XXE Injection to Database Takeover | CVE-2021-29447 | RCE |

แชร์
ฝัง
  • เผยแพร่เมื่อ 17 ม.ค. 2025

ความคิดเห็น • 27

  • @et2931
    @et2931 2 ปีที่แล้ว

    Thank you for this very clear video! Hope your channel will rise quickly to keep you working on this :)

  • @AnonyMous-777
    @AnonyMous-777 2 ปีที่แล้ว +3

    Finally a new video! Explained well thanks.

  • @sezarstarscourge7368
    @sezarstarscourge7368 2 ปีที่แล้ว

    tthank you i luv the music

  • @neiltsakatsa
    @neiltsakatsa 2 ปีที่แล้ว +1

    Awesome 😎 You've just earned a subscriber!

  • @joewharton7735
    @joewharton7735 2 ปีที่แล้ว +3

    Great video but you don't need the pho to decide the base 64. Just do echo " " | n base64 -d

  • @nasserbenouara9354
    @nasserbenouara9354 2 ปีที่แล้ว

    😍😍😍😍😍

  • @MichaelCooter
    @MichaelCooter 2 ปีที่แล้ว

    Are you on Twitter at all for us to follow?

  • @JarppaGuru
    @JarppaGuru 2 ปีที่แล้ว

    when something has name its founded and there fix for it. you feel save then? there is still those that not been found and no names and been there prob from start. you never have secure machine or phone

  • @akashsarkar990
    @akashsarkar990 2 ปีที่แล้ว

    Your voice too sweet❤️❤️

  • @d3spis3m3
    @d3spis3m3 2 ปีที่แล้ว

    Information that should be included: What versions are susceptible < 5.9?

    • @Medusa0xf
      @Medusa0xf  2 ปีที่แล้ว

      I showed here: 5:32

  • @xml-ha6k3r
    @xml-ha6k3r 2 ปีที่แล้ว +1

    Make video on how to approach targets! 👨‍💻

  • @ifqygifhaazhar8786
    @ifqygifhaazhar8786 2 ปีที่แล้ว

    can you give me link for the wallpaper?

  • @patrickbaumann8670
    @patrickbaumann8670 2 ปีที่แล้ว

    Great Video, sorry but i have a question, whats the point when i already have the credentials to the WP Site?

    • @joewharton7735
      @joewharton7735 2 ปีที่แล้ว

      Imo there isn't one really since you can just upload a php shell. But imo it does serve as a really good example of the attack which I think is the point

    • @joewharton7735
      @joewharton7735 2 ปีที่แล้ว +1

      Just realised she seems to be using it as a priv esc. Basically one account with access to the dash may not have the permissions to manage plugins

  • @youtubee4817
    @youtubee4817 2 ปีที่แล้ว

    but if i don't have the credential is literally useless try to upload the payload in the directory. I have need of exploit like sqli the wp page but i don't know how because seem don't exploitable to sqli.

  • @narcomerk19
    @narcomerk19 2 ปีที่แล้ว

    before you upload the wave file suspiciously without knowing the wordpress credentials. You need to have a shell upload to do that. And that would make sense, you can't perform it without using other shell to upload.

    • @vladimirhitler2395
      @vladimirhitler2395 2 ปีที่แล้ว

      you don't have to upload a shell, you can enumerate login credentials like doing password spraying or dictionary attacks

    • @youtubee4817
      @youtubee4817 2 ปีที่แล้ว

      @@vladimirhitler2395 always with the wordlist right?

  • @ir_snd
    @ir_snd 2 ปีที่แล้ว

    injecktor magento pls

  • @mohmino4532
    @mohmino4532 2 ปีที่แล้ว

    Perfect , i Really enjoyed 😎

  • @jimmyboy7504
    @jimmyboy7504 2 ปีที่แล้ว

    Wow 😲

  • @Pwdec
    @Pwdec 2 ปีที่แล้ว

    Can you give the files :x

  • @Shintowel
    @Shintowel 2 ปีที่แล้ว

    Mantap love you

  • @entityfluff
    @entityfluff 2 ปีที่แล้ว

    Keep it up!

  • @crakrjakful
    @crakrjakful 2 ปีที่แล้ว +1

    wow