому

    Nice vedio 👏

  • @fonshu3806
    @fonshu3806 4 роки тому

    Thank you so much mam.

  • @faique2995
    @faique2995 4 роки тому

    Learned something new ;)

  • @pankajholariya8331
    @pankajholariya8331 3 роки тому

    dhyanwaad...😊

  • @shahidhannure237
    @shahidhannure237 4 роки тому

    Awesome

  • @pentest3155
    @pentest3155 4 роки тому

    Thanks farahh great content ! I tried to setup a lab. I used your default.vcl conf but my profile.php/test.css is not cached :(

  • @davidg9469
    @davidg9469 4 роки тому

    Hi! I'd like your opinion on the platform INE Training, I don't know if it's worth it. Have you used it? Have you known anybody who has? They're quite expensive. Cheers mate!

  • @tejkhandor8568
    @tejkhandor8568 4 роки тому +3

    Hey farah,
    If I want to learn from the very start do you teach online ?

  • @HunterLeoGaming
    @HunterLeoGaming 4 роки тому

    I am your new subscriber

  • @pawanchandna3038
    @pawanchandna3038 4 роки тому

    Really good 👍 👍👍

  • @suryateja9800
    @suryateja9800 4 роки тому

    Informative...

    • @FarahHawa
      @FarahHawa  4 роки тому

      Glad you found it helpful!

  • @123455866201Aaron
    @123455866201Aaron 3 роки тому

    It doesn't work for me when I replicate the lab, I inserted the config code given, it did cache when I change pass to hash for php file but when I try to insert the extension of css or other extensions, it just gave me 404 error, any idea where i went wrong? Everything seemed to work except trying to get it to cache the extension

  • @Earnnewskills
    @Earnnewskills 3 місяці тому

    love you

  • @MohitKumar-dh7eg
    @MohitKumar-dh7eg 4 роки тому

    Nice video

  • @HunterLeoGaming
    @HunterLeoGaming 4 роки тому

    Wow

  • @SiddharthChandrasekaran
    @SiddharthChandrasekaran 4 роки тому

    Condition 1: return profile.php when profile.php/nonexistent.css is requested -- this looks like a software/framework specific vulnerability. Is this really a valid, unpatched attack vector today (I'll be surprised)?

    • @FarahHawa
      @FarahHawa  4 роки тому

      The condition itself isn’t something exploitable. It’s the cache config + this quirk which makes it dangerous. So it’s not an “attack vector” that needs to be fixed. You can install the latest version of php and try it yourself by hosting your own web app.

  • @AVARI-ti
    @AVARI-ti 4 роки тому

    Eu estar apaixonado ❤️❤️❤️

  • @fridayknight1387
    @fridayknight1387 4 роки тому

    Hey, can I ask what is the window you opened @5:07

    • @FarahHawa
      @FarahHawa  4 роки тому +1

      I’m not sure what you’re referring to but the repeater tab of Burp Suite is open at that second.

    • @fridayknight1387
      @fridayknight1387 4 роки тому

      @@FarahHawa yeah. Thank you. I just wanted to know that. Thanks!!

  • @Akash_us
    @Akash_us 4 роки тому

    Hi Farah !!
    Which is the best bug for very beginers to search on live websites for bounties
    I hope you help for noobies "_"

  • @vivsvaansharma4882
    @vivsvaansharma4882 4 роки тому

    Hey, I had a doubt. Even if this info is getting stored in the browser, it is still the user's browser. How can hackers access the browser cache of the user on another laptop/pc.

    • @FarahHawa
      @FarahHawa  4 роки тому

      This is the varnish cache we’re talking about, not the user’s browser cache :) Check the h1 reports in the description, you’ll understand the impact!

  • @shrirangkahale
    @shrirangkahale 4 роки тому

    💯

  • @Test-ed8cm
    @Test-ed8cm 4 роки тому

    Its been a month. Are u still gonna upload in the future?

    • @FarahHawa
      @FarahHawa  4 роки тому +2

      Yes, working on the next one right now. Thanks for being patient 🥺🥺 really appreciate it

    • @jonathanhoyos8191
      @jonathanhoyos8191 4 роки тому

      @@FarahHawa Take your time to make a great Content!! Faraah

  • @Joyucomedy
    @Joyucomedy 4 роки тому

    Make more video in week

  • @cyberpirate007
    @cyberpirate007 4 роки тому

    Sweeeet

  • @mikem4052
    @mikem4052 4 роки тому

    Thank you Farah for your videos. Watching this video made me $750 (P2) from a public bug bounty program. Do you accept donations?

    • @FarahHawa
      @FarahHawa  4 роки тому

      So happy to hear this... congratulations!! 🥳 Which program was it?
      And no, I don’t have anything set up for donations right now but I really appreciate the thought :)

  • @anshxoxi8824
    @anshxoxi8824 4 роки тому

    Hi

  • @devoidgaming2870
    @devoidgaming2870 4 роки тому

    MA'AM I wanted some tips on starting a career.. So i contacted you in Instagram and Twitter. plzz ma'am reply me

  • @hakikihacioglu
    @hakikihacioglu 4 роки тому

    Why is the link to a non-existing.css file returns the html content? Does it ever happen? What is the root cause?

    • @FarahHawa
      @FarahHawa  4 роки тому

      It’s a quirk that exists in PHP among other languages. You can try it yourself by setting up a basic website in PHP!

  • @snehajain2390
    @snehajain2390 4 роки тому

    Yo

  • @komradz5577
    @komradz5577 4 роки тому

    ok again, great content but if you keep putting this Peppa pig music i will not watch ur videos. please dont put music in your videos!

    • @FarahHawa
      @FarahHawa  4 роки тому +1

      Peppa pig 😂🤣🤣🤣

    • @FarahHawa
      @FarahHawa  4 роки тому +1

      Ok I’ll try

    • @FarahHawa
      @FarahHawa  4 роки тому +1

      Pls don’t stop watching 🙏🏻😄

    • @komradz5577
      @komradz5577 4 роки тому

      @@FarahHawa i have kids and all day i hear music like this on tv hehe no offense but i really cant hear you when you speak and im very interested to see what i missed and what i dont know. Thanks again!

  • @cyberguy1111
    @cyberguy1111 2 роки тому

    Can i try this on hackerone and other platforms ???