CRLF + XSS + cache poisoning = Access to Github private pages for $35k bounty

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 พ.ย. 2024

ความคิดเห็น • 22

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  3 ปีที่แล้ว

    Hi! Welcome to the comment section! I hope you enjoyed the video!
    Get the first issue of BBRE newsletter: mailing.bugbountyexplained.com/news1
    You have time until Saturday 8th May to sign up if you want to receive the 2nd newsletter.

  • @ahmadshami5847
    @ahmadshami5847 3 ปีที่แล้ว +16

    It's amazing how 2 high school students did all that! now those are some newborn legends

    • @TheKing-ul5pw
      @TheKing-ul5pw 3 ปีที่แล้ว

      TH-cam open redirection th-cam.com/video/aSS23VHAqbU/w-d-xo.html

  • @-bubby9633
    @-bubby9633 3 ปีที่แล้ว +3

    Another fantastic explanation, super concise and easy to understand as always! Thanks for working so hard to keep us update to date and informed. Noticing that little distinction in the source code between converting to int for accessing the page but not when setting the cookie val as a 14 and 17 year old is seriously impressive. Not to mention the cookie scoping bypasses afterwards. Pretty sure at that age I was nothing more than a dumb script kiddie pressing buttons on Havij 😂

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 ปีที่แล้ว +4

      Thank you Andrew. If someone would tell me that guys in such age found a $35k bug, I would think it's maybe an IDOR, some business logic or something like that but Id never think a chain like this..

  • @0SPwn
    @0SPwn 3 ปีที่แล้ว +1

    Crazy. I'm 14 and these guys are obviously doing some crazy stuff!

    • @sontapaa11jokulainen94
      @sontapaa11jokulainen94 3 ปีที่แล้ว

      I wish you a happy journey into cyber security!

    • @0SPwn
      @0SPwn 3 ปีที่แล้ว +1

      @@sontapaa11jokulainen94 Thank you, you too.

  • @imuser007
    @imuser007 3 ปีที่แล้ว +2

    this is amazing man well explained

  • @brijendarsingh3358
    @brijendarsingh3358 3 ปีที่แล้ว

    Clear and concise explaination . thankyou for helping the community .

  • @estebanroman3258
    @estebanroman3258 3 ปีที่แล้ว

    Holyyyy moly! This is huges! Thanks and this channel it's amazing!

  • @blablablabla29382
    @blablablabla29382 3 ปีที่แล้ว +1

    Success unlocked: pay back the bank for all school years.

  • @bugr33d0_hunter8
    @bugr33d0_hunter8 3 ปีที่แล้ว +1

    You the man, i love your videos, and the time you put into them. I was always wondering when someone would, reverse engineer the bugs so we can see how they went about finding the bug, along with a proof of concept. I knew the young wipper snappers would rise up and make my job even harder, lol. I love that shirt, looks good on you. I go the gym as well, have to fill out my club shirts, hehe.

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 ปีที่แล้ว +2

      Hahah thanks for the comment!
      I struggle now to find gym alternatives when they are closed but Im doing my best to keep my shirts pumped up!💪

    • @henrypowell3496
      @henrypowell3496 2 ปีที่แล้ว

      so you understood the whole vid? you are genius, man

  • @dojoku88
    @dojoku88 3 ปีที่แล้ว

    wow That’s awesome,,

  • @cybersecurity3523
    @cybersecurity3523 3 ปีที่แล้ว

    Good bro

  • @machinexa1
    @machinexa1 3 ปีที่แล้ว

    😊👌

  • @toriyono8018
    @toriyono8018 3 ปีที่แล้ว

    First 🥇