Це відео не доступне.
Перепрошуємо.

XSS WAF Bypass Techniques

Поділитися
Вставка
  • Опубліковано 15 сер 2024
  • Master the different ways to bypass the Web Application Firewall to fully exploit Cross-Site Scripting! In this video, I will show how it looks from the defensive side and the ways to bypass those firewall rules.
    ---
    Patreon: ott3rly.com/pa...
    Twitter: ott3rly.com/tw...
    Discord: ott3rly.com/di...
    Get a $200, 60-day credit for DigitalOcean: ott3rly.com/do
    NordVPN: ott3rly.com/No...
    Domain: ott3rly.com/12...
    0:00 - Intro
    0:42 - Initial Setup
    1:57 - User Agent Blocks
    3:36 - IP & Country Blocks
    6:07 - Bypassing Basic XSS Rules
    10:39 - Additional Tips and Tricks
    Disclaimer: This channel is strictly educational for learning about ethical hacking and penetration testing so that we can protect ourselves against real hackers. Hacking without permission is illegal so always ensure you have proper authorization before using security tools in any network environment.
    #bugbounty #xss #firewall #cybersecurity #itsecurity

КОМЕНТАРІ • 47

  • @iloiskihailm8710
    @iloiskihailm8710 5 місяців тому +3

    Dude, you're totally killing it with your techniques, way ahead of everyone else!

    • @Ott3rly
      @Ott3rly  5 місяців тому +1

      My pleasure!

  • @Khalid-bm4fw
    @Khalid-bm4fw 3 місяці тому +2

    Thanks
    We need more content like this

  • @cyberpro151
    @cyberpro151 5 місяців тому +1

    yooo! My brother has again contributed some best things for the community! God bless you dear

    • @Ott3rly
      @Ott3rly  5 місяців тому +1

      Thanks bro!

  • @PleaseTheNinja
    @PleaseTheNinja 5 місяців тому +1

    This is a very good approach! Congrats on your success

    • @Ott3rly
      @Ott3rly  5 місяців тому

      Thanks so much!

  • @abhinavbansal-cc8gr
    @abhinavbansal-cc8gr 5 місяців тому +3

    gr8 video......need more like this..also on advance xss filter bypass

  • @ilhamdn23
    @ilhamdn23 3 місяці тому +1

    i love this content, thank you Ott3rly

  • @user-ud7en9uv2b
    @user-ud7en9uv2b 28 днів тому +1

    Nice ❤‍🔥

  • @detective5253
    @detective5253 4 місяці тому +1

    New subscriber here, i really love your content mate!

    • @Ott3rly
      @Ott3rly  4 місяці тому +1

      Welcome aboard!

  • @asifsaifi2925
    @asifsaifi2925 5 місяців тому +1

    Pretty goodddddddd Man really awesome content

    • @Ott3rly
      @Ott3rly  5 місяців тому

      Glad you enjoyed

  • @vlogsprasenjit
    @vlogsprasenjit 5 місяців тому +1

    Subscribed! Amazing content, I have just started BB

    • @Ott3rly
      @Ott3rly  5 місяців тому +1

      Welcome aboard!

  • @BanglarPranChitra
    @BanglarPranChitra 5 місяців тому +1

    Best best best 😮

  • @Lazyhackerbd
    @Lazyhackerbd 5 місяців тому +1

    great video boss

    • @Ott3rly
      @Ott3rly  5 місяців тому +1

      Appreciate it!

  • @sattharzakeer9594
    @sattharzakeer9594 5 місяців тому +1

    Awesome 😮

    • @Ott3rly
      @Ott3rly  5 місяців тому

      Thanks 🤗

  • @munchlenova6353
    @munchlenova6353 5 місяців тому +1

    Video is exllent

  • @overthinker1877
    @overthinker1877 5 місяців тому +1

    Thx great video 🫶🏽

  • @AhmedMoubarak-pz5yu
    @AhmedMoubarak-pz5yu 5 місяців тому +1

    Thank you for the wonderful videos. I watched most of them, but I have a problem with waf. When fuzz for subdomain enumeration or directory or hidden parameter or anything after a short period of time, l block with waf, and the response is late from the server.

    • @Ott3rly
      @Ott3rly  5 місяців тому +1

      The way you trigger WAF is trying to access the specific endpoints or sending malicious requests. It's just an another layer of defense for websites. Unfortunately, its the biggest pain in the ass for most cases while doing bug bounties. I will be sharing some extra videos on this topic in the future, to help avoid it or bypass it. Feel free to check discord, if you have some questions or looking for collabs ;)

    • @AhmedMoubarak-pz5yu
      @AhmedMoubarak-pz5yu 5 місяців тому

      ​@@Ott3rly❤

  • @ss-rc1gy
    @ss-rc1gy 5 місяців тому +1

    Nice ❤

    • @Ott3rly
      @Ott3rly  5 місяців тому

      Glad you like it

  • @devrajdhiwar9028
    @devrajdhiwar9028 5 місяців тому +1

    Osmm video 🎉❤❤❤❤❤❤❤

    • @Ott3rly
      @Ott3rly  5 місяців тому

      Thanks 🤗

  • @munchlenova6353
    @munchlenova6353 5 місяців тому +1

    How to find what ruals in wfa was used in a website

    • @Ott3rly
      @Ott3rly  5 місяців тому +1

      You will never know. I've just shown how it looks from defensive side.

  • @overthinker1877
    @overthinker1877 5 місяців тому +1

    Any video about browser extension u are using rare one ?

    • @Ott3rly
      @Ott3rly  4 місяці тому +1

      Not sure if that need extra video, but I could answer in next Q/A.

  • @TrackinDaMeta
    @TrackinDaMeta Місяць тому

    I'd like to see one on wordfence

    • @Ott3rly
      @Ott3rly  Місяць тому

      That's too specific topic. I might work on that sometime, but not in the near future.

  • @Shapeshiftshow
    @Shapeshiftshow 5 місяців тому +1

    From where i can practice this bug bounty, i mean do you have any write ups?

    • @Ott3rly
      @Ott3rly  5 місяців тому +1

      Yes I do share a lot of tips and blog posts, check links on channel description.

    • @Shapeshiftshow
      @Shapeshiftshow 5 місяців тому

      @@Ott3rly thank you brother

    • @Shapeshiftshow
      @Shapeshiftshow 5 місяців тому

      @@Ott3rly I have another doubt, is there any vulnerability in code 503?

  • @KH-en1yr
    @KH-en1yr 4 місяці тому +1

    Auth Videos

  • @c_war
    @c_war 5 місяців тому +2

    Basically I'm lame in escape tag normally ">< this doesn't not work ;// I try this do i have to learn specific things in JavaScript to understand this

    • @Ott3rly
      @Ott3rly  5 місяців тому +2

      It's always about the context where your payload will end up. Practise makes it perfect!

  • @user-hb2rl4zn2m
    @user-hb2rl4zn2m 5 місяців тому +1

    Nice video brother ❤

    • @Ott3rly
      @Ott3rly  5 місяців тому

      Thanks ✌