Cross Site Scripting (XSS) | Real World

Поділитися
Вставка
  • Опубліковано 4 січ 2025

КОМЕНТАРІ • 59

  • @88spaces
    @88spaces 28 днів тому +2

    Finally, an example of how it works instead of a high-level overview.

  • @WtfAnupam
    @WtfAnupam 2 роки тому +35

    omg, this was so amazing, there are thousands of videos on XSS but I hardly encountered anyone who explains topics in a such beautiful and simple way. Thank-you so much

    • @EdwinDeJesus-w6i
      @EdwinDeJesus-w6i Рік тому +1

      So he was logged in already on his account. Did he steal his own cookies

    • @jithu-ud1pd
      @jithu-ud1pd 3 місяці тому

      true

  • @ratmoneyg
    @ratmoneyg Рік тому +2

    You are the best teacher of this subject I have found on UA-cam. I graduated this year with a BAS in Cyber Security, but still feel like I’ve only scratched the surface regarding ethical hacking. I’m trying to become self-sufficient at bug bounty hunting, but I’m so bad at it. Your videos are really helping me though (more than other creators). You just explain it so well in shorter, more concise videos. Thanks so much, and keep it up!!!

  • @Deleted_User1090
    @Deleted_User1090 Рік тому

    I have looked for stuff like this forever and it never gives me a simple way or a way that makes sense THANK YOU.

  • @yarinp23
    @yarinp23 10 місяців тому

    Thank you so much! I was searching for this exact thing, using a real payload and explaining instead of simple alert that wont demonstrate harm to the server

  • @antraxgl3577
    @antraxgl3577 Рік тому

    Thank you for the example ! Im starting with pentesting and I decided to go with XSS, it's actually pretty fun and I learned a lot with your video.

  • @Waflon
    @Waflon 2 роки тому +4

    Thanks a lot for this kind of videos. Maybe you could do a OWASP 10 but in this format with 10 basic examples of the most common vul, also i'm from Chile and a new sub.

  • @sumedh1678
    @sumedh1678 2 роки тому +1

    This kind of real world explanation will actually help us to understand attack more. Thanks!!!

  • @himawanraharja
    @himawanraharja 2 місяці тому

    this is amazing, most videos usually just alert.
    btw is it possible to try do one on angular based web?

  • @Mr_tadoo
    @Mr_tadoo 2 роки тому

    Great as always !
    Idea : you can make more videos about server side bugs !

  • @gkdusa
    @gkdusa 3 місяці тому

    great video, you connected all the dots with a real world attack example ! Make a video for exploiting latest AI attacks and 3rd party component vulns

  • @brs2379
    @brs2379 2 роки тому +1

    Hey could you make a video on what your process is for bug bounties? What steps do you take when carrying out recon? What do you check for? And once you've completed recon, what do you do next?

  • @pedrobarthacking
    @pedrobarthacking Рік тому

    Amazing how you teach in a simple form to understood.
    Can you make a video, explain how to test xss when the webApp have some waf/filters ? 🙂

  • @theMintyRaven
    @theMintyRaven Рік тому

    great content, thank you.. I've not seen a real example of xss so far. could you make more contents like this? the real world/hands on hacking videos

  • @harshalmali856
    @harshalmali856 7 місяців тому

    amazing it caught my attention through your video to dig out more in this topic thanks bro

  • @adnanirfan6974
    @adnanirfan6974 Рік тому

    keren, terimakasih ilmunya.
    itulah mengapa penting sebuah website menggunakan SSL agar dapat terredirect ke https dan cookies nya aman

  • @Gr33n37
    @Gr33n37 Рік тому

    grate video, whats fun you get a hard thing and make is simple to understand, views i guess you should also buy this guy's course, i saw it has cool content in it😁

  • @vedant153
    @vedant153 2 місяці тому

    Short and simple, thanks!

  • @GINGER-200
    @GINGER-200 8 місяців тому +5

    very interesting ill be back when i understand what I just watched

    • @GINGER-200
      @GINGER-200 5 місяців тому +2

      im back i get it now

    • @h5e
      @h5e 15 днів тому

      @@GINGER-200 Can you explain?

  • @ss-rc1gy
    @ss-rc1gy 2 роки тому

    thanks for this amazing tutorial , n btw would you like to recommend any books for learning javascript ?

  • @phoenix3488
    @phoenix3488 2 роки тому +4

    That's cool 😲.. so this type of attack is called reflected xss yeah 🤔?

  • @dev.roysalazar
    @dev.roysalazar 6 місяців тому +1

    There is something I don't understand. The malicious input it's saved in the db table that contains your profile info and it is sent and executed in the browser when the web client request to the server for your profile information, so how can this work to steal cookies from other users, since the malicious script it's only sent by the server when you log into your own account?

    • @dev.roysalazar
      @dev.roysalazar 5 місяців тому +1

      To answer my own question: if your user profile can be seen by anyone, when they see your profile they get the malicious code

    • @LinhNguyen-nh8oq
      @LinhNguyen-nh8oq 3 місяці тому

      @@dev.roysalazarthanks, I have the same question

  • @pd1259
    @pd1259 4 місяці тому

    Why are we referencing the xss.js file in the form field? Isn't it possible to directly paste the code from this file into the field?

  • @amoh96
    @amoh96 Рік тому

    Hello plz answer me i have qst abt bug bounty
    i finish html im in Js (Function) When i finish Js can i start learning XSS & Learn Recon & how Web Work & burpsuit and try in labs than start in real world ? and in the same time keep learning about PHP & MYSQL and other OWASP 10 & methodology

  • @SleepyGameFacts
    @SleepyGameFacts 7 місяців тому

    Awesome explanation. Thank you

  • @goodluckmichael9523
    @goodluckmichael9523 2 роки тому

    Thank u sire. Sire can u do more real world vulnerabilities exploitation and how to escalate a certain vulnerability to another Eg xss to csfr

  • @suraj6177
    @suraj6177 Рік тому

    this is amazing work👏

  • @pnuema1618
    @pnuema1618 7 місяців тому

    Would this be considered a persistant XSS attack?

  • @jaredelfaz2558
    @jaredelfaz2558 2 роки тому

    and we want bug bounty explained videos. some blogs are high level we don't understand much of thier bug report write ups. please we want you to explain the easy way.

  • @jaredelfaz2558
    @jaredelfaz2558 2 роки тому

    thank you. we need more hard xss like openredirect to xss ... something hard

  • @kaos092
    @kaos092 Рік тому

    How are you grabbing an admin cookie? That the only part I don't understand. Why would you have access to any data from his session?

    • @Redhawk1961
      @Redhawk1961 4 місяці тому

      I know this is from a year ago, but this is stored xss, the malicious code is on the web server at this point. It's grabbing from a source (in this case, his kali linux server) and it's running anytime the profile created is checked. In this case, he was able to execute with , but there's more ways to execute js if the script function is blocked.

  • @athul070
    @athul070 Рік тому

    bro everyone is saying your videos are amazing
    good job
    I really want make some money through this field but I cant understand this ethical hacking where should I start

    • @ryan_phdsec
      @ryan_phdsec  Рік тому

      I answer the video coming tomorrow.

  • @cemkucuk6738
    @cemkucuk6738 Рік тому

    very very good tutorial! thnx

  • @powerdreng
    @powerdreng 9 місяців тому

    Well explained!

  • @drushkyy2017
    @drushkyy2017 Рік тому

    Do one for cross site request forgery, confused on that one please

  • @ankitahir291
    @ankitahir291 2 роки тому

    Hi, how to prevent xss on joomla CMS... In lang parameter can you share any solution?

  • @dhanitrianggara1772
    @dhanitrianggara1772 Рік тому

    this is amazing work

  • @siddhantsitapara2280
    @siddhantsitapara2280 2 роки тому

    Please Make video on cloud hacking like Synology Nas

  • @rizeenf2004
    @rizeenf2004 2 роки тому

    Cool. Keep it up

  • @castcrus
    @castcrus 11 місяців тому

    So, now the question is how to trick the admin in the real world to visit the link, like I have trouble logging in....

  • @martinlastname8548
    @martinlastname8548 3 місяці тому

    Great dude

  • @theomidtabei
    @theomidtabei 2 місяці тому

    💙💙💙

  • @iqyou-gw4kd
    @iqyou-gw4kd 2 роки тому

    شكرا لك اخي
    thank you sir

  • @GkjcAmpj-s2g
    @GkjcAmpj-s2g 4 місяці тому

    Wilson Timothy Jones Gary Clark Ruth

  • @MustafaGains
    @MustafaGains 9 місяців тому

    ❤❤

  • @rishabhrana3773
    @rishabhrana3773 2 роки тому

    Cobalt strike group

  • @Noctuu
    @Noctuu Рік тому

    didnt know gmk did xss

  • @ttrss
    @ttrss 2 роки тому

    Not exactly "real world" lets be honest, why is http-only set to false??

    • @ryan_phdsec
      @ryan_phdsec  2 роки тому

      Not sure. In react, I have seen applications have dangerouslySetInnerHTML when it couldn't be any more clear NOT to do this.

  • @esamlasheen453
    @esamlasheen453 Рік тому

    How i cans message you on dm ?