Discover hidden assets using Host Header Injection

Поділитися
Вставка
  • Опубліковано 18 лис 2024

КОМЕНТАРІ • 36

  • @bjvercelli
    @bjvercelli 3 роки тому +4

    Your channel is awesome bro. Congrats

  • @ashiqurrahman275
    @ashiqurrahman275 3 роки тому +4

    Keep sharing your knowledge

  • @bhavyseth5949
    @bhavyseth5949 3 роки тому +4

    happy new year. its really nice video. thanks for sharing

    • @thehackerish
      @thehackerish  3 роки тому +1

      Thanks for your feedback! I really appreciate it :)

  • @sundar3357
    @sundar3357 3 роки тому +2

    Happy New year man. ☺️☺️

  • @CyberNinja-p1t
    @CyberNinja-p1t 10 місяців тому

    Thank you for very useful and understandable video

  • @bertrandfossung1216
    @bertrandfossung1216 3 роки тому +2

    Thanks for this video. I learnt a great deal. I need to practice more and hopefully I will have a better grip on it.

  • @thuglife896
    @thuglife896 3 роки тому +1

    Fantastic lesson

  • @bate5a710
    @bate5a710 3 роки тому +3

    Amazing Video, keep it up

  • @rahulhaxor2855
    @rahulhaxor2855 3 роки тому +1

    Thank you for this video... You are my favorite mentor 😍

  • @01zoso
    @01zoso 3 роки тому +2

    Great video, thanks for sharing

    • @thehackerish
      @thehackerish  3 роки тому

      Welcome! Thanks for your feedback :)

  • @davidwarokka882
    @davidwarokka882 3 роки тому

    what if my burp isn't a pro version ? can u tell us how to do it ?

    • @thehackerish
      @thehackerish  3 роки тому

      Buy a Pro version, the Community is also already great

    • @0xfsec
      @0xfsec 2 роки тому +2

      You can use interactsh from project discovery

  • @Cyber-jv8ve
    @Cyber-jv8ve 3 роки тому

    Hello sir, I found a method to bypass host header and shows my only 302 found and my host.Is there any impact of this?I mean is there any way to affect the victim?

    • @thehackerish
      @thehackerish  3 роки тому

      Nope, you can't control the header in other users' browsers

  • @blackychan8175
    @blackychan8175 2 роки тому

    Hi, thats was good video but how i get the internal ip from real life attack?

    • @thehackerish
      @thehackerish  2 роки тому

      Certificate transparency, or test addresses in known private ranges.

  • @chinonsoiwundu5782
    @chinonsoiwundu5782 3 роки тому

    How can I typically get internal IP in the wild? Kindly let me know!

    • @thehackerish
      @thehackerish  3 роки тому +1

      reconnaissance of subdomains, data leaks, or use a subset of private IP space.

    • @chinonsoiwundu5782
      @chinonsoiwundu5782 3 роки тому

      @@thehackerish can you elaborate more on the last option? #subset of private IP....maybe you should recommend for me

    • @chinonsoiwundu5782
      @chinonsoiwundu5782 3 роки тому

      Also about reconnaissance of subdomains, from the example you gave we bruteforce an IP range...how do I reproduce it when I've a list of subdomains

  • @Amazon-Insider
    @Amazon-Insider 3 роки тому

    When you don't have burp pro :/ . great work !

    • @0xfsec
      @0xfsec 2 роки тому

      You can use interactsh from project discovery

  • @GauravSharma-ks9eq
    @GauravSharma-ks9eq 3 роки тому +2

    🔥🔥🔥🔥

  • @elliot9066
    @elliot9066 3 роки тому

    love it