ความคิดเห็น •

  • @STOKfredrik
    @STOKfredrik 5 ปีที่แล้ว +259

    sweeeeeet!!! huge fan! love the color scheme and pace!

    • @PwnFunction
      @PwnFunction 5 ปีที่แล้ว +18

      Thank you!

    • @Test-ed8cm
      @Test-ed8cm 4 ปีที่แล้ว +4

      oh hey its STOK

    • @l2xsniper1
      @l2xsniper1 3 ปีที่แล้ว +3

      @@PwnFunction that would be pretty cool if Linux had that color scheme and font for its command line

    • @psychoSherlock
      @psychoSherlock 3 ปีที่แล้ว

      Stök 😱😱😱😱

    • @gldn_l-ml7pr
      @gldn_l-ml7pr 3 ปีที่แล้ว +1

      Uff STÖK

  • @harshjaiswal1245
    @harshjaiswal1245 5 ปีที่แล้ว +44

    LiveOverFlow haxed! xD Nice video as always!

  • @niprjct
    @niprjct 5 ปีที่แล้ว +4

    I sure hope you do not stop with these tutorials, well done.
    please keep up with the great content and easy to understand lessons.

  • @Sriramofficial
    @Sriramofficial 5 ปีที่แล้ว +12

    I'm so happy that I don't have to explain things to people in a complex way by sending random links to people! :D I'm gonna share it across!

  • @andreslauga
    @andreslauga 4 ปีที่แล้ว +1

    I am a huge fan of the way that you end your videos... That outro is so inspiring!!

  • @StefanRows
    @StefanRows 4 ปีที่แล้ว +3

    Really nice breakdown of IDOR's! Subbed!

  • @nahmedfaisal
    @nahmedfaisal 5 ปีที่แล้ว +4

    Another great video..
    few more 101 videos, and this channel will be the go to channel for learning bug bounty or web security.
    keep up the good work!

  • @logmantarig
    @logmantarig 3 ปีที่แล้ว +1

    Broo, The way you explain is just super smooth and very understandable
    Thank you so much

  • @MrDevo
    @MrDevo 4 ปีที่แล้ว

    Many thanks for the explanation. Very well done! Please don't stop making videos.

  • @shivamgoyal9844
    @shivamgoyal9844 5 ปีที่แล้ว +33

    Awesome video again. I have to say this is gonna be best youtube channel for learning web security. Please make a video on XXE too. 😀

    • @PwnFunction
      @PwnFunction 5 ปีที่แล้ว +11

      I soo wanna get into more better vulns, but I gotta go from the basics for this series. I promise the next video is gonna be on XXE :)

    • @VivekYadav-ds8oz
      @VivekYadav-ds8oz 3 ปีที่แล้ว +1

      @@PwnFunction eyy 2 years late but you actually delivered. Nice!

  • @anakinskywalkerrr
    @anakinskywalkerrr 4 ปีที่แล้ว

    Oh God, I'm so glad I found your channel, you explaining it and so easy to understand.. I'll sub for that

  • @ricardoprieto1849
    @ricardoprieto1849 4 ปีที่แล้ว

    Wouuuuuu NICE DISCOVERY! great great job! thanks

  • @Omar-wm9kz
    @Omar-wm9kz 3 ปีที่แล้ว +1

    What a way of teaching .great

  • @arwildo
    @arwildo 4 ปีที่แล้ว +2

    Nice tutorial, I love your UI taste

  • @vollhard
    @vollhard ปีที่แล้ว

    Love your intro and outro :D and ur content as well

  • @Raj_darker
    @Raj_darker 4 ปีที่แล้ว

    Awesome !! Video Keep posting other Web vulnerabilities video also !!! Thanks !

  • @thecuriousone9504
    @thecuriousone9504 3 ปีที่แล้ว +1

    thank you dude, this helped me so much.

  • @NoBakwas
    @NoBakwas 2 ปีที่แล้ว

    Underrated channel ! Subbed ❤️

  • @VlogDeIT
    @VlogDeIT 5 ปีที่แล้ว +1

    Another awesome video. Thanks.

  • @kratigupta419
    @kratigupta419 4 ปีที่แล้ว +1

    This is really awesome..... You really explained everything in such an easy way...... You should definitely continue uploading more videos on web security... Surely your channel will gain more likes and subscribers... 👍👍

  • @supersaiyan0x016
    @supersaiyan0x016 5 ปีที่แล้ว

    Love you brother 😍 Waiting for more ❤ keep up the good work 🙏

  • @yujianou4476
    @yujianou4476 3 ปีที่แล้ว

    Just wanna say your videos are amazing :)

  • @shivamsrivastava9810
    @shivamsrivastava9810 3 ปีที่แล้ว +1

    very well explaind.. thanks aton 👏♥️

  • @0x414243
    @0x414243 5 ปีที่แล้ว +1

    Awesome video. Thank you so much

  • @AntiHeadshot
    @AntiHeadshot 3 ปีที่แล้ว

    I never heard of this, but it never came to my mind, not checking the privileges of the requesting identity, before returning or doing anything. But seeing how many developers are working im glad videos like this exist.

  • @ujjavalsinghvlog7545
    @ujjavalsinghvlog7545 5 ปีที่แล้ว +1

    Waiting for more Such Awesome videos

  • @narendrajayram1317
    @narendrajayram1317 5 ปีที่แล้ว

    Your videos are super cool for learning web app security. I don't have any hesitation to recommend this channel. Please try to make more videos covering at least OWASP TOP 10

  • @ArkanoidGaming
    @ArkanoidGaming 4 ปีที่แล้ว

    awesome voice , awesome explanation , awesome colors , overall fantastic video

  • @andreslauga
    @andreslauga 4 ปีที่แล้ว

    Awesome video!! Thanks!

  • @dedsec0173
    @dedsec0173 4 ปีที่แล้ว

    Awesome videos, it's easy to learn, thanks for sharing :D

  • @mid-julyenglish1782
    @mid-julyenglish1782 4 ปีที่แล้ว +1

    You should continue maaaaaaaaaaan continue doing stuff like this...

  • @aashita6850
    @aashita6850 ปีที่แล้ว

    You explain so well!!!!

  • @sakyb7
    @sakyb7 5 ปีที่แล้ว

    Nice one.. keep going. . ;)
    Waiting for your video on FUZZING ❤️

  • @PVZHARCORECITY
    @PVZHARCORECITY 2 ปีที่แล้ว

    Loved the reference to LiveOverflow!

  • @ehrajatrathi
    @ehrajatrathi 4 ปีที่แล้ว +1

    I understand idor now, thanks 😀

  • @crispy_rw
    @crispy_rw 5 ปีที่แล้ว

    LOVE YOUR VIDS

  • @rusirumunasinghe7354
    @rusirumunasinghe7354 4 ปีที่แล้ว

    Awesome stuff!

  • @CyberQuickYT
    @CyberQuickYT 3 ปีที่แล้ว +1

    Fun fact: google images suffer from IDOR too (or at least did a year or two back)

  • @kirayamato6128
    @kirayamato6128 2 ปีที่แล้ว

    That's why always use post or raw body json as params to get or post the data.

  • @cancerousgaming7301
    @cancerousgaming7301 4 ปีที่แล้ว

    Nice explanation. Real talk😊

  • @nvk0x
    @nvk0x 4 ปีที่แล้ว

    great video ... love u brother

  • @Rashedulcss
    @Rashedulcss 3 ปีที่แล้ว

    Awesome...!

  • @rogervanbommel1086
    @rogervanbommel1086 3 ปีที่แล้ว

    About that ending, few ideas, maybe the delete post after the check is a non-private internal webpage you can access directly, maybe the server to use is in the request and you can send a server you control, maybe there is a sql injection, or stored xss

  • @Omar-wm9kz
    @Omar-wm9kz 3 ปีที่แล้ว

    Amazing..

  • @karthibalaji3817
    @karthibalaji3817 4 ปีที่แล้ว

    Splendid!.

  • @abhishekmorla1
    @abhishekmorla1 2 ปีที่แล้ว

    Awesome

  • @muzammilkayani777
    @muzammilkayani777 5 ปีที่แล้ว +1

    Great Material

  • @agrawalharshika6538
    @agrawalharshika6538 25 วันที่ผ่านมา

    you're too good in explaining although i request you to make videos on all the owasp top 10

  • @omarsec3178
    @omarsec3178 3 ปีที่แล้ว

    That's great!

  • @berliangigihprakoso6948
    @berliangigihprakoso6948 4 ปีที่แล้ว

    Awesome make video like this again please

  • @chsovi7164
    @chsovi7164 2 ปีที่แล้ว +2

    Can you explain the adding a quote thing?

  • @Samifry
    @Samifry 5 ปีที่แล้ว +1

    i love your content

  • @Sparkette
    @Sparkette 3 ปีที่แล้ว +4

    I once ran into a website that simply had endpoints for fetching and arbitrarily modifying any user's data, and handled all the security logic in the browser. Including comparing the entered password with the user's actual password. In cleartext, of course.
    Oh, and that "modify user data" endpoint? It was more like an "upload file to users directory" endpoint. Which was vulnerable to directory traversal. And since you could specify any file extension...well, let's just say they had rather Pitiful Hack Protection.

    • @123pencilboy
      @123pencilboy ปีที่แล้ว

      Can you get a lawsuit for hacking?

  • @playboicartihey
    @playboicartihey 2 ปีที่แล้ว

    great

  • @jeremiageraldi2123
    @jeremiageraldi2123 5 ปีที่แล้ว

    Cool !

  • @brian_mckenzie8317
    @brian_mckenzie8317 4 ปีที่แล้ว

    Yes I have a question .... I play alot of chess .. and I thank god for chess softwares and chess engines that allow me to practice over and over things I have learnt ... until I get more confident ... and then I like how I can increase the levels as well ... Here's my question .... I have read things and watched your video on IDOR vulnerability ... but I want to practice it ... I want to try it out myself ... and then after I have mastered an easy level I want to be able to increase to harder ones ...
    are there any softwares or websites I can buy that has like 100's of IDOR vulnerabilities that I can use software to exploit and practice all night?? Thanks.

  • @tekken-pakistan2718
    @tekken-pakistan2718 5 ปีที่แล้ว

    Awesome!

  • @viplovebansal3085
    @viplovebansal3085 4 ปีที่แล้ว

    Pretty cool.

  • @tommysuriel
    @tommysuriel 4 ปีที่แล้ว +6

    It's really hard to find this vulnerability now, almost every website out there use a token or some hidden id to check against

    • @arki4433
      @arki4433 2 ปีที่แล้ว

      Luckly

    • @tommysuriel
      @tommysuriel 2 ปีที่แล้ว

      @@arki4433 indeed

  • @hellmick4066
    @hellmick4066 2 ปีที่แล้ว

    "Most of you might add a single of double quote at the end, because it's just an OCD thing at this point"
    I've never heard anything more relatable

  • @CupoChinoMusic
    @CupoChinoMusic ปีที่แล้ว +1

    Managed to find an IDOR in a government webapp.
    Had to send this to them to explain what went wrong 😂😂😂

  • @anatoliisukhomlin9956
    @anatoliisukhomlin9956 3 ปีที่แล้ว

    What's the application are you using for draw your slides?

  • @kirayamato6128
    @kirayamato6128 2 ปีที่แล้ว

    Always implement permission when making an app inorder to restrict some to access other records

  • @kostadingramatikov9692
    @kostadingramatikov9692 3 ปีที่แล้ว

    i have accidentally found one of these in a ecommerce prodocts info site. There was this paid version of the site that will tell you the bset products and you could see for free the common products. But you could change the id in the url and it would not verify your account so you could see other products you are not suposed to the problem was the randomes of the id parameter.

  • @sowhatsupeirik
    @sowhatsupeirik 4 ปีที่แล้ว

    you are fantastic

  • @ashly199
    @ashly199 5 ปีที่แล้ว +1

    I love you!! Keep up the good work.. can I take your knowledge?😂

    • @PwnFunction
      @PwnFunction 4 ปีที่แล้ว +4

      Sure, here you go
      "G😂😂gle".

  • @DEADCODE_
    @DEADCODE_ ปีที่แล้ว

    I love you man 🤗

  • @TNTpeoplenetwork
    @TNTpeoplenetwork 5 ปีที่แล้ว

    Waiting for mores

  • @blomproductions
    @blomproductions 2 ปีที่แล้ว +1

    1337 Elite
    By Björn Gustavsson

  • @faysalahmed7251
    @faysalahmed7251 5 ปีที่แล้ว

    U r boss, bro!

  • @birb9254
    @birb9254 5 ปีที่แล้ว

    Quality Video as always... it would be nice it upload owasp top10 vuln :)...

    • @PwnFunction
      @PwnFunction 5 ปีที่แล้ว +2

      I'll be including them in the `Web Security 101` series.

  • @ashutoshpanda4336
    @ashutoshpanda4336 5 ปีที่แล้ว

    So much better explanation but which music did you use at the end /????

    • @PwnFunction
      @PwnFunction 5 ปีที่แล้ว

      th-cam.com/video/yJg-Y5byMMw/w-d-xo.html

  • @basedboi8852
    @basedboi8852 5 ปีที่แล้ว

    Our local math competition site had this error. It was running nearly the same (PHP!) code since 2003. (It did NOT use POST requests. IT USED A GET REQUEST!!!)

    • @functionaries
      @functionaries 5 ปีที่แล้ว +1

      And how does POST change anything? Lol.

  • @c09yc47
    @c09yc47 3 ปีที่แล้ว

    💓

  • @user-xv9qb6xs4k
    @user-xv9qb6xs4k 2 ปีที่แล้ว

    lol what is AAA anymore if someone codes the gateway like for gigo

  • @yogwaves9935
    @yogwaves9935 3 ปีที่แล้ว

    Im a big dumb but I fucking understood ! Bravo well done 😂😂

  • @prashantkumar2963
    @prashantkumar2963 4 ปีที่แล้ว

    make more videos please.......

  • @Anonymouspock
    @Anonymouspock 5 ปีที่แล้ว

    Wow. LiveOverflow 2.0 :O

  • @int16_t
    @int16_t 3 ปีที่แล้ว

    They can never access it if I wrote my own server and I didn't implemented it.

  • @eduardoandrescastilloperer4810
    @eduardoandrescastilloperer4810 5 หลายเดือนก่อน

    I discovered this vulnerability once on a school website without knowing the formal name. My PDF document with my data was 501.pdf and out of instinct I wondered if there was a 500.pdf and 499.pdf

  • @adekrisna610
    @adekrisna610 5 ปีที่แล้ว

    Next improper acces control pleasee

  • @djt7920
    @djt7920 2 ปีที่แล้ว

    Most of these vulnerabilities worked back in the early stages of MySpace.

  • @official-obama
    @official-obama 2 ปีที่แล้ว

    iDoor: next generation smart lock technology, connects to your phone, fast validation

  • @Jack-zr4kc
    @Jack-zr4kc 3 ปีที่แล้ว

    Ah the php and flask different http?post_id=9&post_id=10

  • @uto-moo
    @uto-moo 4 ปีที่แล้ว

    would someone tell me how to make a video like this?:)

  • @ari_archer
    @ari_archer 3 ปีที่แล้ว

    introducing the new apple technology... iDOOR

  • @Fritttsky
    @Fritttsky 4 ปีที่แล้ว

    Lifeoverflow has literally 1337 as userid?? havent seen use of leet in a long time ;D

  • @dipanshujha7293
    @dipanshujha7293 5 ปีที่แล้ว

    Great explaining the content...keep it up buddy.
    Why u won't come up with 2 videos a week, would be great 🙌

    • @PwnFunction
      @PwnFunction 5 ปีที่แล้ว +2

      Well making these videos take a lot of time anywhere from 2-3 days only for editing audio and the video. The research for the topic also takes more time because I have to read a bunch of blogs, watch hour long talks, play related ctf challenges or find some real world vuln to showcase in the video and read a bunch of writeups which might take anywhere from 3-4 days and on top of that I've got a day job. So putting out 2 vids a week is very hard unless.

  • @a.yashwanth
    @a.yashwanth 4 ปีที่แล้ว +1

    You explain more clearly than live overflow. Not that he doesn't explain well.

  • @kabeerjaffri4015
    @kabeerjaffri4015 3 ปีที่แล้ว

    😍😘😗😙😚

  • @DEADCODE_
    @DEADCODE_ ปีที่แล้ว

    Your sounds looks like jack rhysider

  • @corrywhatever3516
    @corrywhatever3516 3 ปีที่แล้ว

    LEET!

  • @smiley___face
    @smiley___face 2 ปีที่แล้ว

    When you're insecure but also direct at the same time 😳😐

  • @aadarshanand8812
    @aadarshanand8812 3 ปีที่แล้ว

    Why is LiveOverflow always the victim.........seems intentional.

  • @johnniefujita
    @johnniefujita 3 ปีที่แล้ว

    we read "joetee" not "j" "w" "t" 😊👊🏻

  • @crazyfun782
    @crazyfun782 5 ปีที่แล้ว

    1337😍😍😍❤❤❤

  • @PhysicsLK
    @PhysicsLK 3 ปีที่แล้ว

    aaaw

  • @syahrulakbarr
    @syahrulakbarr 5 ปีที่แล้ว +1

    please make video about binary exploitation 😂

  • @LoganLatios
    @LoganLatios 2 ปีที่แล้ว

    everyone does this in roblox

  • @ukuluhamaa5908
    @ukuluhamaa5908 5 ปีที่แล้ว

    Pop filter? Those "p" sounds are kinda loud and distracting

    • @PwnFunction
      @PwnFunction 5 ปีที่แล้ว +1

      I forgot to use it while I record lol

    • @ukuluhamaa5908
      @ukuluhamaa5908 5 ปีที่แล้ว

      @@PwnFunction oh lmao