Watch How Hackers Checkout Products For Free On Any Website And Learn To Defend Against Hackers!

Поділитися
Вставка
  • Опубліковано 27 жов 2024

КОМЕНТАРІ • 482

  • @LoiLiangYang
    @LoiLiangYang  3 роки тому +271

    This technique is not that straightforward in the real world. Because UA-cam does not allow us to upload zero-day exploits. Instead, if you want to seriously know how it works in the real world, join our full ethical hacking course on Udemy with real world examples! www.udemy.com/course/full-ethical-hacking-course/

    • @Insomniac_Insights
      @Insomniac_Insights 3 роки тому +10

      Why are you hiding in top corner?

    • @anonymosehackertim4mysore703
      @anonymosehackertim4mysore703 3 роки тому +1

      Loi sir can you make an video of how to start bug bounty for beginners because near my home there are no any bug bounty teachers but I’m interested on it so plzzzzz👈👈👈

    • @Echo-kw1sp
      @Echo-kw1sp 3 роки тому +1

      @@kunalraut1689 used on which site?

    • @asecurity8988
      @asecurity8988 3 роки тому +2

      Hi mr lio liang yang im member in this chanel and i subscribed but i don't have access to some videos it tell's me that i not a member

    • @worldaffairs2.060
      @worldaffairs2.060 3 роки тому

      Hey how to hacking start

  • @numberiforgot
    @numberiforgot 3 роки тому +123

    If an exploit is on UA-cam, it doesn’t work now.

    • @DynamicLights
      @DynamicLights 26 днів тому +3

      Not at all. I did it to a site and it worked.

  • @viletomedoze5036
    @viletomedoze5036 3 роки тому +866

    This would work if we're still in early 2000s
    Edit: Wow! I did not expect so many likes and comments. Appreciate you all. Thanks!

    • @fjdjzfhrsut8063
      @fjdjzfhrsut8063 3 роки тому +70

      You'd be surprised to know how many million dollar foundations are running websites from the 1990s. Just because they keep on getting away with it.

    • @七人の侍-b1q
      @七人の侍-b1q 3 роки тому +12

      @@fjdjzfhrsut8063 Names?

    • @viletomedoze5036
      @viletomedoze5036 3 роки тому +61

      @@fjdjzfhrsut8063 time to buy a spaceship and live in mars all for 99 cents

    • @lloydguia3118
      @lloydguia3118 3 роки тому +1

      HAHAHHAHAHAH yeah

    • @thresh-
      @thresh- 3 роки тому +3

      Chase Bank and John Deere

  • @iamAustinL
    @iamAustinL 3 роки тому +253

    Amazing, now time to go get them Bugatti's for 25 cents a pop and sell em for 200 stacks of 💰 ben franklins lol

  • @TheDjTotzy
    @TheDjTotzy 3 роки тому +741

    As a full stack Software Eng: laughing in server side validation

    • @rishiktiwari
      @rishiktiwari 3 роки тому +3

      Precisely

    • @oah8465
      @oah8465 3 роки тому +56

      if any dev on my team sends the price instead of the item-hash he will find himself without a job in zero-time.

    • @sagegeas9205
      @sagegeas9205 3 роки тому +14

      Not a full stack dev or anything like that. Just a nerd, and laughing hard.

    • @CommentThink
      @CommentThink 3 роки тому +11

      i clicked this just to comment something similar.. haha 😂

    • @Sasqe
      @Sasqe 3 роки тому +2

      Lmaooo ikrr

  • @PhilLesh69
    @PhilLesh69 3 роки тому +50

    I am a web developer for a content publisher, not for e commerce, but even I would know better than to use any numbers sent by the browser in a transaction. Any price numbers I would send to the browser would simply be for the user to look at. I'm always going to use my numbers from my database and not an easily tampered with POST from variable.

    • @PhilLesh69
      @PhilLesh69 2 роки тому +4

      @MOTIVATIONAL WALLAH - PHYSICSWALLAH Yeah sure buddy. Why don't we call the cops and let them know that you and I plan to do crime stuff together buddy.
      lol.

    • @wardog697
      @wardog697 2 роки тому

      @MOTIVATIONAL WALLAH - PHYSICSWALLAH annoying

    • @gyrozeppeli3515
      @gyrozeppeli3515 2 роки тому

      @@PhilLesh69 Damn

    • @dylanhoffman1147
      @dylanhoffman1147 2 роки тому +1

      humm cop caller snitches get stitches found in Ditches

    • @ygthemasta3480
      @ygthemasta3480 Рік тому

      @@PhilLesh69 buddy headass kid. Yung meza God bud

  • @GrittyMaholmes
    @GrittyMaholmes 3 роки тому +189

    instead of the delivery guy , the cops showed up.....? I NEED A REFUND NOW !!

  • @HenriqueAraujo174
    @HenriqueAraujo174 3 роки тому +298

    Interesting how 99% of hacking tutorial just doesn't work in 99% of websites and they say "How hackers does this or that"....

  • @r4z74
    @r4z74 3 роки тому +202

    This only works if the web app doesn't verify the price on the server-side which rarely happens in decent sites.

    • @lewyathan
      @lewyathan 3 роки тому +16

      this have 1% chance to work lol

    • @r4z74
      @r4z74 3 роки тому +15

      @@lewyathan Yeah, well it depends on the developer... If it's a developer you found on some site and he only cares about the money he wouldn't care about security thus it'll probably work... It could also be an amateur developer and it'll might work

    • @anonymus3286
      @anonymus3286 3 роки тому +2

      Please what website can this work on

    • @r4z74
      @r4z74 3 роки тому +5

      @@anonymus3286 probably non of the websites that you use... If you are pen testing a website and they have a payment system it's worth giving it a try but the vulnerability could come in different forms. I think someone found something similar in "ikea". Try to search up "ikea parameter tampering"

    • @anonymouscyborg5610
      @anonymouscyborg5610 3 роки тому

      But it government sites and many, it is still like so

  • @ekids.bassment
    @ekids.bassment 3 роки тому +153

    I've never calculated anything client-side other than for visual display. Who does this?

    • @IIShana-chan
      @IIShana-chan 3 роки тому +6

      More ppl than you'd think

    • @ihateevilbill
      @ihateevilbill 3 роки тому +4

      Im betting no-one. Having the knowledge to POST but not knowing how to deal with that POST doesnt make any sense.

    • @vaja5357
      @vaja5357 3 роки тому

      @@ihateevilbill frequently developers try to put as much stuff on the front as possible to avoid network and memory overhead on the backend but they mis something and a design flaw is born that way.

    • @toki3204
      @toki3204 3 роки тому +1

      @@vaja5357 i always put security a bit over performance, tho i still make sure i don't write any bullshit code. but storing prices on the backend is a must do. A way to avoid performance issues is to put a cooldown, or use multiple servers and f.e. have nginx put clients to the currently less full server. my friend had one server and tried to put so much security (even tho hes just an amateur), that he himself forgot how some of his scripts work, which caused them to conflict quite a lot, no optimization whatsoever (he didnt even minify the js code). once he said he's done i tried finding vulnerabilities: the conflict between the scripts made so much sinks, that it's been very easy to find an element which could either cause SQL injection, path traversal, and on top of that, he completely forgot about XSS

    • @sulbirgir2484
      @sulbirgir2484 2 роки тому

      me

  • @jk-gn2fu
    @jk-gn2fu 3 роки тому +221

    Moral of the story: never trust the client-side.

  • @TheIndianRoaster
    @TheIndianRoaster 3 роки тому +76

    Every kid seeing this be like : Yes this is what I want, now I can get Roblox for free

  • @sahanpanditharathne2765
    @sahanpanditharathne2765 3 роки тому +35

    This wouldn't even work on sites i build for my university projects 😂😂

  • @randomsaga6619
    @randomsaga6619 3 роки тому +97

    How to use this hack on your Udemy course..

    • @nikhilkatte2715
      @nikhilkatte2715 3 роки тому +6

      it wont work anywhere he it will work if any developer was drunk and was wrote the data base and payment gateway

    • @asurhere9725
      @asurhere9725 3 роки тому

      @Random Saga Bro DM me on insta
      asurhere2021

    • @MsSoldadoRaso
      @MsSoldadoRaso 3 роки тому +1

      @@nikhilkatte2715 hahahahhaha xD

    • @MsSoldadoRaso
      @MsSoldadoRaso 3 роки тому

      @SIDDHARTHTM of course

  • @ismailkaracakaya260
    @ismailkaracakaya260 2 роки тому +4

    This is happening because the backend dev/s are not validating the input coming from the frontend which a 10 years old can do. It is crazy that such devs getting jobs in the industry...

  • @Pwnedby
    @Pwnedby 3 роки тому +4

    It should verify the transaction from the front end to the backend and see if the amount is equal to the transaction

  • @redstarentertainment2621
    @redstarentertainment2621 3 роки тому +11

    This becomes shitty if the developer has done a server side check while order placing.

  • @theencryptedpartition4633
    @theencryptedpartition4633 3 роки тому +60

    Me seeing HTML writing the first 10 secs: Please don’t tell me this is the guy who hacked NASA with HTML😂

  • @binarylossrecovery206
    @binarylossrecovery206 3 роки тому +13

    My Bank Card : No way To buy this...
    Me : Open Google Inspector..
    My Bank Card : Ohh Shit......

  • @TANKBM
    @TANKBM 3 роки тому +24

    Mr Loi Laing you are a wonderful person because you spread knowledge to me, someone who wants to learn, thank you from the heart

  • @HariKrishna-me6sk
    @HariKrishna-me6sk 3 роки тому +15

    Even so, wouldn't the seller just realize he got paid $299 for a $2999 TV and reject the order ?

    • @hallogusy
      @hallogusy 2 роки тому +2

      I think dont cause i think you hack from 2999 to 299 i think te sever will think that you pay 2999

  • @QadriHarris
    @QadriHarris 13 днів тому

    Yeah, it probably worked in early 2000s late 90s with the early machines and software code but now if you edit and change, hyper text it just go back to standard text

  • @mr.bubble1657
    @mr.bubble1657 3 роки тому +5

    I tried it this trick on amazon and now i am in jail !
    Wondering how i commented if i am in jail ?
    I just stole the officers phone when he was performing weekly inspection of my cell !!

  • @sergetonton9609
    @sergetonton9609 3 роки тому +2

    it does not work in any website the majority are protected against this flaw I took the trouble to test thanks for the work you do

  • @blueoak5262
    @blueoak5262 2 роки тому +7

    I guess PS5 doesn't have to be so expensive after all 🤭♥️

  • @f4nicflare612
    @f4nicflare612 Рік тому +2

    Instructions unclear, the UPS driver put me in handcuffs and I’m at the police station now

    • @f4nicflare612
      @f4nicflare612 Рік тому

      @mitchelleintroducerogersfloyd1 what a generous baker! 🍞👨‍🍳

  • @tharunthammaiah9196
    @tharunthammaiah9196 3 роки тому +9

    It's About time I get that New Rolls Royce Boat Tail😂

  • @3dmixer552
    @3dmixer552 2 роки тому +2

    Do you think any shop would send the item out without checking the price and payments? I don't thinks so

  • @silencer2703
    @silencer2703 Рік тому +1

    No modern website worth their salt would ever forget to verify the transaction.

  • @developersharif
    @developersharif 3 роки тому +1

    *To solve the problem php is the only king! before response check the price from db.*

  • @rylon_
    @rylon_ Рік тому +1

    Does this work on amazon or steam?

  • @superguy654
    @superguy654 3 роки тому +9

    I'm confused because will this work or just as soon as you ship it to your house the cops show up?

    • @salvathir
      @salvathir 3 роки тому +4

      Most likely no one will know unless an admin or someone checks it manually which is unlikely especially if the website gets alot of purchases but this video is only a demo to find a bug like this in the wild will be a bit harder and little different but same idea and concept :)

    • @robinhood3001
      @robinhood3001 3 роки тому +1

      @@salvathir f

    • @jammiegreen6934
      @jammiegreen6934 3 роки тому

      @@salvathir j

  • @Sasqe
    @Sasqe 3 роки тому +1

    As a full stack developer, any good website would not allow this to happen?? i hope??

  • @AMINEDZMCA
    @AMINEDZMCA 3 роки тому +11

    Time to download some free packs i guess!

  • @mi4o213
    @mi4o213 3 роки тому +3

    only real hacker do "Right click , inspect element and then just change the money" :D

  • @interesting_stuffs
    @interesting_stuffs 3 роки тому +17

    Manipulating the server request is called Hacking 😂
    Then, i think all the developers are hackers 🤪

  • @simolajustice6555
    @simolajustice6555 3 роки тому +1

    This website it's like is built by someone who just learnt how to build websites with skillshare/udemy courses

  • @leetkhan
    @leetkhan 3 роки тому +4

    It might not work on 100% of websites, the last and current place I worked, both were sending amount from the frontend which directly redirected to payment gateway. So if you ask me it does not hurt to check for this on all websites you use.

  • @pipeliner8969
    @pipeliner8969 3 роки тому +4

    but what is the way t prevent it? I will use this knowlegde to help others not to destroy them.

  • @shahzaibali4911
    @shahzaibali4911 3 роки тому +1

    And that's why you check the prices in the backend :)

  • @pollyolly851
    @pollyolly851 3 роки тому

    He edit request before it post to the backend. but if it have a backend validation. It shouldnt be a problem. .hmmm. Im tempting to try it.

  • @mrkarthick3077
    @mrkarthick3077 Рік тому

    Html tampering it's based on the manipulation of parameters exchanged between client and server in order to modify application data

  • @onthearth1
    @onthearth1 3 роки тому +1

    How does this works in real life? It's interesting..

    • @user-us4nc6kw3z
      @user-us4nc6kw3z 3 роки тому

      *MESSAGE☝️☝️☝️☝️THEY WILL HELP YOU OUT*

  • @Cyber_Sharma
    @Cyber_Sharma 3 роки тому +7

    Now i am going to buy iphone 12 pro max and macbook air

    • @-jamiestorch-4562
      @-jamiestorch-4562 3 роки тому +1

      id be very shocked if u find a site that allows you buy a new iphone.Title is click bait in affaid.

  • @rich_dev_greg
    @rich_dev_greg 2 роки тому +1

    I knew this was possible when I recovered my stolen Bitcoin last year using a hacking software.
    I still have it with me and it still works

  • @KingTechOfficial
    @KingTechOfficial 2 роки тому

    Can you get tracked by doing this

  • @pankajbhoi4900
    @pankajbhoi4900 3 роки тому

    it only reflects the front end.. but it wont reflect the back end... if the price is comming from server side... then it wont work. you need to attack to the database. Now a days it doesn't work if the website is built by framework. Cause they are very secure

  • @greenbeginner3353
    @greenbeginner3353 2 роки тому

    You’re saying that you can buy anything for free on Amazon?

  • @ramkanwar9697
    @ramkanwar9697 3 роки тому +2

    After u refresh the page, the price will reset to it's original value

    • @FunFreak.
      @FunFreak. Рік тому

      😅😅😅 you're a pro

  • @whisperofpast
    @whisperofpast 3 роки тому +1

    How to make video about something that works only in 0.1% and earn some money. Great tutorial.

  • @gettechnow7593
    @gettechnow7593 3 роки тому

    Sir could all this be done in burp suite

    • @Jessicagambo
      @Jessicagambo 3 роки тому

      Seek HELP from ZELLHACK1 on insta he’s so reliable who got that of my company fixed

  • @kavkavy
    @kavkavy 3 роки тому

    no sir we check it on the server side (in controller) so your request gonna be rejected

  • @mitchellyuen7961
    @mitchellyuen7961 3 роки тому +2

    This would not work in any real world e-commerce application, information about a product or cart content would be stored on the backend and handled there, the frontend is just representational.

  • @techchannel3107
    @techchannel3107 3 роки тому +4

    Loi liang yang how can i attend your ethrical hacking in udemy

    • @jimmyjv7723
      @jimmyjv7723 3 роки тому

      How much it cost?

    • @LoiLiangYang
      @LoiLiangYang  3 роки тому

      Here you go: www.udemy.com/course/full-ethical-hacking-course/

    • @tecnicalinfo6418
      @tecnicalinfo6418 3 роки тому

      @@jimmyjv7723 I will give u free if u want

  • @revenge2072
    @revenge2072 Рік тому +1

    how do you defend?

    • @SaVeGe_OmG
      @SaVeGe_OmG 3 місяці тому

      Sorry for late response, To defend you simply do server side validation of the purchase.

    • @SaVeGe_OmG
      @SaVeGe_OmG 3 місяці тому

      The guy in the video did it on client side, It didn't got any server side to check if his purchase was valid so that's why he bought it that easily.

  • @adityarawat01
    @adityarawat01 3 роки тому +1

    How to buypass security and view paid videos on websites

  • @Slattteto
    @Slattteto 3 роки тому

    How do I bring webgoat to the site or brin the site to the webgoat

    • @Jessicagambo
      @Jessicagambo 3 роки тому

      Seek HELP from ZELLHACK1 on insta he’s so reliable who got that of my company fixed

  • @ishitapal6866
    @ishitapal6866 3 роки тому +4

    Shall I try this? 🥺

  • @10lazerclips
    @10lazerclips Рік тому

    this won't work, you are just tempering with your own browser.
    don't forget it have to be validated in the server side

  • @riteekraj3815
    @riteekraj3815 3 роки тому +2

    Two boys were doing this but unfortunately they caught by police 😅

  • @foxeeek
    @foxeeek 3 роки тому +1

    youtube casually recommending this like ur supposed to know how to hack lol
    pretty fun i guess

  • @YazhShah
    @YazhShah 3 роки тому +1

    How does a hacker use windows

  • @tuttifrutti4184
    @tuttifrutti4184 3 роки тому +1

    Bill Gates? Jeff Bezos? Elon Musk? Move out of the way, now I will be the richest man alive, EVER!

  • @christiankusi2974
    @christiankusi2974 3 роки тому +1

    hello, i have subscribed to your channel but whenever I want to watch the videos it says members only. please how can I get access to those videos, is there a way to register? please your videos are really helping

    • @LoiLiangYang
      @LoiLiangYang  3 роки тому +2

      Here you go: ua-cam.com/channels/1szFCBUWXY3ESff8dJjjzw.htmljoin

    • @christiankusi2974
      @christiankusi2974 3 роки тому +1

      @@LoiLiangYang thanks alot. And your video is really helpful. God bless you ❤️.
      I have subscribed, but still saying join this channel to get access. I wish I can send a screenshot

    • @collingodworks7520
      @collingodworks7520 3 роки тому

      @@LoiLiangYang I need your contact or email

  • @ravitejacheruvu2365
    @ravitejacheruvu2365 3 роки тому

    Is it true video? Is it Same to use in personal mobile?

  • @TheHydrogen4
    @TheHydrogen4 3 роки тому

    Who writes code like this? This may have worked back in 2000 when the web was young, and I have my doubts because this is clearly bad design. These transactions are done by product id.

  • @franknguyen802
    @franknguyen802 Рік тому

    It had no longer work on this technique. All the legit websites had already have controlled hacking system. Even though, you have done the same this way, but it’ll never work on this way anymore.

  • @gamingg-p8r
    @gamingg-p8r 3 роки тому +1

    why can't i join to watch these member only videos? how do i go about it coz i can't see a join button

    • @jay-mn7cs
      @jay-mn7cs 3 роки тому

      ni juu wamerestrict geographically, jaribu na vpn

  • @jameskimuyu1317
    @jameskimuyu1317 Рік тому

    The serve side cant verify that transaction.

  • @Slattteto
    @Slattteto 3 роки тому

    How to get the web goat to the store your trying to use iron

  • @MB-di8cw
    @MB-di8cw 2 роки тому

    Hi I have a question. If i want to do them types of fraud, how can I do it without being traced?

  • @ankitchouhan4863
    @ankitchouhan4863 3 роки тому

    If I do whatever you said in this video
    So can i buy this TV at 299 dollars..???

  • @sumanthsai2254
    @sumanthsai2254 3 роки тому

    man this reminds me of kids who remove password field for fb and click sign in and show that this is how its done

  • @saeedkhan321
    @saeedkhan321 3 роки тому

    i do not see join button on your channel. plz guide

  • @nishantbhagat752
    @nishantbhagat752 2 роки тому

    Where was the "how to defend" part???

  • @Immunohematologymadeeasy
    @Immunohematologymadeeasy 3 роки тому

    How to download pdf books ( not free ) ?

  • @mr_rawa
    @mr_rawa 3 роки тому +2

    Does this really work?

  • @EmoViolenceEnjoyer
    @EmoViolenceEnjoyer 2 роки тому

    But wouldn't the seller see that you did this and pursue you for this?

  • @Aparichi78gft
    @Aparichi78gft 21 день тому

    Learn web dev js very helpful in every field ,also now i know i will never trust client aand will validate the server

  • @gamabike_life4105
    @gamabike_life4105 10 місяців тому

    Came here too look to get a concept that what people don’t understand you get the concept so you know what to do

  • @obinnaaizuk513
    @obinnaaizuk513 2 роки тому

    what is that

  • @siorzen1473
    @siorzen1473 3 роки тому

    So i can buy stuff for free now?

  • @alberthong9270
    @alberthong9270 3 роки тому +2

    Please what site can I shop with this your tutorials sir

    • @kumarsahab3828
      @kumarsahab3828 3 роки тому +2

      It's a vulnerable java based application "Webgoat".

    • @rifatneily
      @rifatneily 3 роки тому

      @@kumarsahab3828 bro can you help me?

    • @kumarsahab3828
      @kumarsahab3828 3 роки тому

      @@rifatneily Yes brother tell me

  • @bigdatax6512
    @bigdatax6512 3 роки тому

    im classic person n not programer..if i sell something n not match with the price..i will not send my stuff to buyer,,,simple

  • @tofa2006
    @tofa2006 3 роки тому

    Loi I really need your help what should I do after that

  • @alifrahmanputranda1463
    @alifrahmanputranda1463 3 роки тому

    Who the heck send the price instead of product id and qty?

  • @Amzish
    @Amzish 3 роки тому +1

    Oh men!!! I'm worried about my stores is this bug work for Shopify stores as well?

    • @darshaim
      @darshaim 3 роки тому +2

      no, it doesn't work on shopify, your store is much secure with shopify, so just chill

    • @Amzish
      @Amzish 3 роки тому +1

      @@darshaim Thank you bro

    • @Tux0xFF
      @Tux0xFF 3 роки тому +1

      Shopify wouldnt exist if this was possible, or any other e-commerce solution. This affect only to the one that create their own e-commerce systems, they are in for a great awakening, this attack is not level 0

  • @killerdro42069
    @killerdro42069 2 роки тому

    Holy SHIT it fucking works just bought a motorcycle for $1200 instead of 12,000 the truck will be here tomorrow with my bike I do t know if I’m going to be able to keep it but as far as the exploit goes it worked for me hopefully I will be riding a new motorcycle tomorrow I will comment when bike arrives to my house if it comes I don’t know how they would not be able to notice over 10,000 missing from the amount they received for the bike

  • @mrjaybennett80
    @mrjaybennett80 2 роки тому

    Can I use this to buy Hookers at a discount?

  • @nithishj7614
    @nithishj7614 3 роки тому

    Is it illegal if we try it?

  • @HulteGHG
    @HulteGHG Рік тому

    Btw this still works on many German (Familienunternehmen) sites

  • @GTjames_O
    @GTjames_O 2 роки тому

    Can i do it on my android smartphone?

  • @dayshag5257
    @dayshag5257 2 роки тому

    it didn't even work

  • @whoamisecurity9586
    @whoamisecurity9586 3 роки тому +1

    Sir make video on full website hacking

  • @CandL_IRL
    @CandL_IRL 2 роки тому

    how do i get web goat?

  • @srdjanst1
    @srdjanst1 2 роки тому

    Which browser is that?

  • @surgeon23
    @surgeon23 3 роки тому

    are there really shop websites out there that post the price?

  • @karthik20187
    @karthik20187 3 роки тому +2

    Epic videos will be not available at the right times.

  • @notkaden4479
    @notkaden4479 3 роки тому

    thanks for teaching me how to do it

  • @theflowindahouse8236
    @theflowindahouse8236 2 роки тому

    what version of kali linux is that