Це відео не доступне.
Перепрошуємо.

This FFUF secret trick everybody need to know | Bug hunting poc

Поділитися
Вставка
  • Опубліковано 28 чер 2024
  • // Disclaimer //
    Hacking without permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing & bug hunting so that we can protect ourselves against the real hackers..

КОМЕНТАРІ • 256

  • @ChaRambo
    @ChaRambo Місяць тому +5

    I love when i open youtube and see a new upload from Lostsec in my notifications!

    • @lostsecc
      @lostsecc  Місяць тому

      ☺️🙈❤️🫂

  • @mylosovich24
    @mylosovich24 День тому +1

    Hey Coffin, nice Fuff stuffs! Sending mental fist bumps

  • @madhavanrio3210
    @madhavanrio3210 Місяць тому +10

    Bro gta 5 fan 😂

  • @Raduim
    @Raduim Місяць тому +1

    Congratulations for 10k buddy 💗🎉

    • @lostsecc
      @lostsecc  Місяць тому +1

      thnq brother ❤️🤗

  • @hatemaliyan3933
    @hatemaliyan3933 Місяць тому +1

    Great content 🎉, can you please do video for methodology when u find login pages how u work with that... Thank you 🙏

  • @Ajay_Yadav_Smart
    @Ajay_Yadav_Smart Місяць тому +3

    I was waiting for this video..
    Thanks bro..❤❤

  • @aftabsaifi2436
    @aftabsaifi2436 Місяць тому +1

    Can you please add caption according to video in your next videos.. this may help a lots of begginers

  • @user-qt6md8nh6h
    @user-qt6md8nh6h Місяць тому +1

    Bro, for bug bounty i need to learn the entire javascript , which are the parts i have to learning if anything I'm missing or extra please add it.
    Thanks a lot for sharing u're knowledge to the community god bless you❤

  • @ShermaMahdi
    @ShermaMahdi Місяць тому +1

    You de Man Mate🔥🔥🔥🔥🔥🥰🥰 U deserve Million Likes Bro💯💯💯💯

    • @lostsecc
      @lostsecc  Місяць тому +1

      🙈❤️😇

    • @ShermaMahdi
      @ShermaMahdi Місяць тому +1

      @@lostsecc Wana Say Love U man💯 Your Xss Payload Worked for me mate. Waiting the outcome of my first H1 report. Your magic Works Bro♥️♥️♥️

  • @anatomygamer1129
    @anatomygamer1129 Місяць тому +2

    Hey brother can you please share a xss pdf ?

    • @lostsecc
      @lostsecc  Місяць тому

      i shared in my telegram channel bro

  • @ilixymx
    @ilixymx Місяць тому +1

    Hell Nah!!! . Bro got a official song too 💀💀

  • @TSTpodcasts
    @TSTpodcasts 15 днів тому

    What if the passwords shown are salted? How can you be sure they are real password? can we decrypt them or try logging in with them?
    Great work bro. Learning so much from you!

    • @lostsecc
      @lostsecc  15 днів тому

      use johntheripper tool with rockyou list

  • @cameronribeiro9660
    @cameronribeiro9660 Місяць тому

    I know this is off topic: but to everyone running wsl2 in windows: I was able to install run Ubuntu 24.04 wsl2 on W11 bare metal host (the only way it works) but Kali wsl2 didn’t want to install: but: Any of you tried Running latest Ubuntu as your host and a kali VM inside virtualbox? That is where I have had the best luck. Was just wondering anyone else’s experience.

  • @namangupta681
    @namangupta681 Місяць тому +1

    same url but when i give -mr for matching regex it wont give me anything!! where when I remove -c -mr "root:", it brings me result and then I have to filter it with size:1226.
    why not working with -mr???????

    • @lostsecc
      @lostsecc  Місяць тому

      make sure you have installed all tools used in this oneliner

    • @namangupta681
      @namangupta681 Місяць тому

      @@lostsecc i have all the tools gf , waybackurls.. this ffuf cmd don't show anything with -c -mr without it its working

    • @namangupta681
      @namangupta681 Місяць тому +1

      @@lostsecc why this -mr is not working i have followed same process and checked it 4 5 times still -mr not working

    • @lostsecc
      @lostsecc  Місяць тому

      send me screenshot in telegram

    • @namangupta681
      @namangupta681 Місяць тому

      Please check dm

  • @IBO.ATTACKS
    @IBO.ATTACKS Місяць тому

    عنجد بحب طؤيقتك بالشغل
    you are great bro 😎

    • @lostsecc
      @lostsecc  Місяць тому

      thnx man ❤️☺️

  • @endless2333
    @endless2333 Місяць тому

    you could use burp intruder for this attack? Just wondering. Congrats on 10k!

    • @lostsecc
      @lostsecc  Місяць тому +1

      yes u can but ffuf is so fastt and some more cool features

  • @MuhammedEmirARSLAN01
    @MuhammedEmirARSLAN01 Місяць тому +1

    Yo man why you still rockin' Burp 1.7.13? Got a special reason or you just old school like that?... xD

    • @lostsecc
      @lostsecc  Місяць тому +1

      its light weight and dont freez like latest burpsuite memory full problems ...

  • @P45PU7
    @P45PU7 Місяць тому +1

    on my linux gf command not found, how do I do it? 🤥

    • @lostsecc
      @lostsecc  Місяць тому

      you need to install gf pattren

  • @Anon-0xrobot
    @Anon-0xrobot Місяць тому

    I am following you. Good luck, my friend❤

  • @samhansen-dev
    @samhansen-dev Місяць тому

    I like the image you have for the background of your terminal.Please share the link😅

  • @3bbodal-obaidi602
    @3bbodal-obaidi602 Місяць тому +1

    I don't understand ;-;
    gf: command not found
    urldedupe: command not found
    waybackurls: command not found

    • @lostsecc
      @lostsecc  Місяць тому

      you need to install all these commands

  • @IllIIIIIIllll
    @IllIIIIIIllll Місяць тому

    But what was in the response? I didn't understand.

  • @thiagopereira8800
    @thiagopereira8800 Місяць тому

    Hey man, great content!! :) quick question, is ffuf better than intruder to test for lfi, etc?

    • @lostsecc
      @lostsecc  Місяць тому

      yes it has very high speed threads mode+regex

    • @thiagopereira8800
      @thiagopereira8800 Місяць тому

      @@lostsecc got it, will give a chance here! Thanks

  • @user-nj8fi2ix8i
    @user-nj8fi2ix8i Місяць тому

    Hello Brother I got this error whenever i tried to install GF tool i tried every method still i can't get solution
    fatal: not a git repository (or any of the parent directories): .git

    • @lostsecc
      @lostsecc  Місяць тому

      dm me in telegram give anydesk id

    • @user-nj8fi2ix8i
      @user-nj8fi2ix8i Місяць тому

      @@lostsecc Yes i did kindly check your DM

  • @Voiceee-ix8zn
    @Voiceee-ix8zn Місяць тому +1

    alert("1")

    • @Voiceee-ix8zn
      @Voiceee-ix8zn Місяць тому +1

      see the above comment is not filtered in the source why doesn't it run?

    • @lostsecc
      @lostsecc  Місяць тому

      bcz of csp and all other protection and server side encoding..

  • @doshamiheh9800
    @doshamiheh9800 16 днів тому

    how do you set a background image and logo on your terminal please coffin?

    • @lostsecc
      @lostsecc  16 днів тому

      its option in window terminal download it from microsoft store

    • @doshamiheh9800
      @doshamiheh9800 16 днів тому

      @@lostsecc Okay i did that , but when i duplicate the tab , the background dissapears :( and show another terminal not the usual one

  • @dinethrahewage5869
    @dinethrahewage5869 Місяць тому

    Hey, Mate. How did you install URLdedupe on Windows 11???

    • @lostsecc
      @lostsecc  Місяць тому

      just paste binary in /usr/local/bin

  • @mrfadel4790
    @mrfadel4790 Місяць тому +1

    we need more from you...❤❤

  • @NethaxStark
    @NethaxStark Місяць тому

    We can't use this trick for other attacks like the xss by changing the payload list Am I right?

    • @lostsecc
      @lostsecc  Місяць тому

      you can try ssti by regex 49

    • @NethaxStark
      @NethaxStark Місяць тому

      @@lostsecc ok I am new please please could you elaborate it!

  • @timovc5340
    @timovc5340 28 днів тому

    can i somehow configure ffuf so it doesnt show stuff like ././././../../etc/passwd instead of just ../../etc/passwd? I mean it's the same after all

    • @lostsecc
      @lostsecc  28 днів тому +1

      just add normal lfi payload list

  • @rishabhrana3773
    @rishabhrana3773 Місяць тому

    Bro how you check fod xss in multiple fields in one go can you tell please

    • @lostsecc
      @lostsecc  Місяць тому

      use intruder there is many options like pitchfork etc

    • @rishabhrana3773
      @rishabhrana3773 Місяць тому

      @lostsecc can i use it at same on different location

  • @someyounggamer
    @someyounggamer Місяць тому

    Congrats on 10k subs.

    • @lostsecc
      @lostsecc  Місяць тому

      thnq bro ❤️🤗

  • @Sidharthas89
    @Sidharthas89 Місяць тому

    Awesome brother ❤❤❤
    Where can I get this awesome lfi payloads.
    You have set your wallpaper kali .

    • @lostsecc
      @lostsecc  Місяць тому

      i shared in telegram bro

  • @H4cker_Nafeed
    @H4cker_Nafeed Місяць тому

    What tool do you use for this ? And what is the purpose of using FUFF in the parameter ? And does it work only in php based endpoints? By doing this WAF don't block us ?

    • @lostsecc
      @lostsecc  Місяць тому +1

      its work in all post and get param

  • @TheWahb123
    @TheWahb123 Місяць тому

    How do you bypass waf when dirbusting with ffuf or wfuzz ?

    • @lostsecc
      @lostsecc  Місяць тому +1

      change the ffuf default user-agent

  • @Pal0vieeee
    @Pal0vieeee Місяць тому

    Osmmm || ur content nd background music 😁🥳❣️

    • @lostsecc
      @lostsecc  Місяць тому +1

      thnq ji 🤗❤️

    • @NethaxStark
      @NethaxStark Місяць тому

      @@lostsecc indian bolte

  • @SevenHeavenlyig
    @SevenHeavenlyig 13 днів тому

    Can you please share the wordlist which u used first ?

    • @lostsecc
      @lostsecc  12 днів тому

      i shared in my github

    • @SevenHeavenlyig
      @SevenHeavenlyig 12 днів тому

      @@lostsecc bro your GitHub is not showing up in the index search. It shows 404 error

  • @NethaxStark
    @NethaxStark Місяць тому +1

    Song name?

  • @EnLopXf
    @EnLopXf Місяць тому

    I'm waiting on demonstration of web defacement

  • @d4rk_s4mur41
    @d4rk_s4mur41 Місяць тому

    Hi, amazing work bro! Where did you get wordlist? Can you share the link to this wordlist and other wordlists if you can

    • @lostsecc
      @lostsecc  Місяць тому

      i shared in telegram bro

  • @jht8909
    @jht8909 Місяць тому

    love watching the vids, this one was awesome 👍

    • @lostsecc
      @lostsecc  Місяць тому

      thanks mate ❤️

  • @Impaler_XV
    @Impaler_XV Місяць тому

    bro i’m dumb ngl so i might be asking sum stupid but is it possible to change the screen res of an iphone 13 on ios 18 ??

    • @lostsecc
      @lostsecc  Місяць тому

      bro i never tried it so no idea

    • @Impaler_XV
      @Impaler_XV Місяць тому

      @@lostsecc i thought maybe if restoring a modified backup on your pc you might be able to change the screen res inside it but maybe apple has security measures to not let that happen? if you have time i’ll genuinely give you a 20$ visa gift card to help me find a way to do it on ios 18 beta 2, i’ll pay you first too as long as you show me that it works bro

  • @user-ne8zp2by6u
    @user-ne8zp2by6u Місяць тому +1

    How to you install gta 5 without virus free bro?

    • @lostsecc
      @lostsecc  Місяць тому

      i download from epicgames offical site

  • @tomiwafalade5480
    @tomiwafalade5480 Місяць тому +5

    First!!

  • @user-ro8th6xt9c
    @user-ro8th6xt9c Місяць тому

    why u use old version of burp?

    • @lostsecc
      @lostsecc  Місяць тому

      latest burp consume lots if ram and hangs..old one is ligh weight and give good results..

  • @charlie-he9ft
    @charlie-he9ft 9 днів тому

    How u find theese targets.

  • @RajanChoudhary12
    @RajanChoudhary12 Місяць тому

    We are Kings Brother. I am King you are King. Bhai Bhai

  • @fanky2696
    @fanky2696 Місяць тому

    the type of vuln is path traversal ??

  • @BMV-kl1br
    @BMV-kl1br Місяць тому

    brother why u using old burp suite

    • @lostsecc
      @lostsecc  Місяць тому

      its light weight in latsst burp its consume lots of ram and hangs alot also it has spider feature that will help u more

  • @exotic2032
    @exotic2032 Місяць тому

    Bro can you make video in website info gathering and enumeration how professional get deeper information about website like subdomain endpoint directories present vulnerabilitys

  • @srinaths6855
    @srinaths6855 26 днів тому

    hi bro could share the yours payloads ... that will be help full to us

  • @aatankbadboy3941
    @aatankbadboy3941 Місяць тому

    Bro what happened when we got this etc/passwd file and what's name of this vulnerability

    • @lostsecc
      @lostsecc  Місяць тому +1

      LFI directory traversal

  • @Voiceee-ix8zn
    @Voiceee-ix8zn Місяць тому

    Do you have your github?
    I need XSS payloads

    • @lostsecc
      @lostsecc  Місяць тому

      github.com/coffinxp/payloads

    • @Voiceee-ix8zn
      @Voiceee-ix8zn Місяць тому

      @@lostsecc How did you make so many LFI payloads 💀💀💀

  • @akroidofficial
    @akroidofficial Місяць тому

    what about in modern webs like MEAN, MERN ?

    • @lostsecc
      @lostsecc  Місяць тому

      you can try must change default user agent before ffuf command

  • @wave-bomber
    @wave-bomber Місяць тому

    How do you maks this colorized shell??? 💀💀💀

    • @lostsecc
      @lostsecc  Місяць тому

      install window terminal with kali wsl2

    • @wave-bomber
      @wave-bomber Місяць тому

      @@lostsecc im asking for this spacific style with this spacific image. Its a default?

    • @lostsecc
      @lostsecc  Місяць тому

      you need to change walpaper from its setting

  • @BiFr0ost
    @BiFr0ost 8 днів тому

    can u share the list of the payloads pls?

    • @lostsecc
      @lostsecc  8 днів тому +1

      i shared in telegram and github

    • @BiFr0ost
      @BiFr0ost 8 днів тому

      @@lostsecc ur github account looks like is block :(

  • @cameronribeiro9660
    @cameronribeiro9660 Місяць тому

    Also: I actually thought you were Russian. I’m thinking from India though cause everyone from India seems to be running wsl2 in W.

    • @lostsecc
      @lostsecc  Місяць тому

      wsl2 is lit..no faced any problem till now

  • @0xazyz897
    @0xazyz897 Місяць тому

    i like your channel , but bro be careful , what you're doing is illegal because you're live hacking real targets and uploading it to UA-cam , also the vulnerabilities that you are demonstrating are not patched yet , i tested it and it worked , Keep going my G and Be aware 😉

    • @lostsecc
      @lostsecc  Місяць тому

      dont worry bro people want to watch real targets testing not labs

    • @fahadismail7430
      @fahadismail7430 Місяць тому

      you're absolutely right bro.. keep doing it ...I personally love real life

  • @RajanChoudhary12
    @RajanChoudhary12 Місяць тому

    But i really saw you after a lot of time

  • @mistDexploit
    @mistDexploit Місяць тому

    bro finilly I found your play list in telegram Channel 😂🤝

  • @tlcmajed967
    @tlcmajed967 Місяць тому

    Wich version of burp do you use and why dont use last version ?

    • @lostsecc
      @lostsecc  Місяць тому

      latest burp consume lots of memory and hangs so i used old one its give better results and spider feature

    • @tlcmajed967
      @tlcmajed967 Місяць тому

      @@lostsecc can u give me number of version pls ?

    • @lostsecc
      @lostsecc  Місяць тому +1

      i shared in my github check out

    • @tlcmajed967
      @tlcmajed967 Місяць тому

      @@lostsecc thx bro ❤️❤️

  • @jkai_8
    @jkai_8 Місяць тому

    where can i get the lf1 payload

    • @lostsecc
      @lostsecc  Місяць тому +1

      i shared in telegram

    • @jkai_8
      @jkai_8 Місяць тому

      @@lostsecc whats your telegram

    • @jkai_8
      @jkai_8 Місяць тому

      @@lostsecc found it and joined your telegram thanks so much

  • @vikasnaval3190
    @vikasnaval3190 Місяць тому

    Fantastic as always 😍

    • @lostsecc
      @lostsecc  Місяць тому

      thnx mate ❤️

  • @HackerBuvi
    @HackerBuvi Місяць тому

    first commends in lfi what file and i will try but error: no such pattern

    • @lostsecc
      @lostsecc  Місяць тому +1

      you need to install gf pattren

    • @HackerBuvi
      @HackerBuvi Місяць тому

      @@lostsecc thankyou bro

  • @apple_00
    @apple_00 Місяць тому

    بژی شیرە کور

  • @kingmanxx4883
    @kingmanxx4883 Місяць тому

    Whay use ffuf? , bro use jast intruder in burp

    • @lostsecc
      @lostsecc  Місяць тому +1

      intruder dont do much this much fast and not all have burp pro

  • @histoire-de-blackhat3346
    @histoire-de-blackhat3346 Місяць тому

    in description

    • @lostsecc
      @lostsecc  Місяць тому

      check telegram bro

  • @lilrucky2766
    @lilrucky2766 Місяць тому

    bro what's the appliaton u write codes on?

    • @lostsecc
      @lostsecc  Місяць тому +1

      window terminal wsl2 kali

  • @kartik_exe_
    @kartik_exe_ Місяць тому

    hey bro you still remeber me? and nice you upgraded to windows 11 and bro i want to ask whats ur age and u from where?

  • @Ba1X1aoTao
    @Ba1X1aoTao 12 днів тому

    Very helpful❤

  • @cyber_india
    @cyber_india Місяць тому

    Which worldlist you used?

    • @lostsecc
      @lostsecc  Місяць тому +1

      i will share in telegram

  • @learn7352
    @learn7352 Місяць тому

    Song title bro? I felt excited when I heard it

    • @lostsecc
      @lostsecc  Місяць тому +1

      dark beach slowed

  • @histoire-de-blackhat3346
    @histoire-de-blackhat3346 Місяць тому

    show all command that you do

  • @thehoffgamming7752
    @thehoffgamming7752 Місяць тому

    No talk, no write. Just moving cursor. Wow

  • @cyberx14
    @cyberx14 Місяць тому

    Hey Great Content Can I Get that lFI payloads file?

    • @lostsecc
      @lostsecc  Місяць тому +1

      i shared in telegram channel must check

    • @studyrelaxwithme4564
      @studyrelaxwithme4564 Місяць тому

      I can't find It in your telegram channel

  • @ashishchauhan9745
    @ashishchauhan9745 Місяць тому

    background sound name

  • @sarthakshrivastava6602
    @sarthakshrivastava6602 Місяць тому

    Which terminal are you using

    • @lostsecc
      @lostsecc  Місяць тому

      window terminal wsl2 kali

  • @bakibakikumin7965
    @bakibakikumin7965 Місяць тому

    can you share wordlist brother?

  • @QXJlIHlvdSBibGluZD8
    @QXJlIHlvdSBibGluZD8 Місяць тому

    Awesome video bro!
    Keen to understand how you got the first command when piped to acknowledge
    | gf lfi | urldedupe
    I have waybackurls working but i am not sure how to get gf to see the lfi payload

    • @lostsecc
      @lostsecc  Місяць тому +1

      you need to install gf and its pattren i shared in telegram

  • @madhavanrio3210
    @madhavanrio3210 Місяць тому

    Sir it possible on random urls or only php pages

  • @srikanth4326
    @srikanth4326 Місяць тому

    What is the terminal u are using ? How to get it

    • @lostsecc
      @lostsecc  Місяць тому

      its window terminal with wsl2 kali you can install it from microsoft store

    • @srikanth4326
      @srikanth4326 Місяць тому

      ​@@lostsecc thank you 👍 ....

  • @Cyber_rick087
    @Cyber_rick087 26 днів тому

    Hey bro can you share your payload txt file ??

  • @Booom1444-_-
    @Booom1444-_- Місяць тому

    where can i get that payload?

    • @lostsecc
      @lostsecc  Місяць тому

      i will share in telegram

  • @nlegendgaming8324
    @nlegendgaming8324 Місяць тому

    Please give us some new nuclei-templates 🙈 (your private templates ) 🌚

  • @footballisfun7858
    @footballisfun7858 Місяць тому

    Bro, you are a genius 😂

  • @CircularArc
    @CircularArc Місяць тому

    Yo bro can you make a video on how to start bug hunting

  • @BEESCO-BB
    @BEESCO-BB Місяць тому

    Bro It was very hard 😂😂

  • @fdl11
    @fdl11 Місяць тому

    Can i have lfi payload?

    • @lostsecc
      @lostsecc  Місяць тому

      i shared in telegram channel

  • @jkai_8
    @jkai_8 Місяць тому

    very nice video

  • @Roufinyt0
    @Roufinyt0 Місяць тому

    Bros os is windows and kali mixed😅

    • @lostsecc
      @lostsecc  Місяць тому

      😎

    • @Roufinyt0
      @Roufinyt0 Місяць тому

      @@lostsecc how do you do that that would be really helpful

    • @lostsecc
      @lostsecc  Місяць тому

      wsl2 kali

  • @shycat-yq5ij
    @shycat-yq5ij Місяць тому

    Keep it up bro

  • @paktiko1986
    @paktiko1986 Місяць тому

    amazing, Brother

    • @lostsecc
      @lostsecc  Місяць тому

      thnq brother ❤️😇

  • @tomiwafalade5480
    @tomiwafalade5480 Місяць тому

    Love you bro!!!

    • @lostsecc
      @lostsecc  Місяць тому

      love you three bro ❤️

  • @__CJ.__
    @__CJ.__ Місяць тому

    crazy bro ❤💯🖐

  • @garrinormanivannacov370
    @garrinormanivannacov370 Місяць тому

    amazing bro!

  • @yahai_
    @yahai_ Місяць тому +1

    ❤❤

  • @mrwaahmed9897
    @mrwaahmed9897 Місяць тому

    but this is illegal !!

  • @hema_gaming786
    @hema_gaming786 Місяць тому

    I want word list lfi

    • @lostsecc
      @lostsecc  Місяць тому +1

      check telegram

    • @hema_gaming786
      @hema_gaming786 Місяць тому

      Pro, I searched your telegram and found it, but searching on xss payloads I did not see it

    • @bugde3415
      @bugde3415 17 днів тому

      @@lostsecc Hey bro,That word list has been deleted

    • @bugde3415
      @bugde3415 17 днів тому

      @@lostsecc OK, I found it

  • @spramoda_8979
    @spramoda_8979 Місяць тому +1

    Broo❤❤

  • @a-man2468
    @a-man2468 Місяць тому

    someone stole my comment luv u bro

    • @lostsecc
      @lostsecc  Місяць тому

      love u three bro 🤗❤️