Covering The Under Rated Vulnerabilities: CORS Misconfiguration #1

Поділитися
Вставка
  • Опубліковано 1 лют 2025

КОМЕНТАРІ • 21

  • @MianHizb
    @MianHizb 4 місяці тому +2

    4:10 there is no such thing as request 2 3, its not websockets its http stateless, preflight requets dont occur here, if you can correct that, it will be great, it only happens in non common http methods like delete still that is something else.
    Cheers

  • @bkg2190
    @bkg2190 2 місяці тому +1

    Nice explanation 👍

  • @jawathossainrian
    @jawathossainrian 4 місяці тому

    Really an Great Educational Material Openly Available

  • @AttackerShihab
    @AttackerShihab 4 місяці тому +4

    Hey make portswigger all labs complete video .

  • @ZaraRashidKhan
    @ZaraRashidKhan 4 місяці тому

    Thank you for sharing

  • @jawathossainrian
    @jawathossainrian 4 місяці тому

    Bro can u use UA-cam transcript to add subtitles to your video? Automated subtitle are really pain

  • @akhilreddy9753
    @akhilreddy9753 4 місяці тому +1

    What if it is in the forget password endpoint . I can send the request through cors .is it valid or informative

    • @BePracticalTech
      @BePracticalTech  4 місяці тому +1

      Informative. You need to find an endpoint that is handling something sensitive. For example: An endpoint that can fetch users, edit profile, delete user etc

  • @bugstester9919
    @bugstester9919 4 місяці тому

    which user's cookie is sent by poc.html code, even though there is session_id:admin was the cookie session of the user, which user is deleted by this code of poc

  • @kasihagustinus4922
    @kasihagustinus4922 Місяць тому

    Informative closed

  • @om3726
    @om3726 4 місяці тому

    Hi Bro/sis please make videos on High Severity bugs P1,P2,P3 Starting from easy to find & understand to complex

  • @nedurunaveen0417
    @nedurunaveen0417 4 місяці тому

    Thanks broo

  • @pawankandu914
    @pawankandu914 4 місяці тому

    sir can you please can you share your nu.of experience in bug bounty

    • @BePracticalTech
      @BePracticalTech  4 місяці тому

      @@pawankandu914 I started bug bounty in 2020

  • @Mr.3cho
    @Mr.3cho 4 місяці тому

    I want to be your student to learn bug bounty guruji😅

    • @BePracticalTech
      @BePracticalTech  4 місяці тому

      I am glad to hear this! We will be planning something soon for this one!

  • @SecureByBhavesh
    @SecureByBhavesh 4 місяці тому

    First !!!!!

  • @pratyushkashyyy
    @pratyushkashyyy 4 місяці тому

    Heyyy