Hacking Websites by Uploading files (With symlinks)

Поділитися
Вставка
  • Опубліковано 3 лют 2025

КОМЕНТАРІ • 63

  • @SteveBClark
    @SteveBClark Рік тому +30

    The GOAT is back....❤

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked Рік тому

      :3 I wonder if this can be used on my bug bounty targets. Also, I'm wondering how many Iranian, Lebanon, Saudi Arabian, North Korea, China, and other sites of terrorist, and dictatorship nations I get can into. 😅🥰🤑😋🤤
      Great Indian hacker video. English. :3 😅 Shalom. Namaste.

  • @schooldropout1337
    @schooldropout1337 Рік тому +8

    Is finding a way to upload files without following the usual restrictions considered a security problem?
    Yes, bypassing file upload restrictions is a security vulnerability because it can potentially allow malicious files to be uploaded to a system, which can lead to various security risks and issues.

    • @ANKUR--xoxo
      @ANKUR--xoxo Рік тому +2

      How to do that

    • @schooldropout1337
      @schooldropout1337 Рік тому

      @@ANKUR--xoxo bro raj will provide an exclusive demo for that scenario 🤠

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked Рік тому

      Thanks for the donation, and question, brother! 🤝🤑☺️

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked Рік тому

      :3 I wonder if this can be used on my bug bounty targets. Also, I'm wondering how many Iranian, Lebanon, Saudi Arabian, North Korea, China, and other sites of terrorist, and dictatorship nations I get can into. 😅🥰🤑😋🤤
      Great Indian hacker video. English. :3 😅 Shalom. Namaste.

  • @anudeepkalyadapu1657
    @anudeepkalyadapu1657 Рік тому +1

    What a video ! Looking forward for such videos man! Keep it up

  • @TejaRavipudi
    @TejaRavipudi Рік тому +1

    big fan. happy that you are back.

  • @_SebJ1000
    @_SebJ1000 Рік тому +3

    It's intresting to learn that they place the password in an environment variable, wonder if most devs encrypt it as well. As that might be the slightest bit more secure.

  • @divyam847
    @divyam847 Рік тому +1

    glad that you're back :)

  • @raoulduke8064
    @raoulduke8064 Рік тому +1

    yeees new video! GOAT is back

  • @TheAKAnonymous
    @TheAKAnonymous Рік тому +1

    a suggestion,
    maybe you should try different titles something special surprising to be able to get more views adding curiosity to new students i mean we are technical student we understand your titles but new students might not
    and last thing as always this was a awesome video
    your's
    TheAKAnonymous

  • @HackingBinaries-dt2fh
    @HackingBinaries-dt2fh Рік тому

    Love you man, just subscribed

  • @mindlesstelevision3213
    @mindlesstelevision3213 Рік тому +1

    Good to see you Back ❤️♥️

  • @dishusharma7881
    @dishusharma7881 Рік тому +2

    Where did you learn to pronounce environment as enveeronment? I am curious.

  • @manishneupane6070
    @manishneupane6070 Рік тому +1

    Wow, great video.
    Thank you for making

  • @rajeevpuri8319
    @rajeevpuri8319 Рік тому +1

    thank you Sir , for this easy to understandable video for a noob like me.🙏🙏

  • @jesusdacoast872
    @jesusdacoast872 6 місяців тому

    Very informative, thanks.

  • @monsterzero6928
    @monsterzero6928 Рік тому

    Can you please make a video on burpsuite how to inject files on servers by changing the file extension and injecting a backdoor with that

  • @SankalpaBaral1337
    @SankalpaBaral1337 Рік тому

    Brother do you remember you used to create challenges (like CTF)? Please make those types of videos again.

  • @Nin_Cada
    @Nin_Cada Рік тому +2

    So what is the counter of it? How to not let the hackers get access to the filesystem using symlincks?

    • @ClashWithHuzefa
      @ClashWithHuzefa Рік тому +1

      Check whether if it is a symlink file or not, and don't let the Web server read, access directories, or file outside the Web root. If you are using php, there is a function is_link() to check whether its a symbolic link file or not

    • @Nin_Cada
      @Nin_Cada Рік тому +1

      @@ClashWithHuzefa i see..
      So, couple of rules for the webserver should do the trick. Thanks ✨

    • @ClashWithHuzefa
      @ClashWithHuzefa Рік тому

      @AkeaNine welcome buddy

  • @prudhvikonakalla9605
    @prudhvikonakalla9605 Рік тому +1

    Raj-"kingu kingu"

  • @Tankbuild-t2i
    @Tankbuild-t2i 2 місяці тому

    you can also direct it make a zip file that contains backdoor shell (shell.php)

  • @anuzravat
    @anuzravat Рік тому

    is there some related article for this symlink vuln, u would like to recommend

  • @montala3380
    @montala3380 11 місяців тому

    Hi brother, the symlink is only work when target site use ZIP/ TAR. How about normal upload file? can I upload that symlink file to retrieve the content?

  • @TechnicalHeavenSM
    @TechnicalHeavenSM Рік тому

    😍😍😍.. You are back❤❤

  • @pinged69
    @pinged69 Рік тому

    Does this affect sites that do not do anything with the file, just purely serve it? I have a pretty basic file hosting service thats public, do I need to somehow worry about this? Symlinks are not something that can be POSTed over HTTPS, right?

  • @st.john_one
    @st.john_one Рік тому

    pretty informative and cool, thanks

  • @Si6n9ne
    @Si6n9ne Рік тому

    Is there any way to recreate this vulnerability, I wanna try and test it out
    If yes someone point me to it please

  • @Si6n9ne
    @Si6n9ne Рік тому

    where to get this source file of the one you doing right now,

  • @SwineTech
    @SwineTech Рік тому

    Daemon, a program that runs in the background, anyone noticed the daemon

  • @gowthamreddysomala
    @gowthamreddysomala Рік тому

    Anna nee Videos Kosam Wait Chastunnam ..

  • @mahesharyatech
    @mahesharyatech Рік тому

    Any Issues With Users ?

  • @lnstagrarm
    @lnstagrarm Рік тому +3

    More unique python projects please

  • @ANKUR--xoxo
    @ANKUR--xoxo Рік тому

    THAT WAS CRAZYYYYYY BRUHHHHH 🔥🔥🔥🔥🔥❤❤❤❤

  • @scorpionisready
    @scorpionisready 6 місяців тому

    Informative ❤️

  • @usningame5177
    @usningame5177 Рік тому

    Do you provide. Course

  • @evilspidy6924
    @evilspidy6924 Рік тому

    Is this exploit have any number like cve-#####

  • @NateSec-d2d
    @NateSec-d2d 7 місяців тому

    Good content Man.

  • @jimmlmao
    @jimmlmao Рік тому

    thats actually genius

  • @sagarhp2350
    @sagarhp2350 Рік тому

    He's back.. 🤩

  • @khushipardeshi3114
    @khushipardeshi3114 9 місяців тому

    Hua kisi se actually hack??

  • @rishi8413
    @rishi8413 Рік тому

    love the explaination

  • @ReligionAndMaterialismDebunked

    :3 I wonder if this can be used on my bug bounty targets. Also, I'm wondering how many Iranian, Lebanon, Saudi Arabian, North Korea, China, and other sites of terrorist, and dictatorship nations I get can into. 😅🥰🤑😋🤤
    Great Indian hacker video. English. :3 😅 Shalom. Namaste.

  • @Topfive_realestate
    @Topfive_realestate Рік тому

    Love you bro 💪💪

  • @pavansasank
    @pavansasank Рік тому

  • @byte01-h1z
    @byte01-h1z 3 місяці тому

    Nice !

  • @Faysalauchan
    @Faysalauchan 8 місяців тому

    😮😮 so amazing

  • @TheAKAnonymous
    @TheAKAnonymous Рік тому +1

    so late to watch your video

  • @JohnDoe-xp9rd
    @JohnDoe-xp9rd Рік тому

    Cool

  • @ClashWithHuzefa
    @ClashWithHuzefa Рік тому

    Amazing

  • @vicmacarra
    @vicmacarra Рік тому

    Lel, interesting

  • @IDK_911
    @IDK_911 Рік тому

    just upload webshell

  • @PlayerOne69
    @PlayerOne69 Рік тому

  • @localh0ste
    @localh0ste Рік тому

  • @shahzansid
    @shahzansid Рік тому

  • @sbh3612
    @sbh3612 Рік тому