13 - CSP Bypass (low/med/high) - Damn Vulnerable Web Application (DVWA)

Поділитися
Вставка
  • Опубліковано 5 жов 2024

КОМЕНТАРІ • 11

  • @_CryptoCat
    @_CryptoCat  2 роки тому +6

    oh damn so many dislikes 🙈😂 i made this entire DVWA video series over a weekend with very little prep and before i learned how to make videos properly. apologies for any quality issues/mistakes, hopefully my newer videos are much better 🥰

    • @vacumecleaner
      @vacumecleaner 2 роки тому +5

      Dude don't apologize these are great

    • @_CryptoCat
      @_CryptoCat  2 роки тому +2

      @@vacumecleaner 🙏🥰

  • @rizwanhussain458
    @rizwanhussain458 2 роки тому +6

    Bro u doing a good work actually, there is no video till now for complete dvwa, Thanks a ton man!! Btw how was India?

    • @_CryptoCat
      @_CryptoCat  2 роки тому +1

      Thanks mate 🙏🥰 Been to India a couple of times, love it!! Can't wait to get back 🙂

  • @collabcomm9007
    @collabcomm9007 3 роки тому +1

    Question, why does putting code in the callback= work? Is it only JavaScript code that we can inject? What else can we do here? Can we make the page redirect?

    • @_CryptoCat
      @_CryptoCat  3 роки тому +1

      been a little while since i did this now but you should be able to use any JS code there, see some examples here which include page redirect: book.hacktricks.xyz/pentesting-web/content-security-policy-csp-bypass#third-party-endpoints-jsonp
      for a little more info about JSONP and security issues: vulncat.fortify.com/en/detail?id=desc.semantic.dotnet.javascript_hijacking_jsonp

    • @collabcomm9007
      @collabcomm9007 3 роки тому +1

      @@_CryptoCat Exactly what I was looking for, I should have known to check hacktricks! Thanks mate!

  • @nintendotyrelle
    @nintendotyrelle 2 роки тому +1

    Random, but how old are you? You sound very young but done an internship abroad in 2014 :O

    • @_CryptoCat
      @_CryptoCat  2 роки тому +1

      mmm yeh i get that a lot xD im 31 🧙‍♂ thanks for reminding me!!

  • @orxanovn5057
    @orxanovn5057 2 роки тому +1

    i am know what is self xss...
    but dont understand self xss ))))