Lots of #bugbountytips get posted on Twitter, but some of them are... weird. Let's explore the technical details of one tweet to understand where this tip came from, why this tip was wrong, and eventually learn about the real underlying vulnerability. This is a surprising turn of events!
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Join the Hextree Discord: / discord
Authentication Bypass Due to Empty Where Clause and SQL Injection in CodeIgniter: https://liveoverflow.com/authenticati...
Thank you Eslam for sharing the details with us!
Follow Eslam on Twitter: / eslam3kll
The #bugbountytips tweet: / 1526795822687346688
Eslam's old post: https://infosecwriteups.com/authentic...
Eslam's new blog: https://eslam3kl.gitbook.io/blog/bug-....
Day[0] Podcast: https://dayzerosec.com/vulns/2022/03/...
CHAPTERS
00:00 - Intro
00:41 - The bugbountytips Tweet
01:21 - The Original Blog
02:43 - Talking to Eslam about the Happy Accident
04:36 - Digging Deeper
05:39 - Researching Login Code with Codeigniter
06:54 - Example Vulnerable Login Code
08:08 - Improving the Writeup
09:18 - Surprise SQL Injection!
11:37 - Conclusion
12:31 - hextree
SUPPORT
Per video: / liveoverflow
Per month: / @liveoverflow
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: / liveunderflow
Twitch: / liveoverflow
Twitter: / liveoverflow
Instagram: / liveoverflow
TikTok: / liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#SQLInjection #BugBounty #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
En esta página del sitio puede ver el video en línea Authentication Bypass Using Root Array de Duración hora minuto segunda en buena calidad , que subió el usuario LiveOverflow 31 mayo 2023, comparta el enlace con amigos y conocidos, en youtube este video ya ha sido visto 132,967 veces y le gustó 7.2 mil a los espectadores. Disfruta viendo!