Don't test for IDOR's manually, Autorize is so much faster!

Поділитися
Вставка
  • Опубліковано 11 січ 2025

КОМЕНТАРІ • 50

  • @LeonidasDAce
    @LeonidasDAce 4 роки тому +10

    This was the best, dude. Loved it. Gonna try it tonight🔥

    • @TheXSSrat
      @TheXSSrat  4 роки тому +2

      Thank you so much man 😍🔥

  • @Vinayak123-q8p
    @Vinayak123-q8p 2 роки тому +1

    amazing, this could be probably one of the biggest information that i have ever been given ...we need such playlist more and more in upcoming days.i hope i made you understand the things that i wanted to make you understand..the way how you explain is an amazing. again we need such playlist more and more in upcoming days..

  • @JL-ud6xx
    @JL-ud6xx 3 роки тому +3

    Thank you for your clear explanation! from configuring to explaining output! keep up the good work!

  • @6060fishy
    @6060fishy 4 роки тому +3

    Love the reboot! The bookmarks are a great touch, I am looking forward to your next video!! Thank you

    • @TheXSSrat
      @TheXSSrat  4 роки тому

      Thank you bro 😍😊🔥 and thank you mikro for the bookmarks 😍🔥

  • @h3xvideos869
    @h3xvideos869 4 роки тому +2

    Thank you bro. I really needed this one, been in love with IDOR lately

    • @TheXSSrat
      @TheXSSrat  4 роки тому +1

      Thank you bro 😊🔥 recently found a way to chain IDORs

  • @sourabhyadav9252
    @sourabhyadav9252 4 роки тому +1

    i was waiting for this one to come thanks bro

    • @TheXSSrat
      @TheXSSrat  4 роки тому

      Thank you so much bro 😊 i dident even want to release this one since I already did so much on authorize

  • @cyberpirate007
    @cyberpirate007 4 роки тому +2

    Uncle Rat is Amazing and Insane !! He Stared Bugbounty in January 2020 and He's now Intigriti's Top 40. It's Insane !!! Always

    • @TheXSSrat
      @TheXSSrat  4 роки тому +1

      Respect bro 😍😍😍 you’ve been here for so long

  • @abczwq8364
    @abczwq8364 3 роки тому +2

    thank you so much !!! . great video

  • @vijaySingle143
    @vijaySingle143 3 роки тому +2

    Thank you RAT . you are the only RAT which I like 😍

    • @TheXSSrat
      @TheXSSrat  3 роки тому

      This rat will mess up your hard drive before you know it :3

  • @fm0x1
    @fm0x1 Рік тому +1

    Sorry if I could not understood, but so actually when while you using Autorize in Burp and you see that: "(1) Original Request (2) Original Response and (3) Unauthorized Request", those three are equals, you could found an IDOR? Thanks if someone solve my doubt.
    Awesome video!

  • @sujayhazra8143
    @sujayhazra8143 3 роки тому +1

    thank you amazing hacker

  • @cvija997
    @cvija997 4 роки тому +1

    this is what i need, i love you 🤑🔥

  • @harjotsaini1038
    @harjotsaini1038 4 роки тому +1

    Lit asf 🔥🔥🔥🔥🔥🔥

    • @TheXSSrat
      @TheXSSrat  4 роки тому

      Thank you amazing hacker ☺️☺️😍

  • @aravindv6765
    @aravindv6765 4 роки тому +2

    How to find exact idor, some cases is flase positive in Authorize. Any tips.

    • @TheXSSrat
      @TheXSSrat  4 роки тому +1

      IDOR has a few criteria 😊 first of all ofcourse we need an ID somewhere in the request. Second of all IDORs only work on resources you are not supposed to be able to see

  • @alijujara2432
    @alijujara2432 4 роки тому +2

    Why did you remove the "scope items only" and add it again, I mean the one which is added by default, is it different than the filter you added afterwards?

    • @TheXSSrat
      @TheXSSrat  4 роки тому

      So I could add it again haha 😅 was testing stuff before I recorded and I accidentally left it in there

    • @alijujara2432
      @alijujara2432 4 роки тому +1

      @@TheXSSrat haha okay

  • @Thatsit36
    @Thatsit36 Рік тому

    Couldn't the `/rest/user/authentication-details/` endpoint (at the end of the video) be a false positive because you are signed in as admin and hence getting "Bypassed!" as the original request (Authenticated request) is by the admin?

  • @DEADCODE_
    @DEADCODE_ 2 роки тому

    dudeeeeeeeeee you're goooooooood

  • @Value_Geek9447
    @Value_Geek9447 4 роки тому +1

    You are awesome.

    • @TheXSSrat
      @TheXSSrat  4 роки тому

      Thank you so much amazing hacker 😍🔥

  • @abhishekganesh4434
    @abhishekganesh4434 2 роки тому +1

    Great video🤩 but am facing this below issue.
    I fed Autorize with the cookies of a low privileged user, switched Autorize on and started browsing as an admin just as shown in this video. But Autorize doesn't capture or replay any of the admin requests. Could you please help ?

    • @TheXSSrat
      @TheXSSrat  2 роки тому

      Put in ONLY the headers for authorization like cookies and not all of them 🤗 sometimes a header can duck up authorize

    • @abhishekganesh4434
      @abhishekganesh4434 2 роки тому

      @@TheXSSrat thanks for the prompt response 😍 i too tried with the same owasp juice shop app so I copied the same cookies and Authorization headers just like you did, still faced the issue. Thanks in advance 🙌🏻

  • @logmantarig
    @logmantarig 3 роки тому +1

    Really thanks very useful and amazing video
    I'm very late ;)

  • @TheGhostcc18
    @TheGhostcc18 3 роки тому +1

    Awesome. Ths a lot.

    • @TheXSSrat
      @TheXSSrat  3 роки тому

      My pleasure friend 😍❤️

  • @vikramr1906
    @vikramr1906 3 роки тому +1

    What is name of burp suite extension

  • @drdounge
    @drdounge 4 роки тому +1

    Hey man, what's up? Nice vid again 🔥😁
    Unfortunately Burp Pro is out of my budget atm. Do you know of any alternatives to Authorize?
    I've just read a bit about mitmproxy. Sounds nice to me because you can script arbitrary stuff in Python 😍😜 Have to install and try ZAP as well.

    • @TheXSSrat
      @TheXSSrat  4 роки тому +1

      Thankfully that cleared itself out in the chat today 😍

    • @drdounge
      @drdounge 4 роки тому

      @@TheXSSrat Yes, clarified very nicely 🙂 I think I'll be back soon in the chat, because I might have to recommend to you another metal album 😁

    • @drdounge
      @drdounge 4 роки тому

      @@TheXSSrat Wow ok, sorry but I must recommend it to you right now lol. Because it just has striked me hard listening to it again after such a long time:
      ua-cam.com/play/OLAK5uy_kL37tCTrxU8zdYN36W9oBACNQ4rkW09_E.html
      Sorry if I'm recommending something which might be obvious for you, as said, metal is a genre which I really haven't touched much. But THIS is really good music 👍 Must be a classic of the genre for sure.
      Make sure to check out the video, too, super funny 😁
      ua-cam.com/video/aOnKCcjP8Qs/v-deo.html

  • @maskhiyatusshokhib8272
    @maskhiyatusshokhib8272 2 роки тому

    good

  • @suvarneshkm4845
    @suvarneshkm4845 4 роки тому +1

    2k sub will happen soon :)

    • @TheXSSrat
      @TheXSSrat  4 роки тому +1

      Omg yes 😍😍😍😍🔥 thank you for noticing

  • @tanercoder1915
    @tanercoder1915 4 роки тому +3

    I've been using Autorize for a while and in many cases it shows bypass and it is always false positives. And when site is protected - it is really enforced to use someone else's cookies. Using Auth bearer and Cookie from another user in many cases just duplicates actions on both users accounts. App must be really not thought well for this to work - like in juice-shop.

    • @TheXSSrat
      @TheXSSrat  4 роки тому +4

      First of all, I agree that for some projects authorize is impossible but I don’t really agree with the fact that it’s useless. I’ve used authorize for many projects including a tough one. I will admit you need to set it up just right and that might take a lot of fiddling but it’s 100% better than nothing 😊 maybe I can help you? Feel free to join our discord

  • @uttarkhandcooltech1237
    @uttarkhandcooltech1237 4 роки тому +1

    Coop

    • @TheXSSrat
      @TheXSSrat  4 роки тому

      Soon bro 😍🔥 join discord