Path Traversal in Action! - Billu Walkthrough Ep1

Поділитися
Вставка
  • Опубліковано 11 січ 2025

КОМЕНТАРІ • 20

  • @BarbieBat
    @BarbieBat Рік тому +1

    The best🎉

  • @MrBlackhats
    @MrBlackhats Рік тому +2

    what if we use the file we obtain from path travesal

  • @BarbieBat
    @BarbieBat Рік тому +2

    Can you please make a video about DOS attack and how can we benefit from it

    • @BarbieBat
      @BarbieBat Рік тому +2

      If it’s beneficial of course

    • @thehackerish
      @thehackerish  Рік тому +1

      @@BarbieBat I have never tried it, and it would be so hard to pull off without taking down unauthorized assets if it's network-based. But if an app is vulnerable, say does not have rate limiting and runs on limited resources, yes maybe a bruteforce login or heavy file upload might do the trick

  • @DaazerTV
    @DaazerTV Рік тому +1

    Great content

  • @HairEEck
    @HairEEck Рік тому

    How did you know you had to use a put request through curl?
    I'm curious where you learned that

    • @thehackerish
      @thehackerish  Рік тому

      I learned linux commands in school and online, but that’s just a simple curl command

  • @Tchatarero36
    @Tchatarero36 Рік тому

    Thank you so much Boss

  • @krnpt0s
    @krnpt0s Рік тому

    can you plz make videos about Account hijacking using dirty dancing in sign-in OAuth-flows adapted top us simple mortals

  • @asaad0x
    @asaad0x Рік тому

    could we use lfi to access db files on /var/www/ ?

    • @thehackerish
      @thehackerish  Рік тому

      hmmm...that might work to get cleartext password for the phpmyadmin?

    • @asaad0x
      @asaad0x Рік тому

      ​@@thehackerish yeah maybe, Or even check the code if it's vulnerable to sql already or not?
      OR even check where our uploaded file gets uploaded by lfi and fuzzing then we will be able to upload a shell?

    • @thehackerish
      @thehackerish  Рік тому

      @@asaad0x great ideas, I guess reading the code will be the best approach to decide if it's vulnerable or not.

    • @asaad0x
      @asaad0x Рік тому +1

      Great! Can't wait for your next video❤ and as always Great content and keep pushing 💖

  • @bachelor__
    @bachelor__ Рік тому

    Need Privilege escalation playlist 😂❤ THANK YOU ❤

    • @thehackerish
      @thehackerish  Рік тому +1

      I think I might group all privesc videos in one playlist

    • @bachelor__
      @bachelor__ Рік тому

      @@thehackerish good idea

  • @Kami-hd5sh
    @Kami-hd5sh Рік тому

    ❤❤❤❤😂🎉