Hacking Binance - Bug Bounty Hunting for Cross Site Scripting | Part 2

แชร์
ฝัง
  • เผยแพร่เมื่อ 1 ก.พ. 2025

ความคิดเห็น • 23

  • @Mlaynedere
    @Mlaynedere 5 หลายเดือนก่อน

    Excellent video! Can't wait for part 3!!!

    • @_The_hackers
      @_The_hackers  5 หลายเดือนก่อน +1

      Really glad you enjoyed it, aiming to make Part 3 even better. Thanks so much @Mlaynedere.

  • @Anthony-43
    @Anthony-43 5 หลายเดือนก่อน +1

    Looking forward to part 3

    • @_The_hackers
      @_The_hackers  5 หลายเดือนก่อน

      Thanks, will be comming soon :)

  • @mmijakot
    @mmijakot หลายเดือนก่อน +1

    Keep up the good work ...

    • @_The_hackers
      @_The_hackers  หลายเดือนก่อน

      Thank you so much 💪💪

    • @mmijakot
      @mmijakot หลายเดือนก่อน

      @@_The_hackers Highly welcome, gentlemen ...

    • @mmijakot
      @mmijakot หลายเดือนก่อน

      @@_The_hackers Highly welcome, gentlemen ...

  • @bilaalmuhammad-ql1li
    @bilaalmuhammad-ql1li 5 หลายเดือนก่อน +2

    Your topic is say find xss on binance but you just look on vulnerable web

    • @_The_hackers
      @_The_hackers  5 หลายเดือนก่อน

      Thanks for the feedback! We did start by demonstrating XSS on a vulnerable web application to help explain the concept, but we also moved on to testing for XSS on Binance later in the video. We wanted to make sure everyone, including beginners, understood the basics before diving into real-world bug hunting. If you stick around for the whole video, you’ll see how we applied those techniques on Binance. More advanced content is definitely on the way, so stay tuned!

  • @Alex-vi6iz
    @Alex-vi6iz 5 หลายเดือนก่อน

    Nice video, but I have one question. Isn't it a little too basic trying regular XSS payload in a field then moving on ? Isnt't it worth fuzzing with various payloads using intruder or XSStrike tool ? I would assume most companies did the bare minimum to secure against a basic payload, but maybe a complex one may slip through.

    • @_The_hackers
      @_The_hackers  5 หลายเดือนก่อน +1

      Hi thanks for the question. You are correct, there are more advanced tools you can use for testing for injection attacks. We would like to turn this into a video series were we start off with the basics of these types of attacks. Which is why we also demonstrated on Juice Shop first. This is so that even beginners can have a shot at trying out basic techiques on bug bounties. We will definitely be using more advanced tools as we go along, there are some pros and cons of using XSStrike which we can go over in the next part. If there are any other tools or techniques you would like to see, let us know. It is greatly apreciated :)

    • @Alex-vi6iz
      @Alex-vi6iz 5 หลายเดือนก่อน

      ​​@_The_hackers Ah, it makes sense then. It would be cool to weigh the pros and cons of XSStrike, intruder etc, looking forward to it !

  • @craigblackie2034
    @craigblackie2034 4 หลายเดือนก่อน

    Using dev tools to modify the client side code (as you did for the profile picture) isn't xss.

    • @_The_hackers
      @_The_hackers  4 หลายเดือนก่อน

      You are right it is not, this was done to see if it would be possible to get the img tag to error out to see if the dom was being manipulated, if it was it would mean that XSS might be possible however it wasn't so we moved on. But thanks a lot for the comment :)

  • @ck-in4ez
    @ck-in4ez 5 หลายเดือนก่อน +1

    Man sometimes you need to encoding it to work if you write the cross scripting as plain text will not work try to more methods!

    • @_The_hackers
      @_The_hackers  5 หลายเดือนก่อน

      Thanks for the tip! Yes, we’re aware that encoding can sometimes be necessary for XSS attacks to work. This was our first intro to bug bounty and XSS, so we wanted to keep it straightforward for beginners. We’ve got more complex videos in the pipeline that will dive deeper into these techniques. The video was already 35 minutes long, so we didn’t want to make it too lengthy, but stay tuned for more detailed content coming soon!

  • @hellobye9598-c4u
    @hellobye9598-c4u 5 หลายเดือนก่อน

    Mannn bow I have to wait for part 3 🥲

    • @_The_hackers
      @_The_hackers  5 หลายเดือนก่อน +1

      Hope not to disappoint, stay tuned :)