ความคิดเห็น •

  • @TinyMeatPete
    @TinyMeatPete 3 ปีที่แล้ว +107

    as a British man, hearing somone say "heres a nonce" in an excited voice is funny to me. Other than that, the video was great

  • @sk8erman069
    @sk8erman069 3 ปีที่แล้ว +35

    It’s great to see members of the info sec community work together to solve these complex problems. I’m excited to see more videos like this and can’t wait to see more on your new series on your binary exploitation journey!

  • @FennecTECH
    @FennecTECH 3 ปีที่แล้ว +11

    It just proves that security is **HARD**

  • @Owen-bk5fc
    @Owen-bk5fc 3 ปีที่แล้ว +26

    When you described how the XSS Auditor worked, I couldn't for the life of me figure out how someone thought that was a good idea. It seems so obviously exploitable.

  • @cat-.-
    @cat-.- 3 ปีที่แล้ว +39

    This really reminds me how web is a congo line of crazy features (XSS auditor) followed by lunatic legacy behaviours (clobbering) melting each other down lol

  • @fsacer
    @fsacer 4 ปีที่แล้ว +17

    I like the idea of the required concepts section 👌

  • @leftyyyyyyyy
    @leftyyyyyyyy 2 ปีที่แล้ว +4

    why does this channel have so little subscribers? This content deserves much more appreciation and recognition

  • @justadam3536
    @justadam3536 4 ปีที่แล้ว +2

    I love how your videos are so chill and nice to watch

  • @vic2734
    @vic2734 4 ปีที่แล้ว +4

    This content is amazing man! Keep it coming

  • @Omikoshi78
    @Omikoshi78 ปีที่แล้ว +3

    Knowing dom clobbering, xss auditor tricks, cross domain vectors, etc I could have solved this relatively quickly but I’ve also been in this field for a loong time. Since before there even were classes at uni teaching computer security. This was a insane challenge for anyone that didn’t encounter these techniques before.

  • @nitzan917
    @nitzan917 4 ปีที่แล้ว +2

    Very well made. Great job!

  • @Faraz9023
    @Faraz9023 4 ปีที่แล้ว

    Please upload more often! Love your videos!

  • @hupa1a
    @hupa1a ปีที่แล้ว +1

    Great video! So well explained!

  • @vistimalik2879
    @vistimalik2879 4 ปีที่แล้ว +5

    Very good video keep up the good work 👌😊

  • @KngSovereign
    @KngSovereign 2 ปีที่แล้ว +1

    1:20 - I am totally that one guy that just stumbled upon your videos randomly 😅

  • @user-ir4mm8zh7s
    @user-ir4mm8zh7s 4 ปีที่แล้ว +4

    I am curious more about how you made this awesome style of this tutor

  • @RickKotlarz
    @RickKotlarz 4 ปีที่แล้ว +2

    Greate explanation and video demo. You may want to update the video description to highlight these various attack techniques.

  • @FajarAmanullah
    @FajarAmanullah 4 ปีที่แล้ว

    Very good, easy to understanding

  • @harshjaiswal1245
    @harshjaiswal1245 4 ปีที่แล้ว +7

    Awesome stuff as always! :D

  • @ark3r745
    @ark3r745 4 ปีที่แล้ว +2

    hey bro hope you are doing right, can you do more tutorials on the other vulnerabilities and explain them like you use to do ? pls

  • @thehonestabe
    @thehonestabe 3 ปีที่แล้ว

    Underrated video!

  • @BlueFalconHD
    @BlueFalconHD 2 ปีที่แล้ว

    hey @PwnFunction, what paint/drawing software do you use, and what editing software?

  • @imlautaro123
    @imlautaro123 3 ปีที่แล้ว

    just amazing!

  • @asafcohen3562
    @asafcohen3562 4 ปีที่แล้ว

    Fantastic video

  • @REBL0X3RSCREW
    @REBL0X3RSCREW 3 ปีที่แล้ว

    Lmao first I thought you were liveoverflow cause of the Video Styling and Voice🤣

  • @lcark6596
    @lcark6596 4 ปีที่แล้ว

    Good Job! man.

  • @DarkSet112
    @DarkSet112 2 ปีที่แล้ว

    Which program you use to make a drawing during the video?

  • @HimitsuYami
    @HimitsuYami 2 ปีที่แล้ว

    Hi, random person who just stumbled upon your video here so I have no clue what's going on but it sure is interesting to me lol

  • @FluffyFoxUwU
    @FluffyFoxUwU 2 ปีที่แล้ว

    I love this penguin guy

  • @mthaha2735
    @mthaha2735 3 ปีที่แล้ว

    very deep stuff. nice hoping for more videos like this

  • @Joe_Payne
    @Joe_Payne 2 ปีที่แล้ว +3

    I'm that one person who doesn't know who live overflow is who stumbled apon one of your videos

    • @PwnFunction
      @PwnFunction 2 ปีที่แล้ว +1

      You are a rare one.

  • @user-zt1hx3ci2v
    @user-zt1hx3ci2v 4 ปีที่แล้ว +1

    Great videos! Do you planning to make more?

    • @PwnFunction
      @PwnFunction 4 ปีที่แล้ว +4

      Yes, I'll get back in a week.

  • @SylwesterKogowski
    @SylwesterKogowski 3 ปีที่แล้ว

    Nice thinking ;)

  • @johnswanson217
    @johnswanson217 ปีที่แล้ว +1

    I'm really enjoying your content!
    But your audio is kind of confusing on headsets.
    Your voiceover volume is shifting Left and Right continuously.
    I highly recommend using mono audio for your voiceovers.

  • @DivijHere
    @DivijHere 2 ปีที่แล้ว +1

    98.9K? 100K SOON!!!!

  • @yes-or1md
    @yes-or1md 3 ปีที่แล้ว +1

    It sounds like you are planning a heist or something

  • @wolfrust0
    @wolfrust0 2 ปีที่แล้ว +1

    17:21 recapcha and recapcha

  • @Cookieukw
    @Cookieukw 3 ปีที่แล้ว +1

    muito bom

  • @vasiovasio
    @vasiovasio 3 ปีที่แล้ว

    Good luck with HTTP Only Cookies!

  • @fred-youtube
    @fred-youtube 3 ปีที่แล้ว

    Why did your voice change at 2:54

  • @mukto2004
    @mukto2004 3 ปีที่แล้ว

    whats the name of the editor liveoverflow using ?

  • @youtuber-tc8yk
    @youtuber-tc8yk ปีที่แล้ว

    Excellent content. To get subscribers over million, you should try to make video every 1 month, at least.
    BTW please let me know what theme do you use in vscode? It looks crazy!

  • @vaibhavgavas4691
    @vaibhavgavas4691 4 ปีที่แล้ว +2

    #request
    SSRF (bypass filters and firewall)

  • @expandingsalad786
    @expandingsalad786 4 ปีที่แล้ว +6

    Can you please turn your handwriting into a font?

    • @PwnFunction
      @PwnFunction 4 ปีที่แล้ว +8

      ✅Added to my TodoList.

    • @ZephyrysBaum
      @ZephyrysBaum ปีที่แล้ว +1

      @@PwnFunction Is it done?

  • @GnomeEU
    @GnomeEU 2 ปีที่แล้ว +2

    This looks like another example where a strong typed language would solve all problems.
    Dynamic typed language (eg JS) = bad?

  • @madghostek3026
    @madghostek3026 4 ปีที่แล้ว +4

    Hm I don't quite get it, first the url removes the CONFIG variable, and then the stepone() is called, what called it?

    • @PwnFunction
      @PwnFunction 4 ปีที่แล้ว +4

      You mean the `stageOne()`?
      It's called right after the is loaded, you can see the last line of code @ 20:11 , `onload=stageOne(this)`

    • @madghostek3026
      @madghostek3026 4 ปีที่แล้ว +1

      @@PwnFunction Ah I didn't notice the onload in the , now it makes sense thanks

  • @clientdns1747
    @clientdns1747 2 ปีที่แล้ว +1

    this accent is like a german dude

  • @asafcohen3562
    @asafcohen3562 4 ปีที่แล้ว

    I love ya shit

  • @LoganLatios
    @LoganLatios 2 ปีที่แล้ว

    8:53 in robloc

  • @crawbug8932
    @crawbug8932 ปีที่แล้ว

    4:26 bruh, use the "fold all" command

  • @MechanicalMooCow
    @MechanicalMooCow 2 ปีที่แล้ว

    Your accents makes me want to throttle a small puppy until it begins squeaking

  • @notinsane
    @notinsane 3 ปีที่แล้ว

    NOOOO ME COOKIES!!!!!1!1

  • @_livep
    @_livep 4 ปีที่แล้ว +1

    Who else saw the stream?

  • @mikolajkozakiewicz1070
    @mikolajkozakiewicz1070 3 ปีที่แล้ว +2

    : wow

  • @matthewrease2376
    @matthewrease2376 2 ปีที่แล้ว

    Still not entirely sure how this lets you get *someone else's* cookie...?

    • @nikkiofthevalley
      @nikkiofthevalley 2 ปีที่แล้ว

      If someone else accesses a public page with an XSS on it, they will also trigger the XSS. You can then access the cookies through some method, and then send those off to a website you control that logs the cookies somewhere. I haven't watched the full video, so this probably won't be the exact method used, but this is the general principle of how you do that.

  • @supershadowevil
    @supershadowevil 2 ปีที่แล้ว

    i am that one person hello

  • @EnitinEnitin
    @EnitinEnitin 3 ปีที่แล้ว +1

    This video made me hate the letter "P".

    • @gruanger
      @gruanger 2 ปีที่แล้ว

      And B...

  • @slendi9623
    @slendi9623 4 ปีที่แล้ว +3

    F xss auditor

  • @Jowanoofy_ZO
    @Jowanoofy_ZO ปีที่แล้ว

    My brain: watching dis nonsense.
    My other brain thinking: *thinking of if i take interest in codes by watching all if dis guy video codes i can become agenius familliar with codes in years later before going bankrupt and going genius*