Тёмный
DEVINER
DEVINER
DEVINER
Подписаться
Welcome to my channel, my name is Hitesh Patra, but in the InfoSec community, I go by the alias DEVINER.

I am a Security Engineer, Bug Hunter, and Red Teamer at heart. I am here to share my knowledge and simplify certain aspects of Cyber Security with all of you. You can expect to find a variety of content on my channel, all related to Cyber Security.

Thank you for joining me on this journey and I hope you will find my content informative and helpful.

Let's learn and grow together!
Комментарии
@InsideDataCenter
@InsideDataCenter 3 дня назад
How many machines we have to hack for passing crtp
@dead_gawk
@dead_gawk 5 дней назад
Thanks for making this!
@dead_gawk
@dead_gawk 5 дней назад
Could you provide your Discord handle?
@sTL45oUw
@sTL45oUw Месяц назад
Raji baba, every idiot can download an easy to install software from the internet
@TodiDiang
@TodiDiang 2 месяца назад
Tutorial for rCDS
@Viperi0
@Viperi0 3 месяца назад
hey bro, can i use vm to setup ctfd and how to add command line to find flags.
@adityavinod109
@adityavinod109 3 месяца назад
Hey I'm not able to figure out how to add challenges, like what files do I include and what files do I leave out
@MrPopworld
@MrPopworld 4 месяца назад
Bro, you didnt even show how you get the flag
@jacobharris2373
@jacobharris2373 5 месяцев назад
I am so confused 😕 I came across this video pn accident is this a vuleability with Dan or what does this this due to domains on Dan in simple terms, thank you very much
@MarsLaaars
@MarsLaaars 5 месяцев назад
Hi, what kind of option in Google Cloud would you recommend for a CTF competition with 50 people?
@Islamictvbd1337
@Islamictvbd1337 5 месяцев назад
Bxss regster video please ❤️
@faniiii
@faniiii 7 месяцев назад
Quick Question : I was using CTFd to host a CTF. I deleted some users' points, and now I want to get the timestamps of the submissions that were deleted from the teams. How can I do it?
@0xdamian816
@0xdamian816 8 месяцев назад
Shinzou Wo Sasageyo!
@ISaIGoI
@ISaIGoI 8 месяцев назад
Its fake guys, don't use this website. Even if your BXSS is fired successfully, you won't get a notification about it!
@ISaIGoI
@ISaIGoI 8 месяцев назад
Hmm, I am not getting any notification even after BXSS got fired!
@pwn16
@pwn16 8 месяцев назад
russian 🤣🤣
@_mrrootsec
@_mrrootsec 9 месяцев назад
Don't use these bxss services
@modawi5
@modawi5 8 месяцев назад
why sir?
@vishalpatidar620
@vishalpatidar620 9 месяцев назад
Thanks for sharing the awesome knowledge and tips
@yashgusain621
@yashgusain621 9 месяцев назад
quite informative❤‍🔥❤‍🔥❤‍🔥 tshirts won't get you somwhere but money will
@vinaybhuria6749
@vinaybhuria6749 9 месяцев назад
Bug bounty king #Manas
@amoh96
@amoh96 9 месяцев назад
Thank you boss
@feedomomics8103
@feedomomics8103 9 месяцев назад
Manas bhai ❤
@Rahulsingh-hj3ts
@Rahulsingh-hj3ts 9 месяцев назад
Pero Hacker❤ ..My Friend #Manas
@Demon_of_Joy
@Demon_of_Joy 9 месяцев назад
Big fan Manus bhai pro hacker 🤩
@parsh_patel
@parsh_patel 9 месяцев назад
Manas peru hackor😲
@karthickt3296
@karthickt3296 9 месяцев назад
Hey, just a quick question. Do you propose deployment using docker or the standard way? Also is it really required to set up a cache server to handle the data say for example 30 users trying to access it simultaneously. Thanks!
@screwedpanda
@screwedpanda 9 месяцев назад
Hey, For 30 users you won't need a cache server, when you are dealing with a large number of users - say 1k + then you would need a cache server. I would recommend going with docker deployment, because it's easy to setup and easy to debug.
@crazyhacker2437
@crazyhacker2437 9 месяцев назад
Bhai kya 1 month Lab enough hai ye course ke liye.
@screwedpanda
@screwedpanda 9 месяцев назад
Yes, if you give sufficient time
@crazyhacker2437
@crazyhacker2437 9 месяцев назад
@screwedpanda daily 2 Hours chal sakta hai kya aur Saturday Sunday ko 6 ghante.
@screwedpanda
@screwedpanda 9 месяцев назад
Should be enough, But again! It completely depends on what your learning speed is and how you plan it. All The Best :)
@crazyhacker2437
@crazyhacker2437 9 месяцев назад
@@screwedpanda thank you. I registered for 2 months lab and exam attempt 😅
@screwedpanda
@screwedpanda 9 месяцев назад
@@crazyhacker2437 Awesome, All The Best :)
@prateek8406
@prateek8406 10 месяцев назад
Hello sir, thankyou so much for this video. I have to ask one thing. I have to conduct ctf in college and I'm expecting participation of 200 users can i do it using azure virtual machine?
@screwedpanda
@screwedpanda 10 месяцев назад
Yes you can use any cloud platforms
@MarsLaaars
@MarsLaaars 5 месяцев назад
​Yo! I'm currently going to setup a CTF with Google Cloud, and I'm expecting 30-50 people to attend. What option on google cloud would you recommend for this kind of usage l? It's only going to be active for 1 day @@screwedpanda
@aaronbryant1154
@aaronbryant1154 10 месяцев назад
Hello, are you still checking comments on this video?
@screwedpanda
@screwedpanda 10 месяцев назад
Yes i do
@aaronbryant1154
@aaronbryant1154 10 месяцев назад
@@screwedpanda Thanks for making the video. My school club is thinking about making a CTF platform using CTFd and I am in the beginner stages of doing research for it. Right now, I got ctfd running on localhost and made a simple trivia challenge, but I am looking for challenge ideas as well as information on making a custom theme for CTFd! Do you have any resources?
@fazlomar9754
@fazlomar9754 10 месяцев назад
Hey! Thanks for making this, it was VERY helpful. My college is hosting a CTF using ctfd, I'm new to all this, will this method count as hosting, i.e. can an external device also connect to this if I give them the ip? Also, is it worth it to host it using the $50 plan ctfd offers? I mean we won't really get more than a 1000 users and we just want to host it for 24h so the $50 for the whole month seems like a wastage. Moreover, this is method seems secure because we have frequent power cuts so it could be trouble if we set it up on our own PCs. Can you please explain these, I seriously need help with this. 🙏🙏🙏🙏
@screwedpanda
@screwedpanda 10 месяцев назад
Hey Man, Glad it helped!! If you don't have a huge user base and more than 24h then don't go with the $50 plan, instead you can get a VPS from GCP or Digital ocean for free when you signup on them. Use this link for Digital ocean - m.do.co/c/47cd3b412bb8 . This will give you 200$ free credit for 60 days, and follow the same process that i show in video, you will be good to go :)
@mohamedeletrepy4740
@mohamedeletrepy4740 10 месяцев назад
are u publish your notes
@screwedpanda
@screwedpanda 10 месяцев назад
Won’t be able to do that as it’s a paid course and property of Altered Security
@KunalKumar-ee7mn
@KunalKumar-ee7mn 10 месяцев назад
​@@screwedpandayou can share notes, lol
@yashgusain621
@yashgusain621 10 месяцев назад
next video about htb pro labs
@screwedpanda
@screwedpanda 10 месяцев назад
soon
@prashanthbodepu4716
@prashanthbodepu4716 10 месяцев назад
Helpful!
@abhasaxena5071
@abhasaxena5071 10 месяцев назад
@abhijitsinha3198
@abhijitsinha3198 10 месяцев назад
@Anshuman bhai 🔥 🔥 🔥 (I know him)💪💪
@shivamrana5766
@shivamrana5766 10 месяцев назад
Anshuman bro🔥🔥🔥🔥
@Laghubitta
@Laghubitta Год назад
Bro don't put this carryminati meme template. It seems so unprofessional.
@screwedpanda
@screwedpanda Год назад
Thanks for the feedback, i will take care of it :)
@satyasaketh7212
@satyasaketh7212 Год назад
You English not so bad bro Don't feel like that.
@screwedpanda
@screwedpanda Год назад
Thanks Man :)
@audreybreda8262
@audreybreda8262 Год назад
Gccz scr
@ebogdan1037
@ebogdan1037 Год назад
Unfortunately its not working, login/register down the drain.
@screwedpanda
@screwedpanda Год назад
You can mail them
@user-ne6fy5qg7j
@user-ne6fy5qg7j Год назад
there is one bookmark 'Bug Bounty Tools' can you share those tools ?
@screwedpanda
@screwedpanda Год назад
Maybe later, I will have to remove some false positive
@cyber_india
@cyber_india Год назад
i'm unable to register fill all requirment but now registered.
@screwedpanda
@screwedpanda Год назад
Please contact their support!
@user-tk7wx7hq4y
@user-tk7wx7hq4y Год назад
Hi! Thank you for your videos, they are very interesting and funny moments. Where did you buy a server to run XSS Hunter?
@screwedpanda
@screwedpanda Год назад
I am glad it helped. You can get any server for free like GCP, DigitalOcean for a short time.
@Rifl3man
@Rifl3man Год назад
Hei, do you have any Idea why the nice Graph isn't showing on my Scoreboard page? it only show the users, score, visibility. But not the nice Graphic/Chart Thx
@screwedpanda
@screwedpanda Год назад
Hey, Soon there will be an updated video on this, Please stay tuned!
@niteshsingh6612
@niteshsingh6612 Год назад
Informative! Great Job buddy👌🏻👍🏻
@screwedpanda
@screwedpanda Год назад
Glad it was helpful!
@chandanchirag2329
@chandanchirag2329 Год назад
Very informative
@chandanchirag2329
@chandanchirag2329 Год назад
Nice video to watch
@ranjitkumarpanda4535
@ranjitkumarpanda4535 Год назад
Thank you so much for producing POCs it really helped me to know about How an attacker attack in the real world scenerio. Keep producing such content. It would be better and become more interactive, if you can come up with webcam.
@screwedpanda
@screwedpanda Год назад
Glad, that helped! I am planning on comming up with webcam soon, just have some setups to do!
@ranjitkumarpanda4535
@ranjitkumarpanda4535 Год назад
@@screwedpanda Waiting with love from odisha 🥰
@Free.Education786
@Free.Education786 Год назад
Dear Sir, Please do cover these crucial topics also. Like... How to bypass Drupal CMS How to bypass WAF protection that stops HTML, SQL, and XSS injection payloads? How to find the real origin IP of secured websites behind Cloudflare, Akamai, ModSecurity, AWS CDN, etc. How to bypass WAF using SQLMAP How to find hidden vulnerable parameters and endpoints inside the.js files? How to find hidden admin panels & cPanel and WHM panels. Please cover these important topics. Thanks
@screwedpanda
@screwedpanda Год назад
Sure, Will take this into consideration!!
@Anonymous-yz5ej
@Anonymous-yz5ej Год назад
Great content bro 💓 where to report the bug coz i found a bug ?
@screwedpanda
@screwedpanda Год назад
Congratulations:) You can directly contact them in chatbox!
@Anonymous-yz5ej
@Anonymous-yz5ej Год назад
@@screwedpanda superb thanks:) and keep going waiting for your more videos 💫
@screwedpanda
@screwedpanda Год назад
Note: At 02:16, when i say it got executed with Blind XSS and was not executing any kind of Normal XSS. The whole point of trying Blind XSS payload here is because there was some validation of executing javascript with normal xss payloads like alert, prompt, confirm. This anyways dosen't have much impact as the blind xss payload gets executed in self session. But, as there were restrictions on certain normal xss payload that's when i tried wth blind XSS payload, which worked. If you need more clarification, feel free to contact :)
@user-tk7wx7hq4y
@user-tk7wx7hq4y Год назад
what is meant by "self session"? Server-side session or something else? Unclear