BUG BOUNTY: BYPASSING WAF TO GET LFI (REAL TARGET) | 10K SPECIAL | 2023

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ธ.ค. 2024

ความคิดเห็น • 35

  • @mandikgoyal7740
    @mandikgoyal7740 ปีที่แล้ว +5

    Very Informative Videos Keep up the good work

  • @Th3-Noob-Audit0rs
    @Th3-Noob-Audit0rs ปีที่แล้ว +5

    ❤ hope your video's bypass TH-cam guidelines also

  • @FAHADKHATRI12
    @FAHADKHATRI12 ปีที่แล้ว +2

    This is valuable information!

  • @морс-ф3д
    @морс-ф3д ปีที่แล้ว

    Congratulation on you 10000 subs!!!) You deserve MORE!!!!

  • @zahiruddinahmad55
    @zahiruddinahmad55 ปีที่แล้ว +4

    Please make a video 403/404 bypass

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked ปีที่แล้ว

      Yeee. More of these would be awesome. Hehe. I know we can add hostname:3000, and some stuff like that.

  • @islamkafafy6984
    @islamkafafy6984 ปีที่แล้ว

    Wow Dude you are amazing keep uploading top tier videos more

  • @Fractal_reComm
    @Fractal_reComm 6 หลายเดือนก่อน

    Dude, I'm a big fan and I admire and inspire me, your work, I would like you to help me find simpler sites like this. Generally, my targets are very well protected, but it's possible to overcome them.
    them and this takes much more time than in simpler systems, I have little experience but I have already found some cool vulnerabilities,
    I still can't afford better education in cybersecurity, I would be very happy and I'm sure that the entire community that is also starting out would be very happy and would help a lot, thank you for everything, I hope you read it

  • @abduls4479
    @abduls4479 ปีที่แล้ว

    Awesome video.. thanks man

  • @Deepakkumar-pm2kt
    @Deepakkumar-pm2kt ปีที่แล้ว

    Loved the video man. Learnt a lot from how your explanations.

  • @loki__575
    @loki__575 8 หลายเดือนก่อน

    Great explanation bro. Many people teach if we want to check for such vulnerabilities we need to use payloads like ../../../../etc/passwd. However you shared another perspective - why to just try /etc/passwd, if we can check with other files within web root leading to source code reveal. Thanks for sharing this content

  • @peterp3273
    @peterp3273 16 วันที่ผ่านมา

    Hello friend, u can be my teacher,

  • @HunterX461
    @HunterX461 ปีที่แล้ว

    Congratulations bro for 10k fam ❤🎉Next milestone is of 50k subs😊

  • @akashpatel-bs8ve
    @akashpatel-bs8ve ปีที่แล้ว

    Nice information, jump to 4:00 to main content 👍

  • @imran_hossain123
    @imran_hossain123 ปีที่แล้ว

    Thanks from Bangladesh

  • @hamzaannane885
    @hamzaannane885 ปีที่แล้ว

    From 10k to 100k 🎉🎉🎉 one day

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked ปีที่แล้ว

    Early crew. :3

  • @hackingstudy-g5h
    @hackingstudy-g5h ปีที่แล้ว

    you amazing man, thanks for the effort, you really work hard to give us the best content, and we appreciate it.

  • @MRIDULSG
    @MRIDULSG ปีที่แล้ว

    I have a question regarding this. What I understand is in LFI, you can actually execute the files on the server. In this case, the index.php file shall show the output of the executed version of the index.php file instead of showing the source code. In directory traversal, we can see the content of the file. Please Correct me if I'm wrong.

    • @BePracticalTech
      @BePracticalTech  ปีที่แล้ว

      Actually in local file inclusion, you will be able to see the contents of files present on the server. However, there are certain scenarios where you'll be able to execute the files(like you mentioned) but it depends from target to target.
      The vulnerable endpoint here was actually serving the content of the pdf that's why we were able to get the content of source code.
      Hope you understood

  • @hamzaannane885
    @hamzaannane885 ปีที่แล้ว

    Keep going 🎉🎉🎉 u are the best

  • @mnoobb69
    @mnoobb69 4 หลายเดือนก่อน

    Where are you from bro?

  • @Be_Buddhaa
    @Be_Buddhaa ปีที่แล้ว

    How many programming languages do you know?😢

    • @BePracticalTech
      @BePracticalTech  ปีที่แล้ว

      I know few programming languages

    • @Be_Buddhaa
      @Be_Buddhaa ปีที่แล้ว

      @@BePracticalTech name please ?🥵🔥

  • @TechAmbition
    @TechAmbition 8 หลายเดือนก่อน

    Bro targeting real host
    *Only for educational purposes 😅

  • @tanvirmridha
    @tanvirmridha ปีที่แล้ว

    😮

  • @medamine6745
    @medamine6745 2 หลายเดือนก่อน

    you haven't bypass the WAF, did you get /etc/passwd ? nope !

  • @oswardgaming3223
    @oswardgaming3223 ปีที่แล้ว

    Bro i am new in bug hunting so suggest me the right path for bug hunting

    • @BePracticalTech
      @BePracticalTech  ปีที่แล้ว

      Join our telegram community: telegram.me/bepracticaltech