CRLF + XSS + cache poisoning = Access to Github private pages for $35k bounty

Поділитися
Вставка
  • Опубліковано 6 лют 2025

КОМЕНТАРІ • 22

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  3 роки тому

    Hi! Welcome to the comment section! I hope you enjoyed the video!
    Get the first issue of BBRE newsletter: mailing.bugbountyexplained.com/news1
    You have time until Saturday 8th May to sign up if you want to receive the 2nd newsletter.

  • @ahmadshami5847
    @ahmadshami5847 3 роки тому +16

    It's amazing how 2 high school students did all that! now those are some newborn legends

    • @TheKing-ul5pw
      @TheKing-ul5pw 3 роки тому

      UA-cam open redirection ua-cam.com/video/aSS23VHAqbU/v-deo.html

  • @imuser007
    @imuser007 3 роки тому +2

    this is amazing man well explained

  • @brijendarsingh3358
    @brijendarsingh3358 3 роки тому

    Clear and concise explaination . thankyou for helping the community .

  • @estebanroman3258
    @estebanroman3258 3 роки тому

    Holyyyy moly! This is huges! Thanks and this channel it's amazing!

  • @-bubby9633
    @-bubby9633 3 роки тому +3

    Another fantastic explanation, super concise and easy to understand as always! Thanks for working so hard to keep us update to date and informed. Noticing that little distinction in the source code between converting to int for accessing the page but not when setting the cookie val as a 14 and 17 year old is seriously impressive. Not to mention the cookie scoping bypasses afterwards. Pretty sure at that age I was nothing more than a dumb script kiddie pressing buttons on Havij 😂

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 роки тому +4

      Thank you Andrew. If someone would tell me that guys in such age found a $35k bug, I would think it's maybe an IDOR, some business logic or something like that but Id never think a chain like this..

  • @0SPwn
    @0SPwn 3 роки тому +1

    Crazy. I'm 14 and these guys are obviously doing some crazy stuff!

    • @sontapaa11jokulainen94
      @sontapaa11jokulainen94 3 роки тому

      I wish you a happy journey into cyber security!

    • @0SPwn
      @0SPwn 3 роки тому +1

      @@sontapaa11jokulainen94 Thank you, you too.

  • @bugr33d0_hunter8
    @bugr33d0_hunter8 3 роки тому +1

    You the man, i love your videos, and the time you put into them. I was always wondering when someone would, reverse engineer the bugs so we can see how they went about finding the bug, along with a proof of concept. I knew the young wipper snappers would rise up and make my job even harder, lol. I love that shirt, looks good on you. I go the gym as well, have to fill out my club shirts, hehe.

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 роки тому +2

      Hahah thanks for the comment!
      I struggle now to find gym alternatives when they are closed but Im doing my best to keep my shirts pumped up!💪

    • @henrypowell3496
      @henrypowell3496 3 роки тому

      so you understood the whole vid? you are genius, man

  • @blablablabla29382
    @blablablabla29382 3 роки тому +1

    Success unlocked: pay back the bank for all school years.

  • @dojoku88
    @dojoku88 3 роки тому

    wow That’s awesome,,

  • @cybersecurity3523
    @cybersecurity3523 3 роки тому

    Good bro

  • @machinexa1
    @machinexa1 3 роки тому

    😊👌

  • @toriyono8018
    @toriyono8018 3 роки тому

    First 🥇