XSS to RCE? CrossFit by Hack The Box

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ธ.ค. 2024

ความคิดเห็น • 56

  • @erickjoshuamaico4233
    @erickjoshuamaico4233 3 ปีที่แล้ว +6

    You are so good dude, it is so easy to understand even for someone new in this industry like me

    • @intigriti
      @intigriti  3 ปีที่แล้ว +2

      Thank you! That's always nice to hear! Good luck in this incredible industry!

  • @tonyitalia7798
    @tonyitalia7798 3 ปีที่แล้ว +5

    Awesome work man.
    I'm Brazilian and even so it was super easy to understand your explanation. Thank you very much man.

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      Glad to hear that!

  • @milapmerja5033
    @milapmerja5033 3 ปีที่แล้ว +2

    Wow man! So simple to understand yet so informative. Awesome work man. Keep it up.

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      Glad you liked it! Way more videos to come! 😀

  • @saputello13
    @saputello13 3 ปีที่แล้ว +1

    Very nice! Very easy to understand. Thanks!

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      Glad it was helpful!

  • @0xPr3d4T0r
    @0xPr3d4T0r ปีที่แล้ว +1

    man that was really insane

  • @goodboy8833
    @goodboy8833 3 ปีที่แล้ว +1

    Super well explained.

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      Glad it was helpful! 🔥

  • @anthonyholderbaum6956
    @anthonyholderbaum6956 3 ปีที่แล้ว +1

    Awesome, mindblowing, thank you ! keep it up !

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      Thank you! Will do!

  • @iqyou-gw4kd
    @iqyou-gw4kd 2 ปีที่แล้ว +1

    Awesome work man.

    • @intigriti
      @intigriti  2 ปีที่แล้ว

      Thanks a ton!

  • @aaryanbhagat4852
    @aaryanbhagat4852 3 ปีที่แล้ว

    Its good that draconian is getting a platform!

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      We are glad to have pink draconian on the team 😇

  • @ashishchauhan9745
    @ashishchauhan9745 6 หลายเดือนก่อน

    Awesome work

    • @intigriti
      @intigriti  6 หลายเดือนก่อน +1

      Thanks a lot 😊

  • @mohmino4532
    @mohmino4532 ปีที่แล้ว +1

    good job man im starting love u hhh . but i need to repeat the video many times to understand well because as i said before English is not my native lang😭 but thank u so much 😍

    • @intigriti
      @intigriti  ปีที่แล้ว +1

      Hey, no problem! That's how you learn.. even when videos are in my native language, I often have to repeat many times to understand 😂

    • @mohmino4532
      @mohmino4532 ปีที่แล้ว +1

      @@intigriti thanks i got ur point hhh 😂

  • @KuliBangunan86
    @KuliBangunan86 ปีที่แล้ว +1

    amazing and simply one

  • @fm0x1
    @fm0x1 ปีที่แล้ว

    Amazing Video !!!

    • @intigriti
      @intigriti  ปีที่แล้ว +1

      Thanks! 💜

  • @mukeshsingh7069
    @mukeshsingh7069 ปีที่แล้ว

    Exceptional content, learned a lot, thank you so much. You are amazing bro 👏
    Two things I am confused with the POST request at 17:36
    1. Why & How did the Token worked? Normally it should get expired once it gets used, right?
    Also, if this is the case, then how can I dynamically get the token from the webpage & use it to submit the account creation request.
    2. You spelled submit incorrectly, still the form got submitted. Why & How?

    • @intigriti
      @intigriti  ปีที่แล้ว

      PinkDraconian is no longer with us but I 100% agree, he's an amazing hacker and created some awesome video content for us 🥰
      I didn't solve this machine but for (1) I would hazard a guess (without watching the full video) that the CSRF token either a) doesn't change (intentionally vulnerable) or b) the token resets on each refresh, but the page isn't refreshed before we use the captured token.
      (2) is probably that a POST request to /accounts container a username and password is all that's required for authentication. The "sumbit" parameter is set to "pinkdraconian" as well, which wouldn't really make sense.

  • @dennismunyaka6537
    @dennismunyaka6537 3 ปีที่แล้ว

    I've just subscribed looking for more fire content like this in the future

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      Thanks for the sub! There is pleeeeenty more to come 😀

  • @S2eedGH
    @S2eedGH 3 ปีที่แล้ว +1

    Great explaining I hope you do a lot like this video, Thanks

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      Thank you, I will

  • @presequel
    @presequel ปีที่แล้ว

    wow, great video :)

    • @intigriti
      @intigriti  ปีที่แล้ว

      Thank you! 🙏🥰

  • @noony31122009
    @noony31122009 ปีที่แล้ว +1

    Awesome

    • @intigriti
      @intigriti  ปีที่แล้ว

      Thank you! 💜

  • @j233wfyw
    @j233wfyw 2 ปีที่แล้ว

    Awesome! 😉

    • @intigriti
      @intigriti  2 ปีที่แล้ว

      Thanks! 😄

  • @keanozaralho5490
    @keanozaralho5490 2 ปีที่แล้ว

    I got a 200 response when send the payload, but i didn't received nothing in the server side. Can u help me with this ? I've tried it a lot of ways, with Python server, ngrok, webhookers, netcat, using other ports,etc.. But i never receive the resquest in the server side.

    • @intigriti
      @intigriti  2 ปีที่แล้ว +1

      Is everything else set up correctly? Could you maybe make a video or blog to show?

  • @nhlcreation4240
    @nhlcreation4240 3 ปีที่แล้ว

    Awesome, very informative

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      Thank you very much! We are happy if you like it 😎

  • @burekhacks
    @burekhacks 2 ปีที่แล้ว

    Not sure why but the second payload is not returning anything except a 200 response.. the first one worked just fine

    • @intigriti
      @intigriti  2 ปีที่แล้ว

      Weird, did you end up figuring it out?

    • @burekhacks
      @burekhacks 2 ปีที่แล้ว

      @@intigriti I did indeed! It was a mistake on my end. Thank you for the reply

  • @felizmelvin5329
    @felizmelvin5329 ปีที่แล้ว

    I love the content.

  • @mujta3as3c
    @mujta3as3c 2 ปีที่แล้ว

    Reflected xss to RCE ?

    • @intigriti
      @intigriti  2 ปีที่แล้ว

      That won't be possible, afaik9

  • @atulsharma4501
    @atulsharma4501 2 ปีที่แล้ว

    16:00 CSRF token are not stored as cookies!

    • @intigriti
      @intigriti  2 ปีที่แล้ว

      Thanks for pointing out this mistake! My bad!

  • @Borma425
    @Borma425 3 ปีที่แล้ว

    thanks

    • @intigriti
      @intigriti  3 ปีที่แล้ว

      You're welcome!

  • @markcuello5
    @markcuello5 2 ปีที่แล้ว

    SECURITY