change the content of any website! HTTP Parameter Pollution Explained

Поділитися
Вставка
  • Опубліковано 25 сер 2024
  • // Membership //
    Want to learn all about cyber-security and become an ethical hacker? Join this channel now to gain access into exclusive ethical hacking videos by clicking this link: / @loiliangyang
    // Courses //
    Full Ethical Hacking Course: www.udemy.com/...
    Full Web Ethical Hacking Course: www.udemy.com/...
    Full Mobile Hacking Course: www.udemy.com/...
    // Books //
    Kali Linux Hacking: amzn.to/3IUXaJv
    Linux Basics for Hackers: amzn.to/3EzRPV6
    The Ultimate Kali Linux Book: amzn.to/3m7cutD
    // Social Links //
    Website: www.loiliangya...
    Facebook: / loiliangyang
    Instagram: / loiliangyang
    LinkedIn: / loiliangyang
    // Disclaimer //
    Hacking without permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing so that we can protect ourselves against the real hackers.

КОМЕНТАРІ • 154

  • @JohnWalz97
    @JohnWalz97 3 роки тому +22

    And this is why you validate every parameter and all parts of app state both on the frontend and backend. Also it's best to obfuscate sensitive parameters. And finally, please stop using auto-incrementing IDs 🙄

    • @sazob
      @sazob 22 дні тому

      why should I stop using auto-incrementing IDs?

  • @LoiLiangYang
    @LoiLiangYang  3 роки тому +28

    What's your favourite security tool?

    • @arunawasthi9873
      @arunawasthi9873 3 роки тому +1

      Can we upload a shell from this method??

    • @haShira_222
      @haShira_222 3 роки тому +2

      Metasploit

    • @isurusandakelum1539
      @isurusandakelum1539 3 роки тому +4

      Burpsuit.
      &&
      I think this is a great way to deal with scammers, phishing web sites. Can show us how to do it please, Mr. Loi Liang Yang,......... plss

    • @yangdave611
      @yangdave611 3 роки тому +2

      Loi Liang Yang
      's youtube channel.

    • @anonymoushacker2860
      @anonymoushacker2860 3 роки тому +1

      Nmap,burpsute

  • @itskeith6542
    @itskeith6542 3 роки тому +50

    10 year old me using inspect tool: hahaha im hacking this website :D

    • @JACK-xv4sg
      @JACK-xv4sg 3 роки тому

      true my friend have do that before we play dino game and he say im hacking because i see 10 dinosaur

    • @Armv-8a
      @Armv-8a 3 роки тому

      Me who is trying to glitch Roblox with a Space Username

    • @eliseurey2220
      @eliseurey2220 2 роки тому +1

      Yo same, I troll my teacher because I know HTML I put a realistic 💩 on the screen and once even when I reloaded It didn’t work, I got out of doing the project
      Me: I am a wise 11y old hacker

    • @teoncool5907
      @teoncool5907 2 роки тому

      @@eliseurey2220 ?

    • @mikatori1207
      @mikatori1207 4 місяці тому

      so real

  • @Nobi11
    @Nobi11 3 роки тому +16

    Love from India🇮🇳

  • @hackersdom
    @hackersdom 3 роки тому +8

    nmap , sql map , burpt suit , metasploit , uhh there are so many tools and script I like ...

  • @reijin999
    @reijin999 2 роки тому +5

    Great video. When I first got into web hacking I realized you could Inspect Element and change the value of elements and change countries and dates to arbitrary data. Didn't know this had a name and could be taken to the next level with burp.

  • @rodricbr
    @rodricbr 3 роки тому +7

    1:06 That threat scares the f* out of script kiddies

    • @reijin999
      @reijin999 2 роки тому +1

      he can get my IP address? 😳

    • @rodricbr
      @rodricbr 2 роки тому

      @@reijin999 yes, *ip addr show*
      you're hacked

  • @sdasdsadsa5444
    @sdasdsadsa5444 3 роки тому +2

    the best way is post the backdoor then gain access to the web server then change the content on there using nano editor or just install nano on the server.

    • @galvesda
      @galvesda Рік тому +1

      Hi! do you know how to do that?

  • @alexjr977
    @alexjr977 3 роки тому +4

    My favorite teacher
    Thank you :)

  • @IamMidoZ
    @IamMidoZ 3 роки тому +4

    The same thing that PgTalal used.......

  • @crazymemes4080
    @crazymemes4080 3 роки тому +3

    Heheh😂 i liked that warning ⚠️ . I will catch you GAME OVER 😂😂😂

  • @rubbonn
    @rubbonn 3 роки тому +2

    Was it really necessary to change the request from GET to POST? It seems the form is using get parameters.

  • @NotTheRealTar
    @NotTheRealTar 3 роки тому +3

    You are underrated ..

  • @ktnD612
    @ktnD612 3 роки тому +6

    That part where Loi asked viewers not to try hacking his site because he’d find them was gold 😂

  • @rom_4938
    @rom_4938 3 роки тому +3

    Thanks, thanks, and again, for all the content you teach us

  • @Ankitkumar-kk5rm
    @Ankitkumar-kk5rm 2 роки тому +1

    are changes done on the website or changes are just done on offline web page of website?

  • @asmalorgarithm6889
    @asmalorgarithm6889 3 роки тому +1

    man i am learning a lot from youi, KEEP IT UP

  • @isurusandakelum1539
    @isurusandakelum1539 3 роки тому

    I think this is a great way to deal with scammers, phishing web sites. Can show us how to do it please, Mr. Loi Liang Yang

  • @JVMochi
    @JVMochi 2 роки тому +1

    How do I add burps to foxy?

  • @sashadowgames2049
    @sashadowgames2049 3 роки тому +2

    I have a question: Are your setting on burp suite foxy proxy and internet adjustments/settings neutral? I mean have you touched anything so you burp suite can intercept websites alright? Im askinng because my intercepting isnt working although foxy proxy and burp suite are synchronised and set well...

  • @Leo-x7t9o
    @Leo-x7t9o 3 роки тому

    I am your big fan 🤠,
    From Bangladesh.....

  • @TheUniversalRepublic
    @TheUniversalRepublic Рік тому +1

    Totally not going to use this on someone else’s site 👀

  • @mohamedfahim4583
    @mohamedfahim4583 27 днів тому

    i was tried to change get method into post
    cant do.tell me how to do

  • @egoisticabhigyan
    @egoisticabhigyan 3 місяці тому

    Thanks From India

  • @its_code
    @its_code 3 роки тому

    Very helpful for me.
    Love 💕 from Pakistan.

  • @thwahirmahammed4334
    @thwahirmahammed4334 3 роки тому

    👌🏼👌🏼👌🏼Explained so well that i understood 👌🏼👌🏼👌🏼
    - ("hello world")

  • @JohnDoe-of5ig
    @JohnDoe-of5ig 3 роки тому +2

    Well so im quite new to this and just trying to learn. So do you have a template for your website or something that you could release? ive been spending some time trying to code my own website so i could run these tests but it will take a while especially as im learning html from the basics to make this

    • @JohnDoe-of5ig
      @JohnDoe-of5ig 3 роки тому

      @Bryson Allen yeah i already found the brick thing that i think he might have had? idk but its good so im gonna use it

  • @Mrjtk
    @Mrjtk 3 роки тому

    Love you our teacher... 😘

  • @user-tk2ii7hx1w
    @user-tk2ii7hx1w 5 місяців тому

    OK. NOW SUCH A EASY WEBSITE IS HARD TO FIND

  • @cybershadowtech
    @cybershadowtech 3 роки тому

    We can use this to get the database of any website sign up page by changing it to GET?

  • @MicroscopyMan
    @MicroscopyMan Місяць тому

    My favorite tool is LoiLiangYang`s UA-cam channel.

  • @alexvandermeer1380
    @alexvandermeer1380 3 роки тому

    Make more video,s like this about burp suite

  • @smileaa3821
    @smileaa3821 2 роки тому

    Sir I want to change content or values ,prices in any type of website .Of others web database .could you tell me some solutions or to performe this suggest any softwares.

  • @Amar-lv1yw
    @Amar-lv1yw 3 роки тому +2

    Hey, good video! I wanted to ask if FoxyProxy is a Linux only thing or if it exists for Windows too

    • @rajanparmar7903
      @rajanparmar7903 3 роки тому

      It is a Firefox plug in, u can download on os.

    • @Amar-lv1yw
      @Amar-lv1yw 3 роки тому

      @@rajanparmar7903 oh thank you

  • @rajudeen846
    @rajudeen846 Рік тому

    It is showing only on my pc?

  • @tech4590
    @tech4590 3 роки тому

    Helo sir make tutorials on find logs and track the ip address...

  • @prantarkhisa7319
    @prantarkhisa7319 2 роки тому

    I am trying but nothing changing .can you help me?

  • @ram-tube
    @ram-tube 3 роки тому +1

    It's very useful

  • @lakshityadav8481
    @lakshityadav8481 2 роки тому

    Sir how you switch to burpsuit plz tell in a short 🙏🙏🙏

  • @ALANSAIKOT
    @ALANSAIKOT Рік тому

    sir im from bangla desh plz help me i yur help sir can you chang bord rejult

  • @jacksonjoekafu775
    @jacksonjoekafu775 3 роки тому

    what vpn can you use

  • @suryat4087
    @suryat4087 2 роки тому

    How to prevent this type attack

  • @rodricbr
    @rodricbr 3 роки тому

    Can you do more content with mutillidae 2?

  • @aafiyamemon9535
    @aafiyamemon9535 3 роки тому

    Can we connect to our device ip instead of ip shown by shodan using ghost framework
    Note: i have android debugging option switched on in my android device
    If not then why?🤔
    If yes then how ?
    Plz can u answer me

  • @OSagnikSen
    @OSagnikSen 3 роки тому +1

    hi

  • @pawansharma-mf3xg
    @pawansharma-mf3xg 3 роки тому

    Really helpful🔥

  • @mohamedhossam9267
    @mohamedhossam9267 3 роки тому

    bro i love ur Videos

  • @nirvaangoel8172
    @nirvaangoel8172 Рік тому

    Does this change it for the whole web to see. If I change a word on the website on my laptop, will it change on my dad's laptop?

  • @SecurityTalent
    @SecurityTalent 3 роки тому

    Thanks

  • @sanskar6323
    @sanskar6323 3 роки тому +1

    Love you ❤️❤️

  • @hqhshehwhhwh4181
    @hqhshehwhhwh4181 Рік тому +1

    Your op adres is on the internet so it does not matter

  • @DeepApnea
    @DeepApnea 3 роки тому

    😂😂😂 This guy says "dont try to hack me" 🤣🤣🤣🤣

  • @0xddcce1
    @0xddcce1 Рік тому +1

    i tried in roblox and it is quite fun

  • @abdoukadi9757
    @abdoukadi9757 3 роки тому

    Hi let me know how I can get access to Wi-Fi routers Huawei please, tell me how to hack Huawei routers

  • @manishraghavendra9553
    @manishraghavendra9553 3 роки тому

    Don't try to hack me that's game over 😂😂

  • @snipergamernz4383
    @snipergamernz4383 3 роки тому

    Thanks sir

  • @NotRyan.
    @NotRyan. 3 роки тому

    What was the tool?

  • @neirajthapamagar3673
    @neirajthapamagar3673 3 роки тому

    Fav tool:Burpsuite

  • @allinone-Jschy
    @allinone-Jschy Рік тому

    I want to permanently webpage text then anyone visit the webpage the he show this text.. It's possible?

  • @santhosh0532
    @santhosh0532 3 роки тому

    Please give captions

  • @pro-dizkid4572
    @pro-dizkid4572 3 роки тому

    Tool use for the tutorial

  • @marcw.5492
    @marcw.5492 11 місяців тому

    "game over"

  • @ap7075
    @ap7075 3 роки тому

    sir plz.. share free source of learning hacking

    • @averymila5357
      @averymila5357 3 роки тому

      I recommend you message Brave Franklin on Facebook, he does all this also he just recovered my account within an hour. Woo!

  • @tojogamer1733
    @tojogamer1733 3 роки тому

    So POST means putting data into the site? come on man...

  • @none5349
    @none5349 3 роки тому

    Sir, is the hacker can still hack my router if i left it alone?

    • @NotRyan.
      @NotRyan. 3 роки тому

      Yes if the hacker has your ip address.

    • @none5349
      @none5349 3 роки тому

      @@NotRyan. ouch, what can I do to stop him?

    • @NotRyan.
      @NotRyan. 3 роки тому

      Just don't do weird stuff on the internet and clicking on untrusted links. And if you wish to do so use good vpn.

    • @none5349
      @none5349 3 роки тому

      @@NotRyan. copy.

    • @NotLRK
      @NotLRK 3 роки тому

      @@none5349 actually you can change your ip but its to hard to explain, just search on UA-cam

  • @AA-pg9yv
    @AA-pg9yv 3 роки тому

    nice

  • @Hixe12
    @Hixe12 3 роки тому

    seems cool

  • @rumixmedia7793
    @rumixmedia7793 3 роки тому

    Nmap and Burpsuit

  • @hementsingh3901
    @hementsingh3901 3 роки тому

    hey , u r grt

  • @bossbaby4638
    @bossbaby4638 3 роки тому +1

    1 st comment before refresh

  • @smileaa3821
    @smileaa3821 2 роки тому

    Hi

  • @houssxm7016
    @houssxm7016 3 роки тому

    hey man please please i really need your help someone is hacking me always i formated my pc and still managed to hack me again and used my accounts for abusing people and he changed my steam account email and epic games please can you help meee!!

    • @houssxm7016
      @houssxm7016 3 роки тому

      @Richard Blangiforti I changed my Gmail account yesterday and he still managed to access the account but I finally deleted all the viruses from my pc and maybe just maybe I'm safe right now

    • @Armv-8a
      @Armv-8a 3 роки тому

      @@houssxm7016 it's an exploit attack Change Ur router IP real quick to a other IP

    • @houssxm7016
      @houssxm7016 3 роки тому

      I formated my pc 5 times and got rid of that thing thanks tho✨

    • @Armv-8a
      @Armv-8a 3 роки тому

      @@houssxm7016 now the hacker will hard time hacking ur IP

    • @Armv-8a
      @Armv-8a 3 роки тому

      @@houssxm7016 i had trojan my PC dint go Dead

  • @barathsrinivasr.b6184
    @barathsrinivasr.b6184 3 роки тому

    Burp Suite

  • @Nobi11
    @Nobi11 3 роки тому +1

    1st viewer

  • @sreerajr192
    @sreerajr192 3 роки тому

    🔥🔥

  • @Yubbygucci
    @Yubbygucci 3 роки тому

    First comment 🙌🏽🙌🏽🙌🏽

  • @reddyharikrishna7635
    @reddyharikrishna7635 3 роки тому

    Plz help game hecking

    • @averymila5357
      @averymila5357 3 роки тому

      I recommend you messaging brave Franklin on Facebook! I'm also surprised what he can do.

  • @Mel.Espanol
    @Mel.Espanol 3 роки тому

    Oh god my website is doomed

  • @H.919.h
    @H.919.h 2 місяці тому

    ممكن المترجم العربية 💔

  • @pintukumar-vo3yd
    @pintukumar-vo3yd 3 роки тому

    Can we inject contain in BBC website. If yes . Then please make video

  • @arijitsengupta7916
    @arijitsengupta7916 3 роки тому

    GOD

  • @kingreaper5142
    @kingreaper5142 11 місяців тому

    meh

  • @d0xing13
    @d0xing13 3 роки тому

    First and last viewer 😂😂

  • @caxmu1265
    @caxmu1265 3 роки тому

    net.portswigger.devtools.client.aj
    ?

  • @rakno12
    @rakno12 3 роки тому

    1st

  • @it_rakib_bd3053
    @it_rakib_bd3053 3 роки тому

    fast Views

  • @naevaweb
    @naevaweb 3 роки тому

    $choice = intval($_POST['choice']) :)

  • @IamMidoZ
    @IamMidoZ 3 роки тому

    Can I add for my self robux

    • @user-bd9bx8th2x
      @user-bd9bx8th2x 3 роки тому +1

      yes

    • @IamMidoZ
      @IamMidoZ 3 роки тому +1

      @@user-bd9bx8th2x How pls tell me

    • @Armv-8a
      @Armv-8a 3 роки тому

      @@IamMidoZ or put a space in Ur name so Ur unban in every game Bye bye Mods now I can exploit every Game :D

  • @hagarstwins5035
    @hagarstwins5035 Рік тому

    I hope you can answer my comment: I want text you private 4:45

  • @sanskar6323
    @sanskar6323 3 роки тому

    🔥🔥

  • @OSagnikSen
    @OSagnikSen 3 роки тому

    hi