Finding Your First Bug: Reading JSON and XML for Information Disclosure

Поділитися
Вставка
  • Опубліковано 9 лис 2024

КОМЕНТАРІ • 48

  • @dhruvkandpal9909
    @dhruvkandpal9909 4 роки тому +2

    We need a video on XXE! Excellent explanation ma'am!

  • @nathangriffiths8809
    @nathangriffiths8809 4 роки тому +1

    Very informative video Katie, you answered a lot of the questions rattling around in my head. I hope you don't mind me saying, you are getting a real pro at these videos now. Congrats!

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      😊😊😊😊😊😊 thank you I’m really trying to improve everything I can

  • @cardzzz6585
    @cardzzz6585 4 роки тому +2

    Hey Katie! Thanks for this video! This is not a very popular topic so I really appreciate it!!!!

    • @InsiderPhD
      @InsiderPhD  4 роки тому

      You're welcome! I think a lot of people get intimidated by seeing JSON/XML and don't really know what to do, so I wanted to make this so people can really get into API hacking with me! Especially with future videos covering APIs!

    • @cardzzz6585
      @cardzzz6585 4 роки тому

      InsiderPhD totally!! I know with me, API’s are really intimidating and it’s definitely a weak point in my websec knowledge! So these videos are a great help

  • @1980cantrell
    @1980cantrell Рік тому

    Love your videos .... please do NOT stop..... ❤🎉🎉🎉🎉🎉🎉🎉🎉

  • @MrPaddy35
    @MrPaddy35 4 роки тому

    you are definitely right, if there is lods of json , i mostly thing its system things and just ignore it

  • @danielmaina4817
    @danielmaina4817 4 роки тому +3

    JSON... just what I needed

  • @DeLFeTube
    @DeLFeTube 2 роки тому

    Another great video! Yes - please create an XXE video :)

  • @Abhi-kp1fs
    @Abhi-kp1fs 4 роки тому +1

    Thanks a lot, this was really helpful!

  • @rianislam8155
    @rianislam8155 4 роки тому

    those are really helpful for the newcomers...thanks for this

  • @BlokeBritish
    @BlokeBritish 3 роки тому

    Crocodile Brackets !! haha subscribed

  • @davidt01
    @davidt01 4 роки тому +2

    Voting for XXE video.

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      Your vote has been noted!

    • @davidt01
      @davidt01 4 роки тому

      @@InsiderPhD Hey, I have a question. So what if I can change the content type to application/xml, and it accepts it, but when I try a blind xxe to get a url, the request originates from my ip address. I got it to send a request, but instead of server side, it's from my ip address. Does that mean it's not vulnerable? I've tried other payloads but they don't work.

  • @hackersguild8445
    @hackersguild8445 4 роки тому

    Thanks for sharing. That's really some cool information in the video.:)

  • @sankarghosh172
    @sankarghosh172 3 роки тому

    11:22 It is a graphql response with Json data ....

  • @helalsadat2077
    @helalsadat2077 4 місяці тому

    By Learning From You , You Will See One Day i Will Tag You in a Tweet , thank you very much i am learning alot about API hacking From your videos and Corey J Ball's Book , Lot Of Love and Respect , God Bless You

  • @0xx039
    @0xx039 4 роки тому

    is JSON really intimidating ? I love to see JSON responses

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      I did a poll and some of the discussions resolved around feeling intimidated by APIs and JSON, I wanted to get a video out there just in case esp as I’m doing a ton of videos on API hacking!

  • @mi2has
    @mi2has 4 роки тому

    Yes make video on XXE

  • @shrirangkahale
    @shrirangkahale 4 роки тому +1

    Note: GDPR applies to all programs that have European Users..

  • @holybugx
    @holybugx 4 роки тому

    Nice Video , Thanks

  • @davidg9469
    @davidg9469 4 роки тому

    Hi! I'd like your opinion on the platform INE Training, I don't know if it's worth it. Have you used it? Have you known anybody who has? They're quite expensive. Cheers mate!

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      I’m not familiar with it! The only platform I do have experience with is Pentesterlab and I do recommend that one with a *. I’ll ask around and see!

    • @davidg9469
      @davidg9469 4 роки тому

      @@InsiderPhD on the 20th of this month, they'll be having s seminar about their new Cyber Security course, I'll stay tuned. Thanks for your help.

  • @ismailramzan8927
    @ismailramzan8927 4 роки тому

    Thanks 😊

  • @imaadfaki5585
    @imaadfaki5585 4 роки тому

    Is that JSON from your university API from pervious videos?

    • @InsiderPhD
      @InsiderPhD  4 роки тому +2

      Yup! I worked hard on that damn thing so I’m going to expand it! It has a few new vulns for a blind XSS now :D!

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      Send me a @ on twitter for your prize :)

    • @imaadfaki5585
      @imaadfaki5585 4 роки тому

      @@InsiderPhD it's @yaboi_kryp2o

  • @ca7986
    @ca7986 4 роки тому

    ❤️

  • @faique2995
    @faique2995 4 роки тому

    😍😍😍

  • @zoroatokpas8761
    @zoroatokpas8761 4 роки тому

    There is always one question on my mind iwhat is the difference between API endpoint and directory same ? : dumb qustn i guess, I cannot think of differences :(

    • @InsiderPhD
      @InsiderPhD  4 роки тому +2

      No stupid questions here!
      An endpoint is like a URL that does something so UA-cam.com/watch?v=whatever resolves into a video but UA-cam.com/watch doesn’t do anything so that’s not an endpoint
      A directory actually stores stuff, so think the files for the videos UA-cam, but you usually need a direct link unless you can see into the folder.
      Hope that helps!

    • @zoroatokpas8761
      @zoroatokpas8761 4 роки тому

      @@InsiderPhD Haha thank you !! this cleared me !! your video motivates me to learn more and more :!!

  • @Star-mi5ix
    @Star-mi5ix 4 роки тому

    Do you need to go to college to do bug bounty

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      No, but I think university is useful for other reasons, to meet people, be exposed to lots of different careers and to broaden your horizons!

    • @Star-mi5ix
      @Star-mi5ix 4 роки тому

      InsiderPhD thank you I’m doing a course & I was worried if I need to go to school too & I wasted my time

  • @shrirangkahale
    @shrirangkahale 4 роки тому

    3 rd!!

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      You'll get first soon ;)

  • @gopalethical
    @gopalethical 3 роки тому

    Nice voice

  • @himalrawal7511
    @himalrawal7511 4 роки тому

    How to see json data in real world application

    • @InsiderPhD
      @InsiderPhD  4 роки тому

      You see it a lot in mobile apps, but keep an eye out for app that automatically refresh like yahoo mail or apps with a lot of client activity, APIs are great places to find JSON

    • @SyedImran-qf1eh
      @SyedImran-qf1eh Рік тому

      Hello Mam,
      I have seen your videos but I don't have laptop how can I find through mobile phone.
      Can you please help me.

  • @ViralComparison
    @ViralComparison 2 роки тому

    Thanks😄