849 тысяч подписчиков
184 видео
SQL Injection | Complete Guide
SQL Injection - Lab #1 SQL injection vulnerability in WHERE clause allowing retrieval of hidden data
Cross-Site Request Forgery (CSRF) | Complete Guide
SQL Injection - Lab #2 SQL injection vulnerability allowing login bypass
SQL Injection - Lab #3 SQLi UNION attack determining the number of columns returned by the query
SQL Injection - Lab #11 Blind SQL injection with conditional responses
Cross-Origin Resource Sharing (CORS) | Complete Guide
Server-Side Request Forgery (SSRF) | Complete Guide
Introduction to the Web Security Academy Series
Broken Access Control | Complete Guide
SQL Injection - Lab #4 SQL injection UNION attack, finding a column containing text
Directory Traversal - Lab #1 File path traversal, simple case | Short Version
Command Injection - Lab #3 Blind OS command injection with output redirection | Long Version
SQL Injection - Lab #5 SQL injection UNION attack, retrieving data from other tables
Directory Traversal - Lab #3 File path traversal, traversal sequences stripped | Short Version
Authentication Vulnerabilities - Lab #6 Broken brute-force protection, IP block | Long Version
Command Injection - Lab #2 Blind OS command injection with time delays | Long Version
Command Injection - Lab #5 Command injection with out-of-band data exfiltration | Long Version
Command Injection - Lab #1 OS command injection, simple case | Short Version
Broken Access Control - Lab #3 User role controlled by request parameter | Long Version
PEN-200 (OSCP) 2023 UPDATE REVIEW!!
Broken Access Control - Lab#2 Unprotected admin functionality with unpredictable URL | Short Version
Directory Traversal - Lab #4 Path traversal sequences stripped w/ URL-decode | Long Version
SQL Injection - Lab #6 SQL injection UNION attack, retrieving multiple values in a single column
SQL Injection - Lab #12 - Blind SQL injection with conditional errors
CSRF - Lab #1 CSRF vulnerability with no defenses | Long Version
Directory Traversal - Lab #6 Validation of file extension with null byte bypass | Long Version
SSRF - Lab #3 SSRF with blacklist-based input filter | Short Version
CORS - Lab #1 CORS vulnerability with basic origin reflection | Short Video
Broken Access Control - Lab #11 Insecure direct object references | Short Version
Broken Access Control - Lab #12 Multi-step process with no access control on one step | Long Version
SQL Injection - Lab #15 Blind SQL injection with out-of-band interaction
Authentication Vulnerabilities - Lab #5 Username enumeration via response timing | Short Version
Mastering Directory Traversal Vulnerabilities - The Ultimate Hands-On Course on Udemy!
SSRF - Lab #1 Basic SSRF against the local server | Short Version
Authentication Vulnerabilities - Lab #14 2FA bypass using a brute-force attack | Short Version
SQL Injection - Lab #17 SQL injection with filter bypass via XML encoding | Long Version
Broken Access Control - Lab #1 Unprotected admin functionality | Long Version
Broken Access Control - Lab # 13 Referer-based access control | Long Version
SQL Injection - Lab #18 Visible error-based SQL injection | Short Version
SQL Injection - Lab #14 Blind SQL injection with time delays and information retrieval
Authentication Vulnerabilities - Lab #11 Password reset poisoning via middleware | Long Version
CSRF - Lab #2 CSRF where token validation depends on request method | Short Version
Mastering Command Injection Vulnerabilities - The Ultimate Hands-On Course on Udemy!
SQL Injection - Lab #10 SQL injection attack, listing the database contents on Oracle
SQL Injection - Lab #17 SQL injection with filter bypass via XML encoding | Short Version
SQL Injection - Lab #8 SQLi attack, querying the database type and version on MySQL & Microsoft
SSRF - Lab #1 Basic SSRF against the local server | Long Version
Command Injection | Complete Guide
SQL Injection - Lab #18 Visible error-based SQL injection | Long Version
Command Injection - Lab #4 Blind OS command injection with out-of-band interaction | Long Version
Broken Access Control - Lab #2 Unprotected admin functionality with unpredictable URL | Long Version
Authentication Vulnerabilities - Lab #7 Username enumeration via account lock | Long Version