Exploiting an RPO attack on Firefox | Filedescriptor solves Intigriti's XSS challenge

แชร์
ฝัง
  • เผยแพร่เมื่อ 11 ก.ย. 2024
  • In this video Filedescriptor walks through how to solve Intigriti's May's XSS challenge with an RPO attack on Firefox.
    Intigriti's XSS challenge: challenge.inti...
    A few RPO exploitation techniques: www.mbsd.jp/Wh...
    RPO Gadgets: blog.innerht.m...
    Support us: www.buymeacoff...

ความคิดเห็น • 30

  • @TomNomNomDotCom
    @TomNomNomDotCom 4 ปีที่แล้ว +40

    Very well explained. Fantastic video, thank you :)

    • @josephnimsara3169
      @josephnimsara3169 4 ปีที่แล้ว +1

      hey tomnomnom can you also video like this

    • @zmbd-push-upskamunapaolulx9018
      @zmbd-push-upskamunapaolulx9018 4 ปีที่แล้ว +1

      I think he can, cuz I saw stok and him solving a XSS in hackerone

    • @aaravclark3968
      @aaravclark3968 3 ปีที่แล้ว

      I guess Im asking the wrong place but does anybody know a trick to log back into an instagram account..?
      I stupidly forgot the account password. I appreciate any help you can give me!

    • @daxeric9193
      @daxeric9193 3 ปีที่แล้ว

      @Aarav Clark Instablaster ;)

    • @aaravclark3968
      @aaravclark3968 3 ปีที่แล้ว

      @Dax Eric I really appreciate your reply. I found the site on google and im waiting for the hacking stuff now.
      Seems to take a while so I will get back to you later when my account password hopefully is recovered.

  • @bourbon3406
    @bourbon3406 4 ปีที่แล้ว +2

    Loved the video! Thanks. Expecting more great stuff.

  • @domaincontroller
    @domaincontroller 3 ปีที่แล้ว +1

    00:17 CSS injection 00:26 Firefox only 00:48 source 00:54 sink, innerHTML 01:10 DOM XSS 01:22 widgets.js 03:06 open redirecter 05:07 relative path overwrite

  • @payloadartist
    @payloadartist 4 ปีที่แล้ว +1

    Thanks. Hard a hard time doing this challenge. Much clearer now.

  • @PL-hk7dt
    @PL-hk7dt 4 ปีที่แล้ว +1

    Damn that was good, thank you, hope you will do more of these

  • @stackoverflow2155
    @stackoverflow2155 3 ปีที่แล้ว

    Holy cow!! This is so cool.

  • @reda4632
    @reda4632 4 ปีที่แล้ว +1

    OMG , this so good , thanks for sharing

  • @ichhasserosen664
    @ichhasserosen664 4 ปีที่แล้ว

    Fantastic! Thanks for the video!

  • @jaibajpai6370
    @jaibajpai6370 4 ปีที่แล้ว

    Great explanation

  • @bsysop
    @bsysop 4 ปีที่แล้ว

    Very nice video!.

  • @netbin
    @netbin 4 ปีที่แล้ว

    I am ONLY subscribing to this channel, because Stok recommend me to do so. I hope you not gonna fail it!

  • @neoXXquick
    @neoXXquick 4 ปีที่แล้ว

    amazing...

  • @viralkingdom3711
    @viralkingdom3711 4 ปีที่แล้ว

    tnx bro we need more video tnx

  • @sairam-lj6zu
    @sairam-lj6zu 4 ปีที่แล้ว

    Great video. So all the websites which are using relative path is vulnerable ?
    The //technique behaviour is specific to the challenge ?
    Thanks

    • @reconless
      @reconless  4 ปีที่แล้ว +2

      The // is a misconfiguration on the server that results in open redirects. Here an example real-world case: hackerone.com/reports/52035.

  • @nextlevel4189
    @nextlevel4189 4 ปีที่แล้ว

    My favorite hacker ❤️

  • @kab3800
    @kab3800 4 ปีที่แล้ว

    How can we redirect to a manually created webpage? do we have to use WAMP server for it? Eg. create an html page for redirection (evil.com) which will execute our XSS payload?

    • @reconless
      @reconless  4 ปีที่แล้ว +1

      You can abuse the // open-redirect vulnerability on the Intigriti challenge website. You have to chain that open redirect to achieve XSS.

  • @gopikrishnac5958
    @gopikrishnac5958 4 ปีที่แล้ว

    Hi, how can i access intigriti may month challenge??

    • @reconless
      @reconless  4 ปีที่แล้ว

      Intigriti will make an archive for past challenges. Right now unfortunately you can't :(

  • @eldricksaw2
    @eldricksaw2 4 ปีที่แล้ว

    Hi @filedescriptor, I've recently been scammed by online cryptocurrency exchange with a huge amount. The website seems to be from HK. Do you think you can help me? Singapore police force is not pursuing further investigation due to cryptocurrency being out of MAS jurisdiction. Please let me know, and would appreciate greatly any help you can provide. Thank you.