Watch how Hackers deface websites...

  Рет қаралды 13,793

Tech Raj

Tech Raj

5 ай бұрын

Check out Fing, an awesome network administration tool that lets you manage your network like a Pro! Get 25% off on the premium version using my link: bit.ly/3wOU6e1
In this video, I demonstrate how hackers deface websites with Stored Cross Site Scripting (XSS). Stored cross-site scripting arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe way.
If you don't know what defacing is, it simply means maliciously changing the content of a website so that whenever any user goes to the website they see the content that has been put there by the hacker instead of the actual website.
The website that I used in this video is an open source web application that is built to be vulnerable to numerous vulnerabilities. I made some minor modifications to the app to help me perform my demonstration.
The modified docker image of the app can be found here: hub.docker.com/r/tejaswaroop1...
DISCLAIMER: This video is intended only for educational purposes.
The experiments in this video are performed in a controlled
lab setup and not on a live target. The content is purely
from a penetration testing perspective. I do not
condone or encourage any illegal activities.
To setup this vulnerable app on your computer, install docker and execute these commands:
1. Pull the Image from docker hub:
docker pull tejaswaroop156/juice_shop_mod
2. Start the app
docker run -d -p 3000:3000 tejaswaroop156/juice_shop_mod
Join my Discord: / discord
Follow me on Instagram: / teja.techraj
Website: techraj156.com​​​​​
Blog: blog.techraj156.com
Thanks for watching!
SUBSCRIBE for more videos!

Пікірлер: 44
@mnageh-bo1mm
@mnageh-bo1mm 5 ай бұрын
man your videos are so clear and the music is just mwah
@user-jp6ud3qx6l
@user-jp6ud3qx6l 5 ай бұрын
Long time here. Best video ❤
@mohitjain4943
@mohitjain4943 5 ай бұрын
Have been watching you for years!
@xXxMAKAR0VxXx
@xXxMAKAR0VxXx 4 ай бұрын
Wow, you really intelligent and full of knowledge
@leyashu0799
@leyashu0799 5 ай бұрын
Hello buddy, can you make a full course on website defacement please
@vlogsprasenjit
@vlogsprasenjit 5 ай бұрын
Great Video 👍
@girivasan4311
@girivasan4311 4 ай бұрын
Hi How to install wordpress in subdirectory in aws
@Arian-Ices
@Arian-Ices 5 ай бұрын
How does fing block system work as it's doesn't access your router admin panel
@user-hq8wm8giyujcg
@user-hq8wm8giyujcg 4 ай бұрын
Can i use social media by create account in them through being anonymous
@Alfaz_Infosec
@Alfaz_Infosec 14 күн бұрын
Thanks❤
@saleemahmed8302
@saleemahmed8302 4 ай бұрын
So after injecting the payload how does a website get rid of the code? Because in real world scenarios this can cause a lot of damage.
@ttgyanofficial
@ttgyanofficial 5 ай бұрын
Full video on this with full explanation
@codeberry8230
@codeberry8230 Ай бұрын
It is full video and all things all explained
@arthatattvam7542
@arthatattvam7542 21 күн бұрын
Bro this changes only seen by us when we login with our credentials. How these changes become permanent to other user also
@opposite342
@opposite342 Ай бұрын
1. I don't think this changes every part of the website. Just the url that linked to this user. I might be wrong here but that's how I interpreted this. Especially if the server rerenders thing on requests (Say with a templating engine). Then I don't see how this could pollute any code outside on this user's link. 2. The initial payload needs to be hosted, but once it's does its job, depending on whether the website backends rerenders the page on request or not, it might not needed to be continuously hosting. However, in most modern sites it most likely will still be rerendered. So you will have to continuously host the script.js somewhere. Now, what's the point of this? Say if you have a site someone can donate to you via your user page. You can have a part of your bio be replacing the donate button to link to your own site - and then card stealing that way. (Literally 101 example of xss)
@opposite342
@opposite342 Ай бұрын
Essentially, the target user has to have the script run on their browser. If you search xss and then go to snyk's link on it, you'll even see that their example relied on you chatting a user and the script being passed onto that user's browser - which is the essentials needed for xss.
@SCLEDONFF
@SCLEDONFF 4 ай бұрын
bro HTML page not showing why ??
@user-hq8wm8giyujcg
@user-hq8wm8giyujcg 4 ай бұрын
Im learning hacking, can u tell me what are the best pro hacking group i want to join
@krivadnaaiservices
@krivadnaaiservices 5 ай бұрын
How to host a file on the target website where we left the xss payload.. that's is where the defacement takes place...
@Awesomium3
@Awesomium3 2 ай бұрын
he wont tell
@ttgyanofficial
@ttgyanofficial 5 ай бұрын
Another video on this topic
@beatboss8702
@beatboss8702 5 ай бұрын
How r u doing brother 😁💥
@bablubawra1352
@bablubawra1352 4 ай бұрын
make video how to email spoof happens
@robyee3325
@robyee3325 5 ай бұрын
Isn’t this similar to sql injection?
@vasipalle
@vasipalle 5 ай бұрын
sql injections are bascially cross site scripting (XSS) for databases, this can allow users to download, modify and delete the database or parts of it. XSS on the other hand only works for websites, hence HTML tags
@robyee3325
@robyee3325 5 ай бұрын
@@vasipalle thanks!
@ra.njan_kr
@ra.njan_kr 5 ай бұрын
Good video ,need more ways to hack website... (For learning purposes)
@ra.njan_kr
@ra.njan_kr 5 ай бұрын
Or if any resources or video ,just paste the link of that video or resources.. please
@INDIANchhanel-ii7zz
@INDIANchhanel-ii7zz 5 ай бұрын
😂😂😂
@user-hq8wm8giyujcg
@user-hq8wm8giyujcg 4 ай бұрын
Video on how to find someones phone number, address, email, password, ip address in the first place
@user-ur1db8pc6i
@user-ur1db8pc6i 5 ай бұрын
Hi I
@jokerhackr
@jokerhackr 5 ай бұрын
I want to make a script for a game, brother, I want to earn money. Tell me brother, will you help me?
@jokerhackr
@jokerhackr 5 ай бұрын
how do i contact you
@rockyforreal
@rockyforreal 4 ай бұрын
I think Bro wakeup from a coma
@user-hq8wm8giyujcg
@user-hq8wm8giyujcg 4 ай бұрын
How to hack social media companies and power my social media account so that no one cant block me and my post get popular and on top
@e-talian1245
@e-talian1245 Ай бұрын
It is because
@PARIKAKU
@PARIKAKU 5 ай бұрын
Comeback
@user-hq8wm8giyujcg
@user-hq8wm8giyujcg 4 ай бұрын
How to hack and destroy systems
@e-talian1245
@e-talian1245 Ай бұрын
Yes
@DynamicLights
@DynamicLights 2 ай бұрын
Educational purposes only 😂
@RubinBastakoti
@RubinBastakoti 3 ай бұрын
HELLO
@MarshmelloGTAG
@MarshmelloGTAG 5 ай бұрын
alert(1)
@The_offical_M
@The_offical_M 4 ай бұрын
Bro that not gonna work😂😂😂😂
Solving a REAL investigation using OSINT
19:03
Gary Ruddell
Рет қаралды 153 М.
Comfortable 🤣 #comedy #funny
00:34
Micky Makeover
Рет қаралды 12 МЛН
Mama vs Son vs Daddy 😭🤣
00:13
DADDYSON SHOW
Рет қаралды 51 МЛН
WORLD'S SHORTEST WOMAN
00:58
Stokes Twins
Рет қаралды 133 МЛН
Box jumping challenge, who stepped on the trap? #FunnyFamily #PartyGames
00:31
Family Games Media
Рет қаралды 22 МЛН
I legally defaced this website.
25:48
thehackerish
Рет қаралды 512 М.
3 Levels of WiFi Hacking
22:12
NetworkChuck
Рет қаралды 1,8 МЛН
How Hackers do Phishing Attacks to hack your accounts
20:49
Tech Raj
Рет қаралды 189 М.
How Hackers Write Malware & Evade Antivirus (Nim)
24:04
John Hammond
Рет қаралды 394 М.
How to make Portable Hacking Machine? || PNPtutorials
27:20
PNP Tutorials
Рет қаралды 20 М.
How to Scan ANY Website for Vulnerabilities!
6:26
CyberFlow
Рет қаралды 85 М.
This is how Hackers can *OWN YOU* with just a link!
8:05
Tech Raj
Рет қаралды 1,5 МЛН
How Hackers Bypass Kernel Anti Cheat
19:38
Ryscu
Рет қаралды 625 М.
I Hacked Another File Upload Website
32:50
John Hammond
Рет қаралды 262 М.
Stop, Intel’s Already Dead! - AMD Ryzen 9600X & 9700X Review
13:47
Linus Tech Tips
Рет қаралды 1 МЛН
КРУТОЙ ТЕЛЕФОН
0:16
KINO KAIF
Рет қаралды 7 МЛН