Website Hacking Demos using Cross-Site Scripting (XSS) - it's just too easy!

Поділитися
Вставка
  • Опубліковано 1 чер 2024
  • It's just too easy to attack websites using Cross Site Scripting (XSS). The XSS Rat demonstrates XSS attacks. XSS Rat explains and demos cross-site scripting (xss) attacks.
    // MENU //
    00:00 ▶️ We are taking over the world!
    00:16 ▶️ Introducing//XSS Rat//Wesley
    01:28 ▶️ What is XSS/ Cross Site Scripting?
    02:59 ▶️ Types of XSS
    05:15 ▶️ Reflected XSS
    06:22 ▶️ Example of data sanitization
    07:35 ▶️ Circumventing filtering with the img tag
    11:01 ▶️ Sending a Reflected XSS Attack to Someone
    12:01 ▶️ Using HTML comments as an attack vector
    13:49 ▶️ Using single quotes to break out of the input tag
    15:14 ▶️ Don't use alert() to test for XSS
    17:33 ▶️ What you can do with Reflected XSS
    19:26 ▶️ Stored XSS
    20:31 ▶️ Using comments for XSS
    21:05 ▶️ Example #1 of Stored XSS on Twitter
    21:42 ▶️ Example #2 of Stored XSS
    22:12 -▶️ The answer to the ultimate question of life, the universe, and everything.
    22:56 ▶️ Stored vs Reflected XSS
    24:22 ▶️ AngularJS/Client Side Template Injection
    25:06 ▶️ Don't use JavaScript?
    26:09 ▶️ Where to learn more//XSS Survival Guide
    27:04 ▶️ DOM Based XSS
    29:36 ▶️ List of DOM sinks
    30:12 ▶️ jQuery DOM sinks
    32:15 ▶️ XSS Rat Live Training
    33:00 ▶️ Support XSS Rat//Wesley
    34:06 ▶️ Closing//Thanks, Wesley!
    // Demo Sites //
    hackxpert.com/labs
    hackxpert.com/ratsite
    // David's SOCIAL //
    Discord: / discord
    Twitter: / davidbombal
    Instagram: / davidbombal
    LinkedIn: / davidbombal
    Facebook: / davidbombal.co
    TikTok: / davidbombal
    UA-cam: / davidbombal
    // XSS Rat SOCIAL //
    Twitter: / thexssrat
    UA-cam: / thexssrat
    Website: thexssrat.podia.com/
    // XSS Rat's Udemy course //
    XSS Survival Guide: www.udemy.com/course/xss-surv...
    // XSS Rat's courses and bootcamps //
    thexssrat.podia.com/
    // MY STUFF //
    www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
    xss
    cross site scripting
    portswigger
    ajax
    jscript
    javascript
    xss attack
    xss video tutorial
    xss attack tutorial
    xss explained
    xss attack example
    xss bug bounty
    xss tutorial
    xss vulnerability
    xss vs csrf attack
    xss example
    xsser
    xsssa facebook
    xsssa
    kali linux
    penetration testing
    ethical hacking
    bug bounty
    cross site scripting
    cross-site scripting
    red teaming
    cyber security
    kali linux install
    kali linux 2022
    ethical hacker course
    ethical hacker
    javascript
    ajax
    jquery
    node js
    node js hacking
    portswigger
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    #xss #javascript #hacking
  • Наука та технологія

КОМЕНТАРІ • 224

  • @davidbombal
    @davidbombal  2 роки тому +22

    // MENU //
    00:00 ▶ We are taking over the world!
    00:16 ▶ Introducing//XSS Rat//Wesley
    01:28 ▶ What is XSS/ Cross Site Scripting?
    02:59 ▶ Types of XSS
    05:15 ▶ Reflected XSS
    06:22 ▶ Example of data sanitization
    07:35 ▶ Circumventing filtering with the img tag
    11:01 ▶ Sending a Reflected XSS Attack to Someone
    12:01 ▶ Using HTML comments as an attack vector
    13:49 ▶ Using single quotes to break out of the input tag
    15:14 ▶ Don't use alert() to test for XSS
    17:33 ▶ What you can do with Reflected XSS
    19:26 ▶ Stored XSS
    20:31 ▶ Using comments for XSS
    21:05 ▶ Example #1 of Stored XSS on Twitter
    21:42 ▶ Example #2 of Stored XSS
    22:12 -▶ The answer to the ultimate question of life, the universe, and everything.
    22:56 ▶ Stored vs Reflected XSS
    24:22 ▶ AngularJS/Client Side Template Injection
    25:06 ▶ Don't use JavaScript?
    26:09 ▶ Where to learn more//XSS Survival Guide
    27:04 ▶ DOM Based XSS
    29:36 ▶ List of DOM sinks
    30:12 ▶ jQuery DOM sinks
    32:15 ▶ XSS Rat Live Training
    33:00 ▶ Support XSS Rat//Wesley
    34:06 ▶ Closing//Thanks, Wesley!
    // Demo Sites //
    hackxpert.com/labs
    hackxpert.com/ratsite
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: twitter.com/davidbombal
    Instagram: instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    UA-cam: ua-cam.com/users/davidbombal
    // XSS Rat SOCIAL //
    Twitter: twitter.com/theXSSrat
    UA-cam: ua-cam.com/users/TheXSSrat
    Website: thexssrat.podia.com/
    // XSS Rat's Udemy course //
    XSS Survival Guide: www.udemy.com/course/xss-survival-guide/
    // XSS Rat's courses and bootcamps //
    thexssrat.podia.com/
    // MY STUFF //
    www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

  • @faran4536
    @faran4536 2 роки тому +48

    Wow David you're collaborating with awesome people ♥️♥️.. here you dropped this king 👑

  • @jpierce2l33t
    @jpierce2l33t 2 роки тому +8

    LOL David I just started following the XSS Rat not long ago! Either you're in my head, or I'm on the right track...'cause this just keeps happening! 🤣 Love that you're helping expose these gems of our community to the masses...great stuff man!

  • @juliusrowe9374
    @juliusrowe9374 2 роки тому +1

    Once again great vlog David! Your channel is so awesome, you always have a great wealth of knowledge from all the guest that appear on the channel. I'm very appreciative of learning new things every time I tune in.

  • @bertrandfossung1216
    @bertrandfossung1216 2 роки тому +3

    David you’re just the best. Keep pouring these contents . I’m really having fun .

  • @bloudengaming8736
    @bloudengaming8736 2 роки тому +49

    Your videos are also so informative and entertaining! Thanks David!

    • @davidbombal
      @davidbombal  2 роки тому +2

      Thank you! Glad you like them!

  • @aramv898
    @aramv898 2 роки тому +18

    As a developer this is pretty useful. Thanks for the great value David

  • @rajmaharjan9828
    @rajmaharjan9828 2 роки тому +2

    This channel is on fire! Loving these videos David!

  • @youssefbouchara1179
    @youssefbouchara1179 2 роки тому +20

    Best content creator in the field Cybersecurity by far, informative and entertaining!

  • @charlesmarseille123
    @charlesmarseille123 Рік тому +4

    He is ridiculously clear in his explanations. Beautiful.

  • @fredrickawinyo
    @fredrickawinyo 2 роки тому +3

    Damn!!! Loving these talks; learning so much and it's all thanks to you David, thanks 👍🏽

  • @DF-ss5ep
    @DF-ss5ep 2 роки тому

    Tutorials on the net about this stuff are so confusing. Sometimes they appear to contradict one another. It's no wonder they have mistakes. Good video

  • @Uranium-bh7kt
    @Uranium-bh7kt Рік тому

    Bro i learned so much from this guy, videos like this are terrific, please do as many as you can. Wish you the best!

  • @TheRich464
    @TheRich464 2 роки тому +7

    Amazing video, questions and demo very well done. I always find it amazing how you can look at one thing differently and your in. *looking at the wall with security guard checking ID’s. Wall is only 3 feet wide. Just walk around.
    I’m excited to see how I will look at my own code differently.
    Thanks again!

    • @davidbombal
      @davidbombal  2 роки тому +1

      Thank you! Glad it was helpful!

  • @sexyeur
    @sexyeur 2 роки тому +1

    WOW! Wesley is so awesome! Thank you so much, David Bombal!!! All love. Always.

  • @user-on6zh1zx5y
    @user-on6zh1zx5y 2 місяці тому

    graet video, your guest seems to be a nice instructor, easy to understand him as well

  • @noi.d609
    @noi.d609 2 роки тому

    Third time watching through. I will be signing up for the boot camp thank you for this.

  • @wojciechneugebauer5926
    @wojciechneugebauer5926 2 роки тому +12

    Awesome content as always! Wesley seems pro and really nice guy!

    • @TheXSSrat
      @TheXSSrat 2 роки тому +3

      Thank you friend :D

    • @katok9938
      @katok9938 2 роки тому +1

      @@TheXSSrat you're cool man!

  • @Bharath-wb8uy
    @Bharath-wb8uy 2 роки тому +23

    Thank you buddy all things you do to the community if not for you people like me coming from poor backgrounds would have faced a lot of difficulty to break into cyber security

  • @edmorris4720
    @edmorris4720 2 роки тому +2

    great work david, nice questions!!

  • @ptyspawnbinbash
    @ptyspawnbinbash 2 роки тому +1

    As always, amazing content!

  • @_taconator
    @_taconator 2 роки тому +3

    Great video! thanks for the awesome content David

  • @Cyber_AR15
    @Cyber_AR15 2 роки тому

    Wow, there is so much to learn. That was a really good informative video.

  • @premiumwaale9728
    @premiumwaale9728 2 роки тому

    Thanks for providing me some supercool testing scenarios David..Love u 3000 man❤️..👍😀

  • @rizekishimaro
    @rizekishimaro 2 роки тому

    A Gold Tutorial Video For Me I was Learned SQLI but Still Confused XSS this Video help me alot.Nice David.From Burma

  • @jamesblock8384
    @jamesblock8384 Рік тому +5

    Dang.... you know I've used templating frameworks for so long like handlebars, angular and most recently Vue. I never considered the possibility of script being injected through these templating engines but it makes perfect sense now that I've seen it.

  • @skeptisch2751
    @skeptisch2751 2 роки тому +4

    I saw wesley for the first time in an interview with nahamsec. I immediately subscribed to his Chanel and watched his amazing videos 👍 java script is for me as network guy a little bit complicated but I learned the basics of reflect attack and found some vulnerability (I reported them ). Thank you David and wesley for this amazing video! ✌

    • @davidbombal
      @davidbombal  2 роки тому +3

      Congratulations! That is fantastic :)

  • @Angel_Santiago27
    @Angel_Santiago27 Рік тому

    Very nice video, I really loved it! I think I just found my new path in the IT world.

  • @adityaroy7196
    @adityaroy7196 2 роки тому +3

    YOU CONTINUE TO BEING THE BEST

  • @alfatech8604
    @alfatech8604 2 роки тому +5

    this xssrat guy is a demon at bypassing wow just wow lol pls a video on javascript for hackers would be great

    • @TheXSSrat
      @TheXSSrat 2 роки тому +2

      Thank you dear friend :D

  • @thevotrozz
    @thevotrozz 2 роки тому

    Thanks David, I finally understood Cross Site Scripting

  • @Alain9-1
    @Alain9-1 2 роки тому

    That's the kind of videos we love, great 🎩

  • @verenuspulo
    @verenuspulo Рік тому

    Thanks! Another wonderfully didactic video!

  • @vincentkadevra
    @vincentkadevra 2 роки тому

    Thank you so much, i just upgraded the security of my project :3

  • @gueroloco8687
    @gueroloco8687 2 роки тому

    Interesting David thanks so much to the guy doing the teaching!!!!

  • @Arayankodesouth
    @Arayankodesouth 2 роки тому +1

    Hi David, It would be great if these type of videos include 'how to prevent being a victim of these types of attacks'.

  • @maumotec2345
    @maumotec2345 2 роки тому

    Amazing content :) Thank you both for it

  • @Nunn_the_wiser
    @Nunn_the_wiser 2 роки тому +4

    What a really likable guy and great teaching methods. I've signed up on Udemy

    • @ClassicRiki
      @ClassicRiki 10 місяців тому

      Yeah he does seem nice. You can tell he really loves it but is up for a laugh as well

  • @parexcellence8222
    @parexcellence8222 2 роки тому +3

    Got scared I actually bought Wesley's Udemy course right away. David continue inviting good people to your channel. I have promised to watch your videos instead of the Ukraine war news. Gives me more knowledge.

    • @TheXSSrat
      @TheXSSrat 2 роки тому +1

      Much love friend :D

    • @parexcellence8222
      @parexcellence8222 2 роки тому

      @@TheXSSrat I actually went to your youtube channel and subscriber there too. XSS is popular and I never understood how they were done. How you present your examples are very simple that it is very easy to understand. I see that you have the talent to teach. Thank you.

  • @MSPHOTOGRAPHY-ep8by
    @MSPHOTOGRAPHY-ep8by 2 роки тому +2

    Now I understand how it works thanks David ❤

  • @z3jlewhhda376
    @z3jlewhhda376 2 роки тому

    You are creating amazing content!!

  • @Smiley-pc7ki
    @Smiley-pc7ki 2 роки тому

    You deserve this 🍪 ( cookie represent appreciation in modder's world).

  • @wardellcastles
    @wardellcastles Рік тому +1

    What a great video. I will sign up for the Udemy course. Thank you!

  • @alooy
    @alooy 2 роки тому +3

    This was very information !
    Such topics should be taught in college , not only how to write code .

    • @TheXSSrat
      @TheXSSrat 2 роки тому +1

      The thing is, I think it really helps to know JS before beginning XSS :D

  • @timvw01
    @timvw01 2 роки тому +2

    Great video! Can you do a video on webassembly safety? Its an exiting new tech, and probably has some security pitfalls. For example, webassembly cannot run when you have csp headers. Cheers

  • @afzalmahmud1974
    @afzalmahmud1974 Рік тому

    Glad I know some basic of XSS security to handle as a developer. How foolish I am? . Thank you for your effort sir. Thanks a loot ❤️

  • @sw-code6027
    @sw-code6027 2 роки тому +17

    alert() 🙃😂

    • @davidbombal
      @davidbombal  2 роки тому +8

      Hopefully that doesn't work as UA-cam is better than Twitter!! 😂

    • @sw-code6027
      @sw-code6027 2 роки тому +1

      @@davidbombal One day we will find vulnerability in UA-cam and tell that "Look here's a bug" 😂 I hope we will do it one day 😂

    • @comeycallate9959
      @comeycallate9959 2 роки тому

      @@davidbombal and also doesn't work to all because there are a lot of comments in this video

  • @lexkenn
    @lexkenn Рік тому

    Awesome vid! 💯

  • @trap7369
    @trap7369 2 роки тому

    amazing, he realy dominates the XSS technique

  • @gregoryjones4539
    @gregoryjones4539 2 роки тому +3

    Keep the great content coming

    • @davidbombal
      @davidbombal  2 роки тому +3

      Thank you! Trying to bring the best content I can to UA-cam :)

    • @gregoryjones4539
      @gregoryjones4539 2 роки тому +1

      @@davidbombal i like learning but am very adhd and most of the time i have no problem paying attention to your content i love your mind set poster that fish is going places lol

    • @TheXSSrat
      @TheXSSrat 2 роки тому

      @@gregoryjones4539 I also have ADHD :) Here's an idea friend, can you watch it in parts? I try to chop everything down into pieces and take those one at a time

  • @alanwilson7792
    @alanwilson7792 2 роки тому

    In addition to complex scripting, bad actors could also, for example, add unwanted images to your sites via the anchor tag - one method to screen out all offending tags in user content is to replace "

  • @orbitxyz7867
    @orbitxyz7867 2 роки тому

    Your regular viewer orbit xyz😉😉

  • @LearnAlongFaizan
    @LearnAlongFaizan 2 роки тому

    Video is great, plz make further video's on these topics

  • @edmorris4720
    @edmorris4720 2 роки тому +1

    with reflected xxs can a attacker make a vulnerable website on purpose and host it them selfs then make a url that downloads somthing?

  • @Konvicted17
    @Konvicted17 11 місяців тому

    Great INFO, Cheers !

  • @CharlesBLim
    @CharlesBLim 2 роки тому

    This is the reason why If you want to be a good hacker you really need to know or understand web development.

  • @maanzero6245
    @maanzero6245 2 роки тому

    Thank you so much for your big efforts ❤

  • @SecurityTalent
    @SecurityTalent 2 роки тому +2

    I am buy your wireshark course.... totally Pro level course ....so so Thank you bro....

  • @MichaelVanDelft
    @MichaelVanDelft 2 роки тому

    Keep up the great videos.

  • @ParameshChockalingam
    @ParameshChockalingam 2 роки тому

    So Content security policy and access control headers should be good enough protection right ?

  • @DRKSPAD3
    @DRKSPAD3 2 роки тому +1

    Awesome video

  • @headlights-go-up
    @headlights-go-up 2 роки тому +1

    This is really interesting stuff

  • @neverendingcoralmaze
    @neverendingcoralmaze Рік тому

    Amazing vid!

  • @Firoz900
    @Firoz900 2 роки тому +1

    Good program guru. Thank you.

  • @sergioeduard4422
    @sergioeduard4422 2 роки тому

    Great video 🖤

  • @agadaFrancisLouis
    @agadaFrancisLouis 2 роки тому

    If i were a President and i had a country, I'd have given you a state to govern. Just my way of saying thank you, Mr. David🇳🇬❤❤❤

  • @user-of4sg8tv2d
    @user-of4sg8tv2d 2 роки тому

    can this not be solved by using .textContent instead of .innerHTML to display content on the page, or even convert the input to a string?

  • @alisenjary
    @alisenjary 2 роки тому +2

    All time the best 😊

  • @user-rc6eu4jm4d
    @user-rc6eu4jm4d 8 місяців тому +1

    (bro, I have a very important question for me, if you have the opportunity, please answer me, because I worry about my account every day) what should I do if I crossed a site with an XSS attack?

  • @justinboss4131
    @justinboss4131 2 роки тому

    Great video…. Thanks

  • @leschi4banane414
    @leschi4banane414 Рік тому +1

    Hey, guys, I know I am kind of late, but I have a question. How can I load and run an external JavaScript onerror? (I thought I could maybe inject beef this way!)

  • @GrimComix
    @GrimComix 2 роки тому

    Love this guy!

  • @smeezy845
    @smeezy845 2 роки тому

    If you would obfuscate your JavaScript then it would technically bypass the code that removes "Script"??

  • @noname5046
    @noname5046 2 роки тому

    Nice guest 👍

  • @albax8847
    @albax8847 2 роки тому +2

    You are the best !!

    • @davidbombal
      @davidbombal  2 роки тому +1

      You are very kind 😀There are many amazing people out there 😀

  • @captainkatz1775
    @captainkatz1775 2 роки тому +3

    Didn't know rats were that smart, time to build an army

  • @ImagineIfNot
    @ImagineIfNot 2 роки тому +1

    thankuuuuuu thanku thankuuuuuuuuuuuuuuuuuuuuuuu luv you

  • @O2C69
    @O2C69 2 роки тому

    for any script to execute on a local pc visiting the "infected site", if the user has no admin rights, can the script be executed to do its malicious activity or not?

    • @tigreonice2339
      @tigreonice2339 2 роки тому +1

      It can

    • @O2C69
      @O2C69 2 роки тому

      @@tigreonice2339 just to confirm the script not requiring elevated privileges to do malicious activity?

  • @thecrownofnoah9100
    @thecrownofnoah9100 2 роки тому

    Sooooooo informational, me like 👍

  • @dankmemes2667
    @dankmemes2667 10 місяців тому

    Hi! Im trying to bypass a filter on a webpage that only accepts some limited alphanumeric 11 character strings. What could be the easiest ways to do that? Is it even possible?

  • @anonymoususer1007
    @anonymoususer1007 2 роки тому

    So recently, I had my bank account hacked and someone stole $2500 from my savings (surprisingly, they didn't wipe me out)- any idea as to why they didn't steal all of it? I'm thinking this is how my bank is hacked because the bank itself said, "at least once a day, someone comes into our branch and says, 'I've been hacked.'" Thankfully, they're FDIC insured and I love my bank/trust it, but I'm curious if this is how they might've stole/transferred money. I have info from them and IP address if someone could help me out. He/She accessed other accounts too, but who knows if it's really that person because they could have a "pool" of IP addresses, but definitely have one.

  • @oscarromero1007
    @oscarromero1007 2 роки тому

    thanks for this video!!

  • @osiris5449
    @osiris5449 2 роки тому

    no matter what I do, my internet on my computer and my cellphone, even using my data and turning wifi off (my identity was sold on the dark web); its like someones flooding me out of my connection. what do i do?

  • @babashehumodu1463
    @babashehumodu1463 Рік тому

    Thank you very much sir David

  • @pollyolly851
    @pollyolly851 2 роки тому

    I want to see the source code of the sample website. Where can I see the sample source code?

  • @JontheRippa
    @JontheRippa 2 роки тому

    Wow thank you, good labs 👍

  • @tungphaminh6767
    @tungphaminh6767 2 роки тому

    I heard about an attack where hacker send an image via gmail or fb and they were able to get my token at that time. Is it true that can tell me how hackers created it and how to prevent it?

  • @castcrus
    @castcrus 4 місяці тому

    Yup, his website is a gold mine, awesome guy!

  • @Alireza52341
    @Alireza52341 4 місяці тому

    You know..i didnt understand a thing What can we do with it? I mean i wanna access the terminal of a website host(to run node.js)can i do this?

  • @morganjones4281
    @morganjones4281 4 місяці тому

    Can jQuery do a lot more than Javascript? Isn't jQuery mostly just prepackaged javascript functions? Kind of like a templating engine but for queries?

  • @youtubvancy8929
    @youtubvancy8929 2 роки тому +2

    Hi David, please bring Dr, chuck once again, thankyou.

    • @davidbombal
      @davidbombal  2 роки тому +3

      Hopefully soon. What topics you want him to talk about?

    • @youtubvancy8929
      @youtubvancy8929 2 роки тому +2

      @@davidbombal its hard to choose topics, maybe more on other languages (go, etc). Mobile app development (swift, kotlin). Windows native apps (c#, pyqt), Programming + linux + networking skills, anything which involves programming, thanks.

  • @landrover827
    @landrover827 2 роки тому +1

    Wow! I had no idea… scary.

  • @mashhood7534
    @mashhood7534 2 роки тому +1

    Thanks ❤️ means a lot

  • @brainiac61
    @brainiac61 2 роки тому +1

    Thanks Again!

  • @mtthsgrr
    @mtthsgrr 11 днів тому

    okay, I got it, but if I steal a cookie session, isn't that MY cookie? How does one knows whom cookie it is?

  • @ahmedyt5998
    @ahmedyt5998 2 роки тому

    Hey David can you make a video for the reverse Engireering apktool,and i thank you for all your course

  • @parshantkumar2455
    @parshantkumar2455 2 роки тому

    Hello David sir , I love your videos very much , but sir can you start podcast on spotify and put the conversations with people on Spotify

  • @AnnyMus-rc2zh
    @AnnyMus-rc2zh Рік тому +1

    take a drink every time he says cross site scripting ahah

  • @Cooliofamily
    @Cooliofamily Рік тому

    At around 10 minutes, isn’t this attack just a cross site request forgery/CSRF?

  • @Yucifer_97
    @Yucifer_97 2 роки тому

    Can you talk about browser fingerprint?