How did Masato find the Google Search XSS?

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 พ.ย. 2024

ความคิดเห็น • 137

  • @4.0.4
    @4.0.4 5 ปีที่แล้ว +165

    1) join obscure group with few people
    2) obsess over niche topics
    3) spend years dwelling on the arcane
    *4) realize you've been initiated into a secret order of the elders*

    • @tacokoneko
      @tacokoneko 5 ปีที่แล้ว +11

      as a minecraft player since 2010 i realized this is what i am to all the new players from the popularity surge
      simple survival tricks like elevators, auto farms and optimized pathway and construction techniques awe them
      god forbid i walk past people wearing early minecon capes, players gather and stare..
      if only i could have put tens of thousands of hours into something actually useful like electronic engineering..

    • @rippspeck
      @rippspeck 5 ปีที่แล้ว +8

      Masato: I exploited the frontpage of the internet.
      rando: i liek minecraft

    • @TheDuked
      @TheDuked 4 ปีที่แล้ว +1

      @@tacokoneko damn, this comment hit hard bro, the amount of time I could have spent better.

  • @nug203
    @nug203 5 ปีที่แล้ว +91

    I knew it had to be a conspiracy. There's no other explanation for why I can't find $100k bugs with just one year of experience. Thanks for validating that its definitely not me!

    • @ultronhack8151
      @ultronhack8151 4 ปีที่แล้ว +1

      what about now
      let me know

    • @TypicalURL
      @TypicalURL 3 หลายเดือนก่อน

      What about you now ​@@ultronhack8151

  • @AlbertoRestifo
    @AlbertoRestifo 5 ปีที่แล้ว +7

    I love how you never create this image of being genius, but always point out that your incredible knowledge is the result of years of dedicated work. You're an inspiration, keep up the incredible work!

  • @finesseandstyle
    @finesseandstyle 5 ปีที่แล้ว +8

    Thanks for that final bit where you say not to be frustrated. I'm personally not into XSS atm but it still applies to what I want. Sometimes I just get frustrated at people who are much younger than me and accomplished much more in less time. I needed that

  • @Skulard
    @Skulard 5 ปีที่แล้ว +105

    07:33 "Don't hug me I'm scared" the freaking Notepad!

    • @OrioPrisco
      @OrioPrisco 5 ปีที่แล้ว +3

      oh god no

    • @floatingblaze8405
      @floatingblaze8405 5 ปีที่แล้ว

      I think that's the leafpad editor

    • @Skulard
      @Skulard 5 ปีที่แล้ว +2

      @@floatingblaze8405 for me it looks like the notepad from dont hug me im scared the "creativity" episode

    • @JaytleBee
      @JaytleBee 5 ปีที่แล้ว +3

      Now let's all agree
      To never be creative again

    • @macarena3184
      @macarena3184 5 ปีที่แล้ว +1

      green is NOT a creative color! ¯\_(ツ)_/¯

  • @LasermanSteam
    @LasermanSteam 5 ปีที่แล้ว +30

    I thought the conspiracy was going to lead to "it turns out the way they are all connected is that they all... WROTE FOR SKILLSHARE, AN ONLINE LEARNING COMMUNITY WITH THOUSANDS OF CLASSES etc."

  • @Rngplayhard
    @Rngplayhard 5 ปีที่แล้ว +1

    Thank you... I as a new pentester I tend to feel demoralized sometimes but your video helps!

  • @Charioo
    @Charioo 5 ปีที่แล้ว +87

    i love watching your videos but i hardly have any clue what they mean 99% of the time

    • @WhyGodby
      @WhyGodby 5 ปีที่แล้ว +8

      99.9% of the audience

    • @lucasmenicucci8102
      @lucasmenicucci8102 5 ปีที่แล้ว +3

      Yeah, sometimes I think the explanation goes to fast

    • @v380riMz
      @v380riMz 4 ปีที่แล้ว +2

      Lucas Menicucci you can’t really explain how browser parsers work within 10 minutes.To understand you’d have to work with them and dig deeper in the documentation. I didn’t understand shit either. These guys are on another level so it doesn’t really matter anyway

    • @danielchequer5842
      @danielchequer5842 4 ปีที่แล้ว

      I just like to pretend that I know programing bc I can explain to people what HTML means.

    • @user-zu6ts5fb6g
      @user-zu6ts5fb6g 4 ปีที่แล้ว

      If you know javascript on an intermediate level, you will understand a lot of this. However only real xss researchers will read the documentation as closely as these guys did. This is what you'd have to do in order to understand this video.

  • @ABNaseer1122
    @ABNaseer1122 5 ปีที่แล้ว +10

    I barely know complex concepts of coding etc but that XSS video was so well explained

  • @questwalkerko
    @questwalkerko 4 ปีที่แล้ว +1

    "dont feel bad that you didn't find that stuff"
    and sometimes I lose a battery between the couch cushions that I never find again

  • @devtekve1396
    @devtekve1396 5 ปีที่แล้ว

    This is by far my favorite channel

  • @ewyg
    @ewyg 5 ปีที่แล้ว +7

    hope you can make more video about xss. how can we find xss in multiple ways. where can we learn xss. what tools can we use to help us find xss.

  • @XDRosenheim
    @XDRosenheim 5 ปีที่แล้ว +36

    So basically, shower thoughts.

  • @DEBBAH1907
    @DEBBAH1907 5 ปีที่แล้ว +36

    I was never this early.

    • @iyxan23
      @iyxan23 5 ปีที่แล้ว

      Mee to

    • @sebastianelytron8450
      @sebastianelytron8450 5 ปีที่แล้ว +1

      If you're early post something witty/clever to get lots of likes!!
      People these days smh

    • @DEBBAH1907
      @DEBBAH1907 5 ปีที่แล้ว

      @@sebastianelytron8450 I don't care about likes m8

  • @batchrocketproject4720
    @batchrocketproject4720 ปีที่แล้ว

    This is fascinating, thanks for posting. I have a very naive question that hopefully some reader can answer. I'm well aware of the idea of xss and the efforts put into preventing it but my question is - why? What can it do? The only examples I've ever seen involve showing a popup. Now I get that an xss can execute more than js alert but so what? What use is, for example, reading a cookie to a hacker? How would they ever get the results of their script? Before I get shouted down, I'm not for one minute suggesting there is not a problem, I just want to understand what the problem is. Thanks.

  • @ganstabreakincity
    @ganstabreakincity 5 ปีที่แล้ว

    Great video, I commented you on twitter the other day about gmail xss

  • @eigenmishi_in_3d
    @eigenmishi_in_3d 5 ปีที่แล้ว +1

    Thank you for the info, and for the positive encouragement

  • @gabohXD
    @gabohXD 5 ปีที่แล้ว +2

    And I'm just here... starting with html and css :')

  • @kevinwydler7305
    @kevinwydler7305 2 ปีที่แล้ว

    Thank you, this was really motivating!

  • @ra6160
    @ra6160 5 ปีที่แล้ว +1

    thx to liveoverflow, u rock!

  • @4pThorpy
    @4pThorpy 5 ปีที่แล้ว +2

    Loved the "don't hug me I'm scared reference" green is not a creative colour!

  • @yugioh8810
    @yugioh8810 5 ปีที่แล้ว +4

    I thought he was saying My Quest instead of Mike West.

  • @technostrife1330
    @technostrife1330 5 ปีที่แล้ว +35

    BeautifulSoup in python is not vulnerable to this attack

    • @sebastianelytron8450
      @sebastianelytron8450 5 ปีที่แล้ว +10

      What next? Your mom is not vulnerable to rape?
      EVERYTHING is vulnerable

    • @bailey125
      @bailey125 5 ปีที่แล้ว +50

      @@sebastianelytron8450 Notice how they said 'THIS attack'? They never said "BeautifulSoup in python is not vulnerable to any attack". Of course everything is vulnerable, but many things are immune to certain attacks.

    • @juliavanderkris5156
      @juliavanderkris5156 5 ปีที่แล้ว +24

      @@sebastianelytron8450 They said "this attack", you idiot. As in, this specific payload.

    • @glowingone1774
      @glowingone1774 5 ปีที่แล้ว +8

      @@sebastianelytron8450 god dam you're fucking stupid.

    • @tmack729
      @tmack729 5 ปีที่แล้ว

      @@sebastianelytron8450 cringe

  • @iyxan23
    @iyxan23 5 ปีที่แล้ว +1

    Past: hello
    Too Ez Man!
    Now :

  • @bnal5tab90
    @bnal5tab90 5 ปีที่แล้ว +1

    the funny thing I was developing CSH (client side hacker) and found this wired parsing but I didn't think it will be in Google as it is huge company

    • @bnal5tab90
      @bnal5tab90 5 ปีที่แล้ว +1

      this was 2 week ago

  • @Taaz2
    @Taaz2 5 ปีที่แล้ว

    Thank you very much for doing these videos ! :)

  • @RAGHAVENDRASINGH17
    @RAGHAVENDRASINGH17 5 ปีที่แล้ว +2

    Your channel is awesome

  • @sunnyyang1191
    @sunnyyang1191 5 ปีที่แล้ว

    Hey there’s a website called BugMeNot which you may or may not have heard of. It used to be completely safe but now hackers are using it to share login credentials. Many accounts were hacked during the discord leak which were used on BugMeNot.

  • @aceinside
    @aceinside 5 ปีที่แล้ว +2

    long story short, if you want to do security you'll never catch up and always be behind

  • @steeveedeee
    @steeveedeee 5 ปีที่แล้ว +1

    Amazing video. So inspiring!!

  • @nataoh
    @nataoh 5 ปีที่แล้ว

    Thank you very much for this video. It inspired me a lot. Thank you!!!

  • @jmannUSMC
    @jmannUSMC 5 ปีที่แล้ว

    Per👏se👏ver👏ance👏

  • @AbdulKarim-fs5iw
    @AbdulKarim-fs5iw 5 ปีที่แล้ว

    Thanks for the follow up n details... ✌🏿️🖖🏿

  • @voulyful
    @voulyful 2 ปีที่แล้ว

    What is the advantage to launch code in the clients (myself) browser?

  • @ilyboc
    @ilyboc 3 ปีที่แล้ว

    That's what people mean when they talk about hacking google with HTML

  • @filipstamcar6553
    @filipstamcar6553 5 ปีที่แล้ว +1

    Why didn't Google just block all HTML tags? I understand they are needed for cases like emails but why then need HTML in search query?

    • @MEfe-de6in
      @MEfe-de6in 5 ปีที่แล้ว +1

      then what ? there is a vulnreability always .you cant block everything.

  • @j3r3miasmg
    @j3r3miasmg 5 ปีที่แล้ว +2

    Every time you show some twitter prints, I keep thinking if you are part of this kind of conspiracy, this is just friendship between security researchers or if you are just stalking the top researchers like I do...

  • @soft-alloy2495
    @soft-alloy2495 5 ปีที่แล้ว +4

    wow i thought this vid had been out longer

    • @quad7375
      @quad7375 5 ปีที่แล้ว

      same here i thought this was old as well

  • @masonp1314
    @masonp1314 5 ปีที่แล้ว +5

    So, say someone finds an XSS, but on some website you might not have been asked to find an exploit.. how do you alert the company, without getting into trouble?

    • @EricWilliamsCG
      @EricWilliamsCG 5 ปีที่แล้ว +1

      Why would you worry about getting in trouble? If you really want to stay anonymous email them from temp-mail.org or a similar temp mail service.

    • @renakunisaki
      @renakunisaki 5 ปีที่แล้ว +4

      It's tricky. Many will be grateful if you just send an email with your findings, but occasionally you get the dingus who threatens to sue you for "hacking their internets". It's best to report them anonymously, just in case.

    • @DylanMaddocks
      @DylanMaddocks 5 ปีที่แล้ว

      There's a site called hacker one, along with similar sites where companies put their websites up and give rewards for any vulnerabilities you find. The larger the site (Facebook, squarespace, etc.) the more you get for the bug. I checked it out a few years ago and they can pay thousands of dollars for the discovery of a bug.
      If the site is not on hacker one or the similar sites check if they have the code on github and you can submit the bug there. Otherwise find their TECH email. I would not recommend telling just anyone at the company about it, they're likely to panic and their superiors might try to sue you for breaking their terms of service.

    • @JonathanGray89
      @JonathanGray89 5 ปีที่แล้ว

      That's easy, unless there is a bug bounty or something for it, just don't. It's simply not ethical to exploit a machine without permission. If you happened to already find the exploit then that's mistake number one. Mistake number two would be doing something about it. It's not your problem unless you make it your problem.

  • @vexioz
    @vexioz 5 ปีที่แล้ว

    Thanks for another interesting video

  • @SianaGearz
    @SianaGearz 5 ปีที่แล้ว +1

    6:55 in case someone knows where the gif of a girl putting a box on her head comes from, i'd be thankful.

    • @caboseisstupid
      @caboseisstupid 5 ปีที่แล้ว

      tenor.com/view/embarrassed-box-corner-asian-hide-gif-5201468

  • @earl5954
    @earl5954 5 ปีที่แล้ว

    Im learning a lot at the same time

  • @AnnoyingRains
    @AnnoyingRains 4 ปีที่แล้ว

    XSS sounds like a programming language. .xss

  • @georgplaz
    @georgplaz 3 ปีที่แล้ว

    7:34
    ptsd flashbacks ._.

  • @seifenspender
    @seifenspender 5 ปีที่แล้ว

    That DHMIS reference :D

  • @calebsykes4898
    @calebsykes4898 5 ปีที่แล้ว

    That was a really good video

  • @tomrow32
    @tomrow32 5 ปีที่แล้ว

    Why not just change all characters to Unicode lookalikes before sending it to the renderer?

  • @abdelmohyminzerocode8311
    @abdelmohyminzerocode8311 5 ปีที่แล้ว

    Good work pro

  • @ultramoxx1148
    @ultramoxx1148 5 ปีที่แล้ว +3

    0:10 yeah its just a XSS but!!! Its a XSS on fcking google! xD

  • @TheMrDott
    @TheMrDott 5 ปีที่แล้ว +1

    yah thats so good
    thank you so much
    love you

  • @tomrow32
    @tomrow32 5 ปีที่แล้ว

    7:34 Oh no

  • @naufalhakim2828
    @naufalhakim2828 5 ปีที่แล้ว

    Very interesting

  • @stephenkamenar
    @stephenkamenar 5 ปีที่แล้ว +1

    XSS is TRICKY

  • @amyshaw893
    @amyshaw893 5 ปีที่แล้ว

    I'm pretty sure ive found a small exploit in a website. I can get html tag injection, but no xss, sadly

  • @mix3k818
    @mix3k818 5 ปีที่แล้ว +19

    "LiveOverflow"
    Hm, I wonder where you got that from...

  • @Ouchie
    @Ouchie 5 ปีที่แล้ว

    6:52 IU!

  • @dayumnson9769
    @dayumnson9769 4 ปีที่แล้ว

    I think it's twitter 8:30 :D

  • @hblaub
    @hblaub 5 ปีที่แล้ว +11

    Experience = another word for just being old.

    • @NOLlFE1
      @NOLlFE1 5 ปีที่แล้ว +1

      No im 15 years old and i was a part of twitters hackathon.

  • @amogus7
    @amogus7 2 ปีที่แล้ว

    why parse twice? just append already-sanitized DOM object to the document

  • @AlexVasiluta
    @AlexVasiluta 5 ปีที่แล้ว +1

    Nice

  • @afzalsayed96
    @afzalsayed96 5 ปีที่แล้ว +4

    3:45 Draw puzzle pieces much? 😂

  • @MEfe-de6in
    @MEfe-de6in 5 ปีที่แล้ว

    we are about to getting a fetish level that even not possible.

  • @birb9254
    @birb9254 5 ปีที่แล้ว

    what is parsing?

  • @Matt0x00
    @Matt0x00 5 ปีที่แล้ว

    man i miss ha.ckers and sla.ckers

  • @jstock2317
    @jstock2317 5 ปีที่แล้ว +1

    Complexity within your system creates nonrigorous behavior, and fundamentally represents weak design.

    • @eigenmishi_in_3d
      @eigenmishi_in_3d 5 ปีที่แล้ว

      Complexity represents weak design? How to create powerful systems then?

    • @jstock2317
      @jstock2317 5 ปีที่แล้ว +1

      Eigenmishi in 3D Ooh yeah, what I meant to say was that each part of a system should be simple and compartmentalized. But when the fundamentals are complex as well, then it represents poor abstraction and may be quite difficult to expand.

  • @TimHoekstra
    @TimHoekstra 5 ปีที่แล้ว

    slackers unite!

  • @jamesaylward2303
    @jamesaylward2303 5 ปีที่แล้ว +1

    I would watch your videos but I know nothing : |

  • @ryanwakebradtelle8682
    @ryanwakebradtelle8682 4 ปีที่แล้ว

    So what is the endgame of this type of exploitation?

  • @mellbonus1337
    @mellbonus1337 5 ปีที่แล้ว

    Monsanto

  • @erikjohansson1814
    @erikjohansson1814 5 ปีที่แล้ว +1

    It feels as if you know a little bit about computers?
    Just guessing....

  • @小张同学-v6i
    @小张同学-v6i 5 ปีที่แล้ว +3

    i got to bet you need 10years to become software pros, and another 10 years to become a real hacker!

    • @4.0.4
      @4.0.4 5 ปีที่แล้ว

      It highly depends on challenging yourself constantly. Some people spend decades doing the same thing and are just barely good at it. Others become masters in their craft after a few years. The difference? The real pros don't see it as a job, but a passion.
      You too can become LiveOverflow if you Live the Overflow.

  • @BadAimWeeb
    @BadAimWeeb 5 ปีที่แล้ว

    *seen*

  • @forgedwithsteel
    @forgedwithsteel 5 ปีที่แล้ว

    i like your voice.

  • @superjugy
    @superjugy 5 ปีที่แล้ว

    Green is not a creative color!

  • @armaansameer8171
    @armaansameer8171 5 ปีที่แล้ว

    💯🚩

  • @necronomicon1472
    @necronomicon1472 5 ปีที่แล้ว +1

    "I thought we could talk about how Masato found this XSS and milk the cow some more."

  • @iyxan23
    @iyxan23 5 ปีที่แล้ว

    754th VIEWERS!

  • @MsTobistar
    @MsTobistar 5 ปีที่แล้ว

    Man hört einfach das du auch deutschsprachig bist 😅 aber gutes Video 👌🏼

  • @jwrm22
    @jwrm22 5 ปีที่แล้ว +2

    I won't say that getting as good as these guys is a waste of time. But keep in mind that working 12 years on XSS today might not be as beneficial.
    We do not know what the world will look like in 12 years. Everything you do now will help you in the future, so learn a new skill.

  • @terra1355
    @terra1355 5 ปีที่แล้ว

    11th!

  • @ra6160
    @ra6160 5 ปีที่แล้ว

    fuckkkkkkkk

  • @-Keystoeducation
    @-Keystoeducation 2 ปีที่แล้ว

    f

  • @crazymemes4080
    @crazymemes4080 5 ปีที่แล้ว

    Bro i want to get connected with you in any social media plz bro

  • @madghostek3026
    @madghostek3026 5 ปีที่แล้ว

    notification squad

  • @vkredgod2340
    @vkredgod2340 5 ปีที่แล้ว

    Big early

  • @PeachyGreed
    @PeachyGreed 5 ปีที่แล้ว

    No X-Files theme song? Downvoted sorry.

  • @michaelselui6998
    @michaelselui6998 5 ปีที่แล้ว

    Only Google search engine, what about others (Duckduckgo )😂, we shouldn't use Google anyway

    • @xXLanyuzAnlunXx
      @xXLanyuzAnlunXx 5 ปีที่แล้ว

      You can try it too!

    • @Matt0x00
      @Matt0x00 5 ปีที่แล้ว +1

      Don't use google... he says from a comment on TH-cam