Server-Side Request Forgery (SSRF) Explained

  Рет қаралды 22,246

NahamSec

NahamSec

Жыл бұрын

Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training
Buy Me Coffee:
www.buymeacoffee.com/nahamsec
Live Every Sunday on Twitch:
/ nahamsec
Free $100 DigitalOcean Credit:
m.do.co/c/3236319b9d0b
Follow me on social media:
/ nahamsec
/ nahamsec
twitch.com/nahamsec
hackerone.com/nahamsec
/ nahamsec1
Github:
github.com/nahamsec
Nahamsec's Discord:
discordapp.com/invite/ucCz7uh
#offensivesecurity #redteam #bugbounty #hackerone #hackers #hacking #infosec #hackingtutorial #owasp #educational

Пікірлер: 98
@francoischaer
@francoischaer Жыл бұрын
hey Ben, we surely already love your content, but, for those like me, who are new to the industry, trying to learn and move forward, we need the technical, very basic content, this will help us understand more in depth how things goes. thank you again for the great content you are delivering, and for the amount of dedication you are putting in
@bashiqali2142
@bashiqali2142 Жыл бұрын
Content + real vulnerability example would be great 🔥
@citywitt3202
@citywitt3202 7 ай бұрын
As CEO of a startup please keep this stuff coming. It took a lot to convince the dev team that exploits weren’t just down to weak passwords so I arranged an in house demo. Jaws dropped. This stuff builds so much awareness. Thank you!
@irfankhalid3122
@irfankhalid3122 Жыл бұрын
Never thought I could learn SSRF in a more comprehensive way by under 15 minutes! Thanks man!
@NahamSec
@NahamSec Жыл бұрын
Thanks! I'm glad it helped!
@BlancoBox
@BlancoBox 7 ай бұрын
While I may not have commented before, I've been an avid admirer of your work. As an aspiring pentester, I find your technical content to be precisely what I seek. While your other content is commendable, it's ultimately the expertise you bring that I look up to for learning. Your contributions are truly appreciated.
@baraamansi7637
@baraamansi7637 Жыл бұрын
OFC it would be truly helpful to see more content like this
@shiewhun1772
@shiewhun1772 Жыл бұрын
Yes, this is great. From a web developer perspective. I'm trying to under how my server side applications could be hacked and this is great content. Please, continue.
@sveneFX
@sveneFX Жыл бұрын
Fully in with technical vids, especially when you chain these with Real life vulns you have found 👌
@vaibhavsangwan996
@vaibhavsangwan996 Жыл бұрын
Hey I absolutely love this, I would love to learn from more technical videos like this.
@rllan006
@rllan006 Жыл бұрын
100% both. I like the nuance you teach here. For example login page and SSRF. This is fantastic content.
@janekmachnicki2593
@janekmachnicki2593 9 ай бұрын
Content + real+technical aspect of pen testing and bug hunting .Thanks
@user-yq1ov8re3s
@user-yq1ov8re3s 5 ай бұрын
More content is needed like this along with real life examples that you experienced during bug bounty or other testing application
@billelghezal7855
@billelghezal7855 Жыл бұрын
Thank you very much, I hope you'll continue doing these kind of videos 😊
@JPwnage
@JPwnage Жыл бұрын
Man, keep both coming.!! maybe pick a day to post technical and assign another day for the mentorship aspects or something... Either way ... BOTH ARE EQUALLY IMPORTANT FOR SUCCESS!! ...Also i would love a video on how to transfer from labs /ctf into hacking real world apps. As the fundamentals are the same or close but also very different in alot of ways.
@supritpandurangi5647
@supritpandurangi5647 Жыл бұрын
Waiting for this type of content ; please Continue Ben :)
@ss-rc1gy
@ss-rc1gy Жыл бұрын
fantastic :o , i would like to see a full and advanced recon video from you :)
@Free.Education786
@Free.Education786 Жыл бұрын
Please, if possible, cover these advanced topics like How to bypass Drupal CMS or other secured CMS? How to bypass HARD WAF protection that stops HTML, SQL, and XSS injection payloads? Payload single-double-triple encoding using Cyber-Chef? How to find the real origin IP of secured websites behind Cloudflare, Akamai, ModSecurity, AWS CDN, etc.,? How to bypass Hard WAF using SQLMAP or Burpsuite? How to find hidden vulnerable parameters and endpoints inside the .js and .jason files? How to find hidden admin pages, cPanel pages, and WHM pages ? Please cover these important topics. Thanks
@long2330
@long2330 Жыл бұрын
Thanks for helpful content! It would be great if u could do more specific showcases about blind SSRF. For example there is a case that I only receive the DNS queries back to the collab. I guess because of outbound restriction but it seems like the server was trying to reach to that domain. Any way in this case that you can prove the ssrf is there with just DNS? Or do you have any suggestion on setting up things in internal network to prove the vulnerability is there? Was a long comment but hope u could imagine the case 😂 thanks
@user-ie1hp3el3m
@user-ie1hp3el3m 10 ай бұрын
Hi man, I would like to hear you how to do bug bounties exactly and maybe if you can show on live all the necessary steps to do it
@yourinatestrn3436
@yourinatestrn3436 Жыл бұрын
Yea would love this type of content plz part 2
@ethyhack
@ethyhack Жыл бұрын
yes please, give us more content of this kind.
@GrimComix
@GrimComix Жыл бұрын
Yes, more content like this please 😁
@lovedaysmart9183
@lovedaysmart9183 Жыл бұрын
Just what we need Ben 😊 thank you 👏🏻
@3N18AKPzmGOsBgWKH
@3N18AKPzmGOsBgWKH Жыл бұрын
Haya! I have quite a lot of experience in pentesting webapps, but i do not have any experience in hosting an instance of a webserver, securing it or being able to load an insecure server, but in a secure way cause we don't want a creepy scanner rooting it and being malicious when i want to test it :P So my question, could you make a lill tutorial in how to, for example, use a docker or maybe host a site in different means through a Digital Ocean instance? :P Would be fun to learn a little bit about it and then being able to pentest towards it. By learning this, one can use your knowledge to host a file hosting instance to make an RFI etc, which is a bit difficult without an outwards facing host ^^ Stay safe and happy late Easter!
@augustvansickle1
@augustvansickle1 Жыл бұрын
Would love to see more technical content! TIA
@The_capitol
@The_capitol Жыл бұрын
I would like to see one of the vulnerabilities you have found and walk through the info gathering stage all the way to the post exploit while explaining the mindset/methodology
@NahamSec
@NahamSec Жыл бұрын
Soon :)
@volatileobj3cts
@volatileobj3cts Жыл бұрын
Super down with more technical content!
@vibhavtiwari7260
@vibhavtiwari7260 Жыл бұрын
we need more part of this
@andrewsan2998
@andrewsan2998 Жыл бұрын
East or West, naham is the best.
@BulbulBigbossbd
@BulbulBigbossbd Жыл бұрын
Hi NahamSec, I'm a regular viewer of your content.can you make video on business logic in dept!! waiting for it
@amoh96
@amoh96 11 ай бұрын
We really want this explain bugs for beginners and give us some advice about the bug i really wish u make playlist for this !! thank u alot
@ogbooker4538
@ogbooker4538 Жыл бұрын
both content is fine and some free tutorials
@zak6820
@zak6820 Жыл бұрын
Yes more content like this pls
@bugs-lk3jf
@bugs-lk3jf 11 ай бұрын
Great Content; More Please 🤑
@ogbooker4538
@ogbooker4538 Жыл бұрын
stay consistent big bro
@heli_9
@heli_9 Жыл бұрын
I’d love more technical videos
@jeremyg737
@jeremyg737 Жыл бұрын
part 2? more content like this!
@onsiyammalembe1546
@onsiyammalembe1546 Жыл бұрын
I love this content make more please
@SecurityVaultYT
@SecurityVaultYT Жыл бұрын
Epic, Part 2 please.
@tehlan6340
@tehlan6340 Жыл бұрын
You are great bro
@devanshuthanvi731
@devanshuthanvi731 Жыл бұрын
Perfect type of content 😃👍
@firosiam7786
@firosiam7786 Жыл бұрын
Is Bola and idor the same type of vulnerability with different names
@dtchallohfranc3360
@dtchallohfranc3360 11 ай бұрын
Part 2 please 😍
@rafekhen4263
@rafekhen4263 Ай бұрын
more content like this please
@Drakan1990
@Drakan1990 6 ай бұрын
More please!
@soulvideos7834
@soulvideos7834 Жыл бұрын
More content like this 🙂🙏❤️🔥
@tabysh_s5016
@tabysh_s5016 Жыл бұрын
Ben One Suggestio | Make a precise playlist of OWASP TOP 10 2021 | Like a 10 min video / on each critical vulnerability
@fadelafanmahendra653
@fadelafanmahendra653 Жыл бұрын
more content like THIS!
@andrewlentz1205
@andrewlentz1205 Жыл бұрын
I think you should pivot to doing Unboxing Videos. If that's not in the cards then please keep the technical videos coming!
@samadafridi1059
@samadafridi1059 2 ай бұрын
part 2 or complete playlist on the web Vuln
@TrecXsec
@TrecXsec Жыл бұрын
More part 2. Need more technical vids
@LulzWalker
@LulzWalker Жыл бұрын
Love this!
@irvingirving6275
@irvingirving6275 Жыл бұрын
Preach!
@gokul5582
@gokul5582 Жыл бұрын
What to do if we don't have burp collaboraor ?
@djrozh5438
@djrozh5438 Жыл бұрын
Creat a playlist content like the types of vulnerabilities and bugs that are common or rate easy to hard like xss or account takover
@stevejones371
@stevejones371 Жыл бұрын
More, more more real world how to once we have done recon. We need to know the steps on how to find bugs.
@alihussainzada3392
@alihussainzada3392 Жыл бұрын
It was awesome Next xxe plz
@imosolar
@imosolar 11 ай бұрын
More real bugbouty tech work
@CookingCooking77
@CookingCooking77 Ай бұрын
MORE CONTENT !!!
@Tergaurav
@Tergaurav Жыл бұрын
Vulnerability content or owasp top 10 pls
@tchalla109
@tchalla109 Жыл бұрын
Drop video with all of the topic you mentioned in the video.
@SunilTiwari-ez9lj
@SunilTiwari-ez9lj Жыл бұрын
More parts on this topic ..
@CYBER_BLUE4
@CYBER_BLUE4 4 күн бұрын
Part two
@loneliestwolf4228
@loneliestwolf4228 Жыл бұрын
Part 2 please....
@user-vz5de3sv2e
@user-vz5de3sv2e Жыл бұрын
I would like to see basic contents like this.
@user-pv6ge1li5t
@user-pv6ge1li5t 3 ай бұрын
more vcontent like this cover all top 10 owasp vulnerability please...
@Aashishsec
@Aashishsec Жыл бұрын
more content on web attacks
@braaemad2745
@braaemad2745 Жыл бұрын
more and more plz
@NathanielMitchellnm
@NathanielMitchellnm Жыл бұрын
Part 2!
@mindf4rt
@mindf4rt Жыл бұрын
More pls =)
@noureldinehab2686
@noureldinehab2686 Жыл бұрын
💙
@suryaroja03
@suryaroja03 Жыл бұрын
please post content like this...thank you
@taqiuddinismail9542
@taqiuddinismail9542 8 ай бұрын
more content like thiss
@akeelw084
@akeelw084 2 ай бұрын
part 7 we want
@mahdihasan42
@mahdihasan42 Жыл бұрын
we need location traking tutorial
@bashiqali2142
@bashiqali2142 Жыл бұрын
😊
@aavezsheikh5781
@aavezsheikh5781 Жыл бұрын
More content
@weniweedeewiki.6237
@weniweedeewiki.6237 Жыл бұрын
PART 2 BRO DEFO
@Asadneon
@Asadneon 3 ай бұрын
web hacking content more please
@drive8263
@drive8263 Жыл бұрын
Both....
@raghvendrachouhan3433
@raghvendrachouhan3433 10 ай бұрын
theory is all good but when it comes to practical i'm hopeless.
@husamgameel1489
@husamgameel1489 Жыл бұрын
yup yup more tutorials for hacking and IT stuff how to do ore bypass
@ZarakKhanNiazi
@ZarakKhanNiazi Жыл бұрын
I love you naham
@NahamSec
@NahamSec Жыл бұрын
@SalimShaikh-ip7gi
@SalimShaikh-ip7gi Жыл бұрын
Part2
@0xbeven462
@0xbeven462 Жыл бұрын
I reported my browser 😂
@entertainment_in_blood
@entertainment_in_blood 8 ай бұрын
PART-2
@srcybersec1736
@srcybersec1736 Жыл бұрын
Want more vdo
@navidof5
@navidof5 Жыл бұрын
part 2
@user-bs1ju9yt5m
@user-bs1ju9yt5m Жыл бұрын
Part 2 ,,4,5,6,7,8,9,-----,99999
@mahdihasan42
@mahdihasan42 Жыл бұрын
location hack
@Haxr-dq6wt
@Haxr-dq6wt 11 ай бұрын
Bad explanation with a lot or wrong info
@tehlan6340
@tehlan6340 Жыл бұрын
I make hacking videos
@handle_my_handle
@handle_my_handle Жыл бұрын
Part 2
@yourmove9993
@yourmove9993 Жыл бұрын
part 2
@JD-wj1bf
@JD-wj1bf 10 ай бұрын
Part 2
Server-Side Request Forgery (SSRF) | Complete Guide
47:04
Rana Khalil
Рет қаралды 62 М.
WHY IS A CAR MORE EXPENSIVE THAN A GIRL?
00:37
Levsob
Рет қаралды 17 МЛН
Can you beat this impossible game?
00:13
LOL
Рет қаралды 55 МЛН
1 класс vs 11 класс (неаккуратность)
01:00
$10,000 Every Day You Survive In The Wilderness
26:44
MrBeast
Рет қаралды 94 МЛН
WHY YOU SUCK AT HACKING // How To Bug Bounty
10:05
NahamSec
Рет қаралды 20 М.
If I Were to Start in Cyber Security, I'd Do This
13:40
NahamSec
Рет қаралды 11 М.
Attacking organizations with big scopes: from zero to hero
50:50
Positive Events Eng
Рет қаралды 6 М.
Server-Side Request Forgery (SSRF) Explained And Demonstrated
6:13
Loi Liang Yang
Рет қаралды 76 М.
Cross-Site Request Forgery (CSRF) Explained
11:59
NahamSec
Рет қаралды 14 М.
Server-Side Request Forgery (SSRF) | Demo
5:28
ITPro
Рет қаралды 25 М.
Cross Site Request Forgery - Computerphile
9:20
Computerphile
Рет қаралды 755 М.
How I found the $1,500 SSRF in Stripe bug bounty program
9:09
Bug Bounty Reports Explained
Рет қаралды 10 М.
Cross Site Request Forgery vs Server Side Request Forgery Explained
12:23
wyłącznik
0:50
Panele Fotowoltaiczne
Рет қаралды 24 МЛН