Тёмный

SQLi WAF Bypass Techniques Part 2 - Other Attacks 

Ott3rly
Подписаться 3 тыс.
Просмотров 1,2 тыс.
50% 1

Опубликовано:

 

1 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 11   
@MdAsifulHuq
@MdAsifulHuq 2 месяца назад
Thanks for the invaluable resources
@MdAsifulHuq
@MdAsifulHuq 2 месяца назад
Really so under ratrd
@Bug1HunterMit
@Bug1HunterMit Месяц назад
Firstly, thanks so much for your videos, they are very informative. Had a quick question - I frequently see some cases where SLEEP(n) works for one request, where the delay of n seconds is seen. But subsequent requests don't have that delay. Neither are the requests blocked themselves. In your experience, do WAFs have rules, which accept such requests, but have ML/AI, where it matches such a request with SLEEP with response timings, and only manipulates the response time after seeing one successful sleep attempt, by returning a generic response at some random interval for future responses? In other words, if it senses the backend is delaying, it just returns the previous response or something as is? Probably as an attempt to not overtly give away what it is blocking? When a sleep executes for the exact amount in the payload, it's hard to ignore! Not sure if any random server behind the scenes causes a sleep, but I am leaning towards some learning algorithm in WAFs that are now doing this - I did see some bounty reports as well, where people were not able to reproduce the delay due to sleep...
@Ott3rly
@Ott3rly 28 дней назад
Never went that deep into how WAF works actually. It could be many things, sometimes the servers themselves are slow, sometimes there could be some AI/ML defenses in place, honeypot redirects, etc.
@bugbouty
@bugbouty 4 месяца назад
great ott3rly
@ss-rc1gy
@ss-rc1gy 4 месяца назад
very underrated content , keep going :D
@mysteriousministar2481
@mysteriousministar2481 4 месяца назад
what about ghauri ? or + version
@Ott3rly
@Ott3rly 4 месяца назад
ghauri was shown in previous video.
@jayasurya3485
@jayasurya3485 4 месяца назад
Thankyou.
Далее
SQLi WAF Bypass Techniques Part 1 - Time-Based Attacks
10:46
Own Blind XSS Server Setup
15:20
Просмотров 197
HTTP Parameter Pollution Explained
11:08
Просмотров 252 тыс.
Introducing 0DE5
39:38
Просмотров 88 тыс.
Level Up Your Port Scanning Skills
11:25
Просмотров 1,6 тыс.
XSS WAF Bypass Techniques
11:39
Просмотров 4,9 тыс.