Тёмный

HTB Academy: Attacking Web Applications with FFUF - Vhost Fuzzing and Filtering Results 

ITalia Tech
Подписаться 649
Просмотров 5 тыс.
50% 1

In this video, I walk through the "filtering results" exercise in the FFUF HTB Academy module.
The link below helps explain how virtual hosts work. As a quick summary, you can run several websites on the same server. So in order to locate those extra websites or domains, we need to do virtual host fuzzing.
When a webserver receives a request, it looks for the hostname in the HTTP header, and depending on the hostname, it serves different websites. So when we're fuzzing for those different websites/domains, we're using that common subdomain wordlist and see which ones return results. This means we need to filter the results that we get initially when we run our first ffuf command that you will see in the video.
www.thegeekstu...

Опубликовано:

 

4 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 5   
@alexealexe3127
@alexealexe3127 2 года назад
a very good explanation
@italia-tech
@italia-tech 2 года назад
Thanks! Much appreciated!
@cloudliving447
@cloudliving447 Год назад
thanks for help, i was really stuck
@HungTran-tz9uj
@HungTran-tz9uj 3 месяца назад
Good, thanks for tutorial
@m7mad540
@m7mad540 Год назад
thx
Далее
How to Look For Virtual Hosts // How To Bug Bounty
12:53
TRENDNI BOMBASI💣🔥 LADA
00:28
Просмотров 695 тыс.
DNS Enumeration Tutorial - Dig, Nslookup & Host
20:52
Просмотров 120 тыс.
Fuzzing & Directory Brute-Force With ffuf
51:20
Просмотров 47 тыс.
Web Enumeration - Virtual Hosts
30:05
Просмотров 369
How to use Gobuster to find hidden web content
6:21
Discover hidden assets using Host Header Injection
15:05
What is Fuzzing (using ffuf)
12:54
Просмотров 19 тыс.