Тёмный

TikTok Security Vulnerability Report - Username Change Exploit by Sj Almayahi 

Sajad Abdulelah
Подписаться 406
Просмотров 36 тыс.
50% 1

Опубликовано:

 

25 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 110   
@BraveSj
@BraveSj 2 месяца назад
Hello, for now its patched, but i working on it, So subscribe my channel to see if there is an update t.me/z3skrpro
@imamuddinalmustaqim8138
@imamuddinalmustaqim8138 Месяц назад
it's seem to out of scope vulnerability on most platform, as it only informative issue
@WirDawg
@WirDawg 2 месяца назад
It just changes the id name not the real name, I think this is invalid
@zeyadmoustafakamal
@zeyadmoustafakamal 2 месяца назад
This is a not true. you use your session ID which is something you can't get except for your account, so I can't change someone's else username.
@BraveSj
@BraveSj 2 месяца назад
@@zeyadmoustafakamal the bug is to change your username as you like, like a special characters “#,%,^,*?+?=?_,\,|,~,,€,£,¥,•,,?,!,’” And any language you want
@zeyadmoustafakamal
@zeyadmoustafakamal 2 месяца назад
@@BraveSj Oh thanks. and also it seems that they are validating the username in the frontend only which seems to be crazy for engineers who take like more than 100k per year.
@tpevers1048
@tpevers1048 2 месяца назад
What special characters will do lol nothing change..
@Stefikiks
@Stefikiks 2 месяца назад
@@tpevers1048 Looks cool to just put special characters when you cant normally
@death-lt5ig
@death-lt5ig 2 месяца назад
@@zeyadmoustafakamal they check it backend, some old endpoints dont have that check, i used to a lot of tiktok autoclaimer work, and some old endpoints just had no security what so ever except signature checks
@titandelavega5923
@titandelavega5923 Месяц назад
im a backend dev this is bullshit
@sdafasfF
@sdafasfF Месяц назад
there is no vulnerability you are just calling the api endpoint yourself to change your username if it is the fact that you can change it without waiting a time period that is not a vulnerability that is more of a bug which is low level with no risk
@AlA-bd5bg
@AlA-bd5bg 2 месяца назад
This isn’t an vulnerability although TikTok still doesn’t care and just limits the stuff you can do with account like you can’t follow people but this method still works in the iOS api if the account was created and api was requested in certain country’s like uae Brazil Japan
@Astro_Jr0
@Astro_Jr0 28 дней назад
This is just your account's session. Not other's
@SIurps
@SIurps 2 месяца назад
Getting your session id, then using it to send a request to change your nickname to an invalid username. Not really any exploit
@ifrostxy
@ifrostxy 2 месяца назад
yes it is. this is a thing since like 2 weeks and changes the USERNAME, not Nickname, to whatever u want (can use special characters) and bypasses the 2 week waiting time. its called the "font method" and lots of people have been doing it
@SIurps
@SIurps 2 месяца назад
@@ifrostxy Using specific characters on TikTok names is a thing already. But claiming someone else’s username is not possible unless u mean with the font method
@ficknuttensohn
@ficknuttensohn 2 месяца назад
​its not a thing bruh? only if u use an exploit like in this vid@@SIurps
@knight808.
@knight808. 2 месяца назад
⁠@@SIurpswho said anything about claiming someone else’s username?
@SIurps
@SIurps 2 месяца назад
@@knight808. It’s with the font characters though
@mamuli01
@mamuli01 25 дней назад
when mind & chatgpt unite 💪
@MalFuncNoRet
@MalFuncNoRet 20 дней назад
Shit validation with sessionid only?
@CarlosGorg5
@CarlosGorg5 2 месяца назад
فرحت انك عربي لما شفتك كتبت تيست سؤال هل هذا يعني ان يمكن حقنها xss? وانا بحثت عن ذاك اليوزر لم اعثر على نفس الاسم التي بالفديو
@BraveSj
@BraveSj 2 месяца назад
يمكنك حقنها ولكن موجوده حدود وفلاتر، اليوزر غيرته وسويت غيره
@kraussimbituba
@kraussimbituba Месяц назад
Olá meu amigo! Parabéns! Mais um inscrito
@Omeros
@Omeros 2 месяца назад
My man ❤️
@RandomVideos-im4ue
@RandomVideos-im4ue Месяц назад
Brothers it is just inspect element which you are changing through python code.
@xsar5440
@xsar5440 Месяц назад
you do not know how changing a value via inspect element works right? basically if you reload a page anything you change via inspect element will go back to its original value so it has nothing to do with changing values via inspect element. don't know if it actually works I didn't try it but it seems fun
@RandomVideos-im4ue
@RandomVideos-im4ue Месяц назад
@@xsar5440 it didn't changed value via reload in the video because it initiates the sessions of the browser in python program which keep alive the values during reload.
@RandomVideos-im4ue
@RandomVideos-im4ue Месяц назад
@@xsar5440 it didn't changed value via reload in the video because it initiates the sessions of the browser in python program which keep alive the values during reload.
@RandomVideos-im4ue
@RandomVideos-im4ue Месяц назад
@@xsar5440 it didn't changed value via reload in the video because it initiates the sessions of the browser in python program which keep alive the values during reload.
@RandomVideos-im4ue
@RandomVideos-im4ue Месяц назад
@@xsar5440 it didn't changed value via reload in the video because it initiates the sessions of the browser in python program which keep alive the values during reload.
@aziz9488
@aziz9488 2 месяца назад
how is this is a vulnerability loool
@irwys
@irwys 2 месяца назад
how is it not
@aziz9488
@aziz9488 2 месяца назад
@@irwys ok change my username to fuckboy69 that's a vulnerability
@Hugos68
@Hugos68 2 месяца назад
changing your username is something you can already do? Wether you do it via the app that calls the API or call the API through python, it's the same.
@aziz9488
@aziz9488 2 месяца назад
@@Hugos68 bro just discovered APIs lool
@Airtime_Teasers
@Airtime_Teasers 2 месяца назад
@@aziz9488 the point is that he can put any characters he want as his username
@belve1337
@belve1337 2 месяца назад
it still works ?
@zvickyhac
@zvickyhac 2 месяца назад
how to capture sessionID , if use SSL ?
@BraveSj
@BraveSj 2 месяца назад
Its one in the payload
@A3kmander
@A3kmander 2 месяца назад
Perfect 👌
@欠
@欠 2 месяца назад
caught an username before it got patched lolz
@hyperlit1989
@hyperlit1989 Месяц назад
​@@ௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌௌஹi had a YT account thats blanked display lol
@ZSquirrel678
@ZSquirrel678 2 месяца назад
This is no exploit lol, its basic api call that your account has access to 😂
@riccardozappitelli450
@riccardozappitelli450 2 месяца назад
the exploit is that he can put special characters in the username
@IllIIIIIIllll
@IllIIIIIIllll 2 месяца назад
​@@riccardozappitelli450bro it doesn't change his original name, he's just able to change in frontend but after refreshing the old username appears😂.
@logansmlisbackthegamer
@logansmlisbackthegamer 2 месяца назад
@@riccardozappitelli450that’s his display name doofus
@ZestyV8
@ZestyV8 Месяц назад
@@logansmlisbackthegamerno ist Not 💀💀💀👍
@logansmlisbackthegamer
@logansmlisbackthegamer Месяц назад
@@ZestyV8 it is
@advicepicks
@advicepicks 2 месяца назад
you're changing your nickname, not username
@BraveSj
@BraveSj 2 месяца назад
You can check my channel and see the usernames 😉 t.me/z3skrpro
@advicepicks
@advicepicks 2 месяца назад
@@BraveSj oh.
@da40au40
@da40au40 2 месяца назад
Vulnerability for the user not for the server
@ReelFuseBox_YT
@ReelFuseBox_YT 2 месяца назад
Bounty?
@AlyxiaRR
@AlyxiaRR 2 месяца назад
i’m so glad ts got patched lol
@AlA-bd5bg
@AlA-bd5bg 2 месяца назад
It isn’t patched
@AlyxiaRR
@AlyxiaRR 2 месяца назад
@@AlA-bd5bg it is lol
@Leonardoo-o5v
@Leonardoo-o5v Месяц назад
@@AlA-bd5bg yeah he got patched
@Anego5914
@Anego5914 2 месяца назад
it's only visual thing once you close the session it will reset u should tell this to people
@BraveSj
@BraveSj 2 месяца назад
No i posted accounts that i edit and you can visit em T.me/z3skrPro
@overthinker1877
@overthinker1877 2 месяца назад
Is it possible to do it with burp instead of this py script?
@BraveSj
@BraveSj 2 месяца назад
sure, just send HTTP requests to interact with APIs, similar to what the Python script does.
@гексо
@гексо 2 месяца назад
But it's only visible to you, not to other people. (😂🤣)
@BraveSj
@BraveSj 2 месяца назад
@@гексо no, for everyone visit my username, i shared the users i got in my tg t.me/z3skrpro
@picoarsya-chan2903
@picoarsya-chan2903 2 месяца назад
​@@BraveSjprove it with another video
@nested9301
@nested9301 2 месяца назад
Dummy he is change it on the backend
@compan_
@compan_ 2 месяца назад
@@picoarsya-chan2903 its propably patched, but for someone who knows how this works i can confirm that everyone sees it
@bersek-777
@bersek-777 Месяц назад
@@picoarsya-chan2903 bro he called the api how tf should it only be visible for him
@KosmicK1
@KosmicK1 2 месяца назад
Bro changing the user name in the source code 😢😅
@oxfordd.edittt
@oxfordd.edittt 2 месяца назад
0:41 doing a request with customed headers to the tiktok api
@oxfordd.edittt
@oxfordd.edittt 2 месяца назад
and he was just getting his session id
@zdosdev3284
@zdosdev3284 2 месяца назад
this bug is populor now in arabs its working
@546pvp
@546pvp 2 месяца назад
bro
@plugib7129
@plugib7129 Месяц назад
bug bount?
@beyonds8186
@beyonds8186 2 месяца назад
can you share source code? I want to try tho xD
@_R55_
@_R55_ 2 месяца назад
لا تقتل المتعه يا ولد
@Thirumurug0xan
@Thirumurug0xan 2 месяца назад
Got it 👍
@Tliver
@Tliver 2 месяца назад
script>?
@hlcd-7191
@hlcd-7191 2 месяца назад
it’s still work ?
@BraveSj
@BraveSj 2 месяца назад
@@hlcd-7191 yep
@hlcd-7191
@hlcd-7191 2 месяца назад
@@BraveSj script please ?
@BraveSj
@BraveSj 2 месяца назад
@@hlcd-7191 t.me/z3sbot
@CarlosGorg5
@CarlosGorg5 2 месяца назад
ممكن ترسلي الكود ما عندي تلغيرام
@BraveSj
@BraveSj 2 месяца назад
instagram.com/ss_j
@xearie
@xearie 2 месяца назад
how?
@BraveSj
@BraveSj 2 месяца назад
t.me/BraveSj
Далее
Is Valorant Spyware?
8:15
Просмотров 839 тыс.
how is this hacking tool legal?
11:42
Просмотров 317 тыс.
I get on the horse's nerves 😁 #shorts
00:12
Просмотров 3 млн
The TRIPLE FOLDING phone has a Problem.
12:54
Просмотров 515 тыс.
Ruining Discord Servers with a Bot Exploit!
9:32
Просмотров 528 тыс.
Discord Connections Are Broken...
7:01
Просмотров 453 тыс.
Watch me hack a Wordpress website..
28:52
Просмотров 266 тыс.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
Просмотров 687 тыс.
How Open Source Discord "Raiding" tools hide Malware
11:08
I Used Code to Go Viral on Social Media
8:54
Просмотров 243 тыс.
How THIS button is hacking people
11:23
Просмотров 50 тыс.
How to HACK ChatGPT
4:53
Просмотров 344 тыс.
Learn Reverse Engineering (for hacking games)
7:26
Просмотров 1,1 млн