Cross-Site Scripting (XSS) Explained And Demonstrated By A Pro Hacker!

Поділитися
Вставка
  • Опубліковано 18 лис 2024
  • // Membership //
    Want to learn all about cyber-security and become an ethical hacker? Join this channel now to gain access into exclusive ethical hacking videos by clicking this link: / @loiliangyang
    // Courses //
    Full Ethical Hacking Course: www.udemy.com/...
    Full Web Ethical Hacking Course: www.udemy.com/...
    Full Mobile Hacking Course: www.udemy.com/...
    // Books //
    Kali Linux Hacking: amzn.to/3IUXaJv
    Linux Basics for Hackers: amzn.to/3EzRPV6
    The Ultimate Kali Linux Book: amzn.to/3m7cutD
    // Social Links //
    Website: www.loiliangya...
    Facebook: / loiliangyang
    Instagram: / loiliangyang
    LinkedIn: / loiliangyang
    // Disclaimer //
    Hacking without permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing so that we can protect ourselves against the real hackers.

КОМЕНТАРІ • 592

  • @bachtiarmuhammad8716
    @bachtiarmuhammad8716 3 роки тому +372

    "i hope you learn something valuable...". This is absolutely valuable,
    I have been trying to find how dangerous XSS is, but never get satisfied answer except this one. Thanks loi!

    • @JL-ud6xx
      @JL-ud6xx 3 роки тому +10

      practical example, instead of theoretical which we see many site...

    • @digges90
      @digges90 3 роки тому

      Damn, this is gold

    • @oluwaseunmicheal1571
      @oluwaseunmicheal1571 3 роки тому

      Please can I have your telegram username I need to speak to you please if I may

    • @bachtiarmuhammad8716
      @bachtiarmuhammad8716 3 роки тому

      ​@@oluwaseunmicheal1571 speaking about what bro ? :v

    • @Richard-ji4kc
      @Richard-ji4kc Рік тому

      WEll i see it now but i just got this computer and i hate that its been hacked i did not know cause all the redirects etc. and identity theft i keep seeing fimiliars names as well including goat

  • @clem4224
    @clem4224 3 роки тому +71

    Dude you deserve way more views. Straight to the essential, clear, understandable. You won a new follower !

  • @Wastelander1972
    @Wastelander1972 2 роки тому +26

    Dude, I’ve been studying cyber for over two years. This is amazing. The first time I can actually see this in action. Thank you!

  • @ajanitau3405
    @ajanitau3405 2 роки тому +21

    I'm brand new to IT and was reading about open web app projects and came across the word Cross Site Scripting. Your explanation and demonstration was so clear, concise and yeah, scary! Thank you. I'll be studying your content for sure!

  • @SHAMulA147
    @SHAMulA147 Рік тому +6

    I've tried many times to understand what is really happening with XSS and this was the best way it has ever been explained to me

  • @denisivanov4888
    @denisivanov4888 3 роки тому +157

    This channel is gold. All I can say.

  • @philk.2208
    @philk.2208 3 роки тому +30

    Best demonstration of XSS that I have ever seen - thank you

  • @saikrishnavinjamuri4058
    @saikrishnavinjamuri4058 3 роки тому +1

    This is awesome... If someone is in hurry of preparing for the interview.. get this..

  • @Gupatik
    @Gupatik 3 роки тому +6

    thank you man, now I can start my career with you here in UA-cam even before I go to university

  • @swipe87
    @swipe87 3 роки тому +8

    You're a legend. Straight to the point and you spoke quickly with no filler.

  • @tomislavkukic1395
    @tomislavkukic1395 3 роки тому +10

    Thank you so much. I'm a web developer and this info is a gold. You explained this in such way that anybody can understand the great risk. This is scary how easy it is to hack the site if it is not protected against these attacks.

    • @oldnews4160
      @oldnews4160 2 роки тому

      How difficult is it to disable/prevent xss?

    • @WebieTM
      @WebieTM Рік тому

      @@oldnews4160 I think quite easy for developers. Just don't use innerHTML for user content, just innerText.
      As soon as you as a user realise a website has this vulnerability, you can either check by inspecting or contact the website owners.

    • @tealic367
      @tealic367 3 місяці тому

      @@oldnews4160 im a bit late, but to prevent xss, a little security can go a long way. Obviously there are a lot of advanced security techniques, but simple things like input restriction (like preventing the input of '') or output encoding (where things like '

  • @davidrocky
    @davidrocky Рік тому +1

    Wow, I knew a little about XSS but I didn't had the creativity to think that this kind could be made with this technique! Thank you so much for the presentation!

  • @yfz9684
    @yfz9684 3 роки тому +2

    just been assigned to a security project dealing with XSS, and your video is really helpful and valuablr . a big thumb up bro

  • @kevinportillo1971
    @kevinportillo1971 3 роки тому +2

    Now I know how those infected sites have been hijacked before to host a phishing site, great demo!

  • @41_a_nihalpathan78
    @41_a_nihalpathan78 Рік тому +2

    Man this was awesome 🤩 being a CEH guy I was still not able to understand how to perform XSS in proper way but this one video cleared my all concept ❤ u deserve millions of likes and views

  • @icaruz9094
    @icaruz9094 2 роки тому

    FIRST TIME I WATCHED THIS I WAS NO IDEA WHAT I'M WATCHING I DON'T UNDERSTAND ANYTHING BUT NOW FOR MONTHS STUDYING JAVASCRIPT AND DOM MANIPULATION I CAN NOW EASILY UNDERSTAND EVERYTHING, THE MORE I DIVE INTO TECH THE MORE MY PERSPECTIVE CHANGES ABOUT INTERNET

  • @shireliyahu6801
    @shireliyahu6801 Рік тому +2

    Loi you are the best! I love that you acutally shows us how XSS works rather than just explain it in pretty words :) Thank you so much!

  • @rushabhshah9164
    @rushabhshah9164 2 роки тому +2

    Amazing video.
    Went through various articles and demos explaining XSS but this one is by far the best one

  • @ManishKumar-rz9ub
    @ManishKumar-rz9ub Рік тому +1

    I found great tutorial on XSS after several year, :) Thanks for sharing it so intuitively.

  • @jaegar1nine266
    @jaegar1nine266 Рік тому +2

    You got another subscriber. You explain and show the process so much better than Hack the Box. I’m currently slogging thru the Linux Fundamentals course and it is hard.

  • @brokenwindowpanes8220
    @brokenwindowpanes8220 3 роки тому +2

    This guy doesn't spend 30 minutes speaking bullshit and only 2 minutes showing the real thing. I'm a fan

  • @grimorisX
    @grimorisX 3 роки тому +11

    Wow, this is insane. Ngl I'm a little freaked out by this. Great information as always. Thanks 🤟👍

  • @andrewfarinola358
    @andrewfarinola358 11 місяців тому +1

    Extremely well done, found your video looking up what XXS was because i wanted to see how dangerous the CS2 exploit is. Thanks for the great info.

  • @ryanleong6266
    @ryanleong6266 2 роки тому +5

    Clear and concise explanation and demonstration. Couldn't ask for better.

  • @RidwanOseni
    @RidwanOseni Місяць тому

    I have never been more confident about my cyber security career after watching this channel. You’re a gem. Thank you.

  • @hairychewy28
    @hairychewy28 Рік тому +1

    This has been the best explanation of what a XSS is. Thank you!

  • @aragorn2753
    @aragorn2753 2 роки тому

    " i hope you learnt something valuable "
    Is that a question sir ..
    Your channel is a diamond thank you so much

  • @KeesFluitman
    @KeesFluitman Рік тому +1

    Nice job. Next question is, this seems like an easy task to fix. What else should one do to protect yourself and what is the current state of XSS protection and danger?

  • @kimdanielestoy3888
    @kimdanielestoy3888 Рік тому

    I am a career shifter and my current work is related to cybersecurity, and thank you for this

  • @purrkachuu
    @purrkachuu 2 роки тому +2

    instant subscribe worthy. clear explanation, clear voice, valuable content

  • @lurifos9576
    @lurifos9576 3 роки тому +8

    I know that XSS is dangerous, but I never realised it can be this dangerous. +1 sub.

  • @Gh0st_0723
    @Gh0st_0723 3 роки тому

    Ugh I hate all these spam hacker comments on every infosec video. Thank you for the content. Beautifully explained like always.

  • @chrisissun
    @chrisissun Рік тому

    thank you just ran into a NoScript detected a potential Cross-Site Scripting attack wow this is helpful

  • @alejandroharo0217
    @alejandroharo0217 7 місяців тому

    on the process of getting my CompTIA. I was a little confused on this topic but wow. It really is scary. thank you for the video!

  • @damilolaoluwole5640
    @damilolaoluwole5640 2 роки тому

    Thanks for the explanation. Now I can easily differentiate XSS attack from a Cors attack.

  • @secinject814
    @secinject814 Рік тому +2

    Wow you earned a sub and a ton of respect. You're fast, to the point, highly information-dense.. perfect level of difficulty for me. So happy the algorithm brought me here. Keep it up boss!

    • @c.w.bertrand4633
      @c.w.bertrand4633 Рік тому

      The guy is incredible. I really enjoyed it. And it's really scary at the same time

  • @abdulrahmanmsusa9225
    @abdulrahmanmsusa9225 3 роки тому +10

    Amazing content Mr.Yang. Highly resourceful 👍

  • @ramseykarr6870
    @ramseykarr6870 2 місяці тому

    clear, concise and to the point explanation. Just amazing!

  • @babayaga5225
    @babayaga5225 3 роки тому +3

    Perfect timing! I was actually testing it a few days ago!
    PS: I didn't expect your password to be 12345678 :P

  • @TWFSHOW
    @TWFSHOW 3 роки тому +1

    Game over..... Great info . Most useful channel 4 ethical hacking learning 👍👍👍👍👍

  • @joshuam2341
    @joshuam2341 3 роки тому +4

    Hi Loi! Great video! Could you please make a video about your desktop setup or what you look for in laptops that are tailored for penetration testing?

  • @yudilai5640
    @yudilai5640 Рік тому

    So I was thinking: if you are going to look side ways, maybe you don't need a head cam when we see the work on the screen. Thanks for the video, very informative

  • @DimitarKrumov
    @DimitarKrumov 3 роки тому +2

    This made my day! Thanks for the great explain the process and where to find them to test and prevent

  • @mattv2497
    @mattv2497 3 роки тому +6

    Terrific content! Learning so many new techniques.

  • @jacklee1612
    @jacklee1612 3 роки тому +3

    Excellent introduction on this topic ! Audio quality is great as well, keep it up :)

  • @peytpeyt9113
    @peytpeyt9113 3 роки тому +3

    Thank you, you teach very well even if i already know most of things thats you show, you make them more understandable.

  • @emdadulhossainakand48
    @emdadulhossainakand48 2 роки тому

    The best Chanel for learning ethical hacking

  • @cybermatters
    @cybermatters Рік тому

    Thank you so much for letting me know how dangerous stored xss is .

  • @nathantipton4294
    @nathantipton4294 6 місяців тому

    Thank you for the detailed explanation. Can someone answer the question; does this kind of ethical hacking of your own site or apps allow some better capabilities for development?
    I want to understand if this is helpful for developers to not get locked out or to better monitor traffic?

  • @shimtristan
    @shimtristan 3 роки тому +5

    Invaluable information. Many thanks Loi!

  • @lindanib541
    @lindanib541 3 роки тому +4

    Awesome video, as always. One suggestion though, could you post the links in the description? Thanks :)

  • @paulbaker8449
    @paulbaker8449 Рік тому +1

    What an awesome video! I’m glad I came across your videos, I have one real nooby question though…
    If this SQL stuff is so easy to put into websites, what do banks, shopping or government websites use to protect themselves from these attacks?

  • @worldtreeboy8712
    @worldtreeboy8712 2 роки тому

    Well explained. Just subscribed after watching your video for the first time.

  • @BiO-_-MeKaNiZeM
    @BiO-_-MeKaNiZeM 3 роки тому +1

    Instant sub after the 1st video, good job explaining and the demonstration helps so much 👍

  • @clock-ai
    @clock-ai 2 роки тому

    Your explanation is very clear and easy to understand

  • @synchronulleins
    @synchronulleins 3 роки тому

    I'm a very beginner, but I'm interested in cyber security.... And it's pretty scary to see how easy it is to get your informations...

  • @kevinc8955
    @kevinc8955 3 роки тому +1

    The problem is you can only realistically get better by practice and diverse practice against differing targets is likely against the law unless you have a job in pentesting.
    It’s all fun and games until the authorities knock on your door.

  • @mahmudabdi1363
    @mahmudabdi1363 3 роки тому +2

    Wow I love your episodes.......Guys let's get to 1million subscribers

  • @yuki_nakato
    @yuki_nakato 2 роки тому

    XSS = GAME OVER. Thank you for creating great content!

  • @dhanrajp6818
    @dhanrajp6818 3 роки тому +2

    Ty for the demo. However have a doubt. How does tool plant malicious js to another users browser. The demo showed is the js and user login is done in the same local machine. Can u make the server render the webpage with malicious js??

  • @nithin1979
    @nithin1979 9 місяців тому

    Good demonstration of XSS using a feedback form

  • @masterofnoob4621
    @masterofnoob4621 3 роки тому +2

    Please start ... complete hacking course 🙏❤

  • @ThomasVFree
    @ThomasVFree 2 роки тому

    What is the best spot on your channel for a beginner earning his SEC+?? I want to start practicing on my home network..

  • @emperorj4783
    @emperorj4783 3 роки тому

    The only channel I watch when learning hacking:)

  • @aakashjana6225
    @aakashjana6225 3 роки тому +2

    Nowadays all web frameworks come with really innovative input sanitization techniques which make XSS attacks absolutely useless. Any tricks to bypass these would be cool

    • @MsSoldadoRaso
      @MsSoldadoRaso 3 роки тому

      Yes, I love angular ❤️

    • @harshthechampful
      @harshthechampful 3 роки тому +1

      Does it depend on the way the component is scripted at all? Like the framework handles all the sanitization and there is no chance of XSS?

    • @aakashjana6225
      @aakashjana6225 3 роки тому +1

      @@harshthechampful problem is you have to have a good idea of what kind of framework the code is coz reactJS when deployed is still the old vanilla JS which makes it difficult sometimes to know if its react, angular , vue or something else. And also there is quite a bit of abundance of 3rd party libraries to bump up the sanitisation game note that the browser you use also prevents some mailicious features making XSS difficult and added to that SQL has come a far way now to the point you cant trick it all that easy.

  • @physics3641
    @physics3641 2 роки тому +2

    All of us know we don't learn hack to hack our own system😂😂😂

  • @orangefish0297
    @orangefish0297 11 місяців тому

    Learning about Cyber security after the CS2 XSS exploit that was reported yesterday
    I want to hear your opinion on that! It's actually making me really anxious

  • @我爱您中国
    @我爱您中国 3 роки тому

    The most dangerous ones are the ones who created these apps for hacking purposes but thanks for sharing this great video love it thumbs up for you!

  • @rahulrajendrasaw
    @rahulrajendrasaw 3 роки тому

    i always watch full ads video in your channel sir
    so that you will bring more videos for free to us without any cost
    thanks

  • @shamelessone1987
    @shamelessone1987 6 місяців тому

    I needed an example outside of the classroom's Vector Image with some script inside of it. I could see how thats easy to fall for

  • @deeepzzz
    @deeepzzz 3 роки тому

    Good video, with wonderful description.
    I have a doubt:
    If I am a hacker-programmer, why should I try to execute ... inside a text box? I can make use of the browser developer console, right?
    Another doubt:
    In the video, you are entering email and comment (as a user). The hacker is entering email & script-in-the-comment-box. How the hacker got the user's credentials (to enter script in the user's homepage)?
    OR you mean to say, the script provided through the comment box is set in the server code and will be available for all the users? (I am actually confused with XSS after user's login)

    • @rumfordc
      @rumfordc 3 роки тому

      you're not executing the script "inside a text box." rather, you are submitting a comment to the website servers. then, when anyone visits the website to view the comment, the HTML they receive contains your script which immediately executes it.

    • @tejaspachpile9269
      @tejaspachpile9269 2 роки тому

      Stored means basically going to the server directly and reflected is client side

  • @mawaddaturriza7158
    @mawaddaturriza7158 Рік тому

    im a frontend developer, looking for a video how dangerous xss is, because i know nothing at all about how it will impact our data. hope to see a video how to prevent it as a developer from you because i love to see how you explain informations

  • @PerryCS2
    @PerryCS2 3 роки тому

    You remind me of the guy from (youtube) PBS Space Time (but a non English version of him). :) Great tutorial. Always nice to see how these attacks are done so I can make my website and APPS more bullet proof. :)

  • @age7753
    @age7753 2 роки тому

    So I Have A Question
    You Type The Script to tht Web site does it affect other users or only you?
    And Thank You For The Video

  • @raihanzaki5
    @raihanzaki5 19 днів тому

    i suprised that subscribe button is highlighted when you mentioned it

  • @Cyb3rBuddy
    @Cyb3rBuddy 3 роки тому +2

    Hello sir Loi Liang Yang, I learnt something new today 😀😀
    Thank you ❤️❤️

  • @nine2mdnt
    @nine2mdnt 2 роки тому

    What a valuable resource, so clear and easy to understand, thanks

  • @veronicadiaz9454
    @veronicadiaz9454 Рік тому

    wow amazing video, Im studying cyber security and knowing this its very useful! I'm subscribing!

  • @thechaker886
    @thechaker886 3 роки тому

    in fact i've learned something valuable, Thank you from Algeria.

  • @justicer14
    @justicer14 Рік тому

    You seem experienced, could you bring down a website for me?

  • @edwinnikoi3844
    @edwinnikoi3844 3 роки тому +1

    Just subbed, great content. Clear and concise

  • @janina7110
    @janina7110 3 роки тому

    Dear Loi, just remember one thing, you are our hero....

  • @microondassemprato4879
    @microondassemprato4879 3 роки тому +1

    That's awesome, but what is the use of XSS reflected, has the same level of danger?

  • @b07x
    @b07x 3 роки тому +6

    alert("Eeeeeeeeeee");
    //UA-cam can't be hacked that easily

  • @edgargrajeda610
    @edgargrajeda610 Рік тому

    Thank you so much, you do a great job of explaining it this helps me with my college XSS lab.

  • @ByteShadow
    @ByteShadow 3 роки тому

    Any chance you have a Udemy or hacking course available?

  • @cicio7777
    @cicio7777 2 роки тому

    So inserting the comment just completely took over the XSS vulnerable web server in question?
    Loi, what exactly is happening on the web server that is enabling this?
    Doesn't it still require someone to click the vulnerable link in the comments?

  • @PerryCS2
    @PerryCS2 3 роки тому

    I use your site to help make my website and APPS in development more secure. Thx :)

  • @hsardrake5373
    @hsardrake5373 3 роки тому +1

    You can prevent that in PHP using the strip_tags() function passing the input data into the function

    • @bobbystotmisc
      @bobbystotmisc 3 роки тому

      Yeah the XSS he covers is rather basic. Its DOM and Mutation XSS that we seen in modern applications. Unless a site is made manually without a framework or by a fool who doesn't know what they're doing, these standard input injection attacks wont be found in enterprise applications.

    • @hsardrake5373
      @hsardrake5373 3 роки тому

      @@bobbystotmisc I agree, is better to use frameworks while developing big or enterprise applications

  • @apolitik
    @apolitik 3 роки тому

    Is there a video on how to take all the code of a site and make an identical for other project?

  • @andyfreeman2805
    @andyfreeman2805 3 роки тому

    I love your content, I am working in coal mine industry, I learned linux and got a RHCE certification in 2020, how should I get my foot into cybersecurity?

  • @bhavdeepsinghchavda7619
    @bhavdeepsinghchavda7619 2 роки тому

    Hey bud.. This is awesome, I am new bee with Kali Linux and offensive security world... though I have almost 13 years work experience as an Infra Architecture for Cisco UCS world, Just wanted to take my career towards Cyber Security, Could you please guide me.. Thank you!!

  • @amjidkhan6261
    @amjidkhan6261 3 роки тому

    Love the attitude of this guy. Don't waste time

  • @JamesBrown-rp5oq
    @JamesBrown-rp5oq 3 роки тому

    The video is very clear but my question is can you do this without beef? For example if you have access to a site can you write your own code to put in it, and also does it always change the url

  • @faizankhd
    @faizankhd 3 роки тому

    What is this software you are using to execute the command

  • @rubeushagrid4131
    @rubeushagrid4131 3 роки тому

    I just want to learn this because i want to make sure that my website is as secure as can be possible

  • @asthakhare9161
    @asthakhare9161 3 роки тому

    Mobile hacking lectures !! plzzz ! BTW Love your Videos :
    )

  • @missanonymous6413
    @missanonymous6413 3 роки тому

    Please which operating os are you using

  • @yaxis7267
    @yaxis7267 3 роки тому

    this is cool and all but it bothers me how late the webcam is with the audio 😅

  • @GameReality
    @GameReality 2 роки тому

    This is total fun and amusement 🙂 Love your music Peace and Love from Sweden