RACE CONDITION BUGS!

Поділитися
Вставка
  • Опубліковано 20 гру 2024

КОМЕНТАРІ • 60

  • @FarahHawa
    @FarahHawa  2 роки тому +7

    For practical exploitation of race condition issues, you can use OWASP TimeGap Theory. Read more about it here: timegaptheory.com/

    • @AbhiMBalakrishnan
      @AbhiMBalakrishnan 2 роки тому

      Wow, thanks a lot for sharing my little project, Farah. This made my day 😍

    • @cair0_
      @cair0_ 2 роки тому

  • @8080VB
    @8080VB 2 роки тому +2

    I liked the way you included examples on what condition this is being exploited .

  • @selvakumars9550
    @selvakumars9550 2 роки тому +1

    Clean and Elegant mam. Please keep up the pace!

  • @oldAyushShuklaYouTube
    @oldAyushShuklaYouTube 2 роки тому +6

    This is very informative and simple for a beginner like me, Thank you Farah!

  • @edwinjesuscruzlozano994
    @edwinjesuscruzlozano994 7 місяців тому

    Hola me encantan muy bien explicados y me sacas de muchas dudas

  • @saptaksaha1702
    @saptaksaha1702 2 роки тому +5

    The way of explanation is to the point..u can try this kind of explanation

  • @aahaanalibhujwala6116
    @aahaanalibhujwala6116 2 роки тому +1

    Thanks for adding test cases
    Appreciate it

  • @puneetkumar1385
    @puneetkumar1385 2 роки тому

    Thank you farah for this all lovely content, genuinly thanks

  • @slbpriank91
    @slbpriank91 2 роки тому

    This the kinda videos I follow Farah for! 😍

  • @francisstephenj3875
    @francisstephenj3875 2 роки тому

    Post this types of videos. It's very simple.

  • @melwinalm
    @melwinalm 2 роки тому

    Great explanation. Thank you for sharing.

  • @suniltripathy1399
    @suniltripathy1399 2 роки тому

    I would love if you can include remediation part

  • @expectus1992
    @expectus1992 2 роки тому

    Informative + simple. It would have been great if you could also tell the mitigation tips for the problems

  • @hacking8527
    @hacking8527 7 місяців тому

    Thanks for making this wonderful video I have one doubt. if there is a user creation or a comment posting on the web page and we have captured that in the Burp send to Intruder at started with null payload with 500 suppose if it's created 500 users or posted 500 comments then it will come under the Race condition?

    • @FarahHawa
      @FarahHawa  7 місяців тому +1

      That could just be lack of rate limiting on the endpoint

    • @hacking8527
      @hacking8527 7 місяців тому

      Thanks Farah for replying, i understand it's like as you mentioned if we are booking at the hotel and only one left but two of them booking at the same time then that scenario will come in test for race conditions other like i mentioned will come in lack of rate limiting right?

  • @meljithpereira5532
    @meljithpereira5532 2 роки тому

    Ek dum badiya 🙃

  • @udohellz4340
    @udohellz4340 2 роки тому +2

    Like I've had this explained once but you're use of real world scenarios really solidified it... My only gripe, the music ..it gives me this Dora the explora-esk vibe 😂

  • @pauraspatil9314
    @pauraspatil9314 2 роки тому

    Nicely Explained!

  • @thushi4107
    @thushi4107 2 роки тому

    Good explanation,
    But please do a sample experiment in the videos like this

  • @Sourav_Debnath
    @Sourav_Debnath 2 роки тому

    really liked the video.

  • @myself.mohammed.ibrahim
    @myself.mohammed.ibrahim 2 роки тому

    Absolutely this information and way of explanation is so neat and easy to understand, thanks #Farah

  • @aiteshammamadapur8141
    @aiteshammamadapur8141 2 роки тому

    New thing for me. Any general solutions for racing conditions?

  • @kirankumarsubuddi363
    @kirankumarsubuddi363 2 роки тому

    Video was pretty good. I liked the animations/objects that you have introduced. How did you created the animations ? Can you provide some references for it.

    • @FarahHawa
      @FarahHawa  2 роки тому

      I used Canva to make everything!

  • @hva8055
    @hva8055 2 роки тому

    I have just learnt a new vulnerability

  • @p.k5016
    @p.k5016 2 роки тому

    Thanks Alot Maam

  • @kr4k3nn
    @kr4k3nn 2 роки тому

    Great. Precise. Thanks. :)

  • @RX_100.0
    @RX_100.0 2 роки тому +1

    Where is vulnerable lab for this video
    Btw very nice info provided

    • @AbhiMBalakrishnan
      @AbhiMBalakrishnan 2 роки тому

      OWASP TimeGap Theory is a lab dedicated for race condition issues

    • @RX_100.0
      @RX_100.0 2 роки тому

      @@AbhiMBalakrishnan is it free lab..?

    • @FarahHawa
      @FarahHawa  2 роки тому +1

      @@AbhiMBalakrishnan thanks for sharing! :)

    • @AbhiMBalakrishnan
      @AbhiMBalakrishnan 2 роки тому

      @@FarahHawa Thank YOU. I'm a big fan of your work. One thing that sets you apart from other infosec content creators and professionals is your focus on constant improvisation. This video is a good example - you are trying a new format. Similarly, you are not a find bugs and fire person. Your guidelines on writing/creating better PoCs were a gem. I personally believe your work is highly underrated and underappreciated. I'm sure things will change, you are years ahead of many creators and people will realize the value of your work over time - I'm looking forward to that.

    • @FarahHawa
      @FarahHawa  2 роки тому +1

      @@AbhiMBalakrishnan this comment made my day, thank you so much for your kind words 💜

  • @mfundimfundoh5473
    @mfundimfundoh5473 2 роки тому +1

    Thank you !!

  • @rynexxx8661
    @rynexxx8661 2 роки тому

    thanks for this..keep going

  • @rajkaran3798
    @rajkaran3798 2 роки тому

    Great keep it up 🤟🤟

  • @siddharthchhetry4218
    @siddharthchhetry4218 2 роки тому

    Wow learnt a lot thank you

  • @AyushKumar-hv2ww
    @AyushKumar-hv2ww 2 роки тому

    Very nice 👌👌👍🙏

  • @shubham_srt
    @shubham_srt Рік тому

    Thank YOu :)

  • @exoooooooo
    @exoooooooo 2 роки тому

    No explanation how to prevent this bug?

  • @manav2003
    @manav2003 2 роки тому

    U forget to add reports can u please mention them....
    BTW osm vedio🥰

  • @ArSiddharth
    @ArSiddharth 2 роки тому

    Nice ☺️

  • @laurent9255
    @laurent9255 2 роки тому

    So in my opinion a simple python script using multithreads will do the same . No need to use Burp .

    • @FarahHawa
      @FarahHawa  2 роки тому

      Yes, that’s true! I use Burp because I find it convenient but it’s totally not necessary

  • @bobby3003
    @bobby3003 2 роки тому

    The cutest hacker on the whole UA-cam 💖✨

  • @shabbirkhan690
    @shabbirkhan690 2 роки тому

    Some project for you...if u able to perform gray hat hacking.

  • @cair0_
    @cair0_ 2 роки тому

    pump

  • @venomsnake4829
    @venomsnake4829 2 роки тому

    I am just here to see your face
    Your content is not good as other infosec guys like ippsec or stok or liveoverflow

  • @noormohammadgagguturi
    @noormohammadgagguturi 2 роки тому

    1st Comment

  • @omkarchavan1820
    @omkarchavan1820 2 роки тому +1

    Men of culture gather here 😛

  • @lapuranjan5574
    @lapuranjan5574 2 роки тому

    💘💘💘💘💘💘💘💘💘💘💘💘

  • @anshulpal4379
    @anshulpal4379 Рік тому

    4 minute ki video main 1 minute to ad dikha diya @FarahHawa