Bug Bounty Explained! How Hackers Break Into Your Website Using Only JSON?! Protect Your Website!

แชร์
ฝัง
  • เผยแพร่เมื่อ 22 ม.ค. 2021
  • // Membership //
    Want to learn all about cyber-security and become an ethical hacker? Join this channel now to gain access into exclusive ethical hacking videos by clicking this link: / @loiliangyang
    // Courses //
    Full Ethical Hacking Course: www.udemy.com/course/full-web...
    Full Web Ethical Hacking Course: www.udemy.com/course/full-web...
    Full Mobile Hacking Course: www.udemy.com/course/full-mob...
    // Books //
    Kali Linux Hacking: amzn.to/3IUXaJv
    Linux Basics for Hackers: amzn.to/3EzRPV6
    The Ultimate Kali Linux Book: amzn.to/3m7cutD
    // Social Links //
    Website: www.loiliangyang.com
    Facebook: / loiliangyang
    Instagram: / loiliangyang
    LinkedIn: / loiliangyang
    // Disclaimer //
    Hacking without permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing so that we can protect ourselves against the real hackers.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 53

  • @LoiLiangYang
    @LoiLiangYang  3 ปีที่แล้ว +19

    Like, share and subscribe to learn all about cybersecurity!

    • @sialsialsial5101
      @sialsialsial5101 3 ปีที่แล้ว

      Please provide translate Mr because I'm from Indonesia and me bad to speak english

    • @sureshkumar-fk9ep
      @sureshkumar-fk9ep 3 ปีที่แล้ว

      Please make a video bug bounty full course

    • @otkennix
      @otkennix 3 ปีที่แล้ว

      Sir how can I join channel members on your channel??

    • @amazing7538
      @amazing7538 3 ปีที่แล้ว

      Full support

    • @charlesamakoye5750
      @charlesamakoye5750 3 ปีที่แล้ว

      Hello Sir, I'm unable to access some tutorials on your channel as they are members only. I've subscribed and clicked the link to join but still i can't access them. Kindly help, Thank you

  • @alliedeena1141
    @alliedeena1141 3 ปีที่แล้ว

    Great! Please make more tutorials like this...

  • @azxc2b569
    @azxc2b569 3 ปีที่แล้ว

    Thank you so much for such good tutorial. please I am in need to learn about rce and ssrf.

  • @LinuxSploitOfficial
    @LinuxSploitOfficial 3 ปีที่แล้ว +2

    Great Content, keep it up

  • @stefano6632
    @stefano6632 3 ปีที่แล้ว

    Great video!
    Could you also make a video on how to avoid spam filters? Thank you

  • @codingwithgyver1637
    @codingwithgyver1637 3 ปีที่แล้ว +1

    seems its like SQL injection and XSS but using in JSON. Amazing that you teach us this. THank you

    • @techchannel3107
      @techchannel3107 3 ปีที่แล้ว +1

      bro it is an XSS. JSON is the only verb on the web. actually, MOST of the websites haven't JSON vulnerability.

  • @antnio773
    @antnio773 3 ปีที่แล้ว +2

    Nice video! Some insights: XSS here has more impact if you could turn it into GET request. The way you are showing here doesn't do that much or doesn't have much impact, imho

    • @dingdong3021
      @dingdong3021 3 ปีที่แล้ว

      Its not about the impact hes showing

  • @eXfilPr4tik
    @eXfilPr4tik 3 ปีที่แล้ว

    Great content !

  • @puneetchauhan5495
    @puneetchauhan5495 3 ปีที่แล้ว

    Wow,great tuto...,

  • @devloupiz4587
    @devloupiz4587 3 ปีที่แล้ว +1

    Hello I think you could use a proxy switcher to switch to the burpsuite proxy , What do you think about it?

  • @realhomy
    @realhomy 3 ปีที่แล้ว

    Nice explanation

  • @febin2217
    @febin2217 3 ปีที่แล้ว +6

    Pro tip: Use foxyproxy to setup the burp proxy quickly..... 🙂

  • @hectorgutierrez6941
    @hectorgutierrez6941 3 ปีที่แล้ว

    That’s really true json they could get anything

  • @Demonking440
    @Demonking440 3 ปีที่แล้ว +1

    dude are you using attack on titan's soundtrack? :D

  • @Cyb3rBuddy
    @Cyb3rBuddy 3 ปีที่แล้ว +2

    Re-uploaded why? 🙄

  • @briannamutali6360
    @briannamutali6360 3 ปีที่แล้ว +4

    Hey.....some of your videos are written "join this channel to view members-only content"...How do I join?

    • @ankushkumar4347
      @ankushkumar4347 3 ปีที่แล้ว +4

      By paying certain amount of feed and this guy deserve that😊

  • @theviperidae
    @theviperidae 3 ปีที่แล้ว +2

    How do retrieve my own data which is deleted?
    Please make a Video.

  • @saurrav3801
    @saurrav3801 3 ปีที่แล้ว

    Bro after toggle security level to 5 ..is this possible to hack or it's just show it's highly secured

  • @sadnansakin7608
    @sadnansakin7608 2 ปีที่แล้ว

    cool

  • @Wildcamper01
    @Wildcamper01 3 ปีที่แล้ว

    How to install owasp mutillidae 11 in kali Linux please make a video

  • @batmangaming762
    @batmangaming762 3 ปีที่แล้ว +5

    Hey loi liang yang can you make tutorial deface website

  • @VivekKumar-ls6oe
    @VivekKumar-ls6oe 3 ปีที่แล้ว

    can you share the link in this platform because of that just GitHub repository open even only open photo pls guys share this link.

  • @husnainshahid238
    @husnainshahid238 3 ปีที่แล้ว +3

    Re uploaded 🤫🤐❤

    • @Mersal-uj5nh
      @Mersal-uj5nh 3 ปีที่แล้ว

      Why what happened, are something's removed from previously uploaded video?

  • @pow274
    @pow274 3 ปีที่แล้ว

    First With 95 others

  • @researchai8182
    @researchai8182 3 ปีที่แล้ว

    How do I see the rest of your video. ? Your channel doesn’t allowed

  • @antimatter6728
    @antimatter6728 3 ปีที่แล้ว

    Im confused how is this can be dangerous to other users? I saw you insert your payload everytime you make a request so that means the payload are not permanent inside the json right?

    • @matheusborges1290
      @matheusborges1290 2 ปีที่แล้ว

      There's a kind of xss named stored, that has persistance.

  • @hsardrake5373
    @hsardrake5373 3 ปีที่แล้ว

    If you had written document.body.style.display = "none" you would make the page to disappear

  • @deveshshah2571
    @deveshshah2571 3 ปีที่แล้ว +2

    This is like self xss, there is no security impact in this

    • @dorianvoka5591
      @dorianvoka5591 3 ปีที่แล้ว

      exactly, there ist litereally no company on bugbounty platforms that has self xss in scope, it is out of scope

    • @anishdhamala9233
      @anishdhamala9233 3 ปีที่แล้ว

      @@dorianvoka5591 you definetely missing some info.
      Go to hackerOne and search Fetlife in directory and read their policy

    • @dorianvoka5591
      @dorianvoka5591 3 ปีที่แล้ว

      @@anishdhamala9233 bruh fetlife, watch out for the outer 90000000 programs

  • @zigaudrey
    @zigaudrey 3 ปีที่แล้ว

    It look like it is only for website with login. My site will be an art gallery and no javascript, so it's okay.

  • @Ahmed95406
    @Ahmed95406 2 ปีที่แล้ว

    🤩🤩🤩

  • @aaraannjaan
    @aaraannjaan 3 ปีที่แล้ว

    Brother, this is cross site scripting itself know?

  • @javadhussain8518
    @javadhussain8518 3 ปีที่แล้ว

    How to reconnect hacked devices using Metasploit Framework?

    • @Tyler-ev7xq
      @Tyler-ev7xq 3 ปีที่แล้ว

      Persistent backdoor

  • @grandmakisses9973
    @grandmakisses9973 3 ปีที่แล้ว

    Use foxy proxy

  • @bala-st9cj
    @bala-st9cj 3 ปีที่แล้ว

    ANOTHER NAME IS XSS ATTACK

  • @udaywahi
    @udaywahi 3 ปีที่แล้ว

    First comment

  • @ruinwilliam4215
    @ruinwilliam4215 3 ปีที่แล้ว +1

    If you can add Chinese subtitles, I think there will be more audience

  • @smartcomputring1034
    @smartcomputring1034 3 ปีที่แล้ว

    jo kiyu indian video dekha ra he wo muje riply kare