video thumbnail 11:31
Guessing vs. Not Knowing in Hacking and CTFs

2020-10-18

[public] 57.2K views, 5.03K likes, 26.0 dislikes audio only

channel thumbLiveOverflow

I really hate it when I have to guess stuff. This applies to CTFs, but also to my real-world work in penetration testing. It is incredibly frustrating to bruteforce or guess something, that could just be read in the source code. I much rather focus on technical details, tricks and techniques.

Try the XSS challenge: https://hacking.app/xss/xss_chall1.html#welcome

Failed DOM Clobbering Research part 1/2: /youtube/video/dZXaQKEE3A8

Chaining Script Gadgets to Full XSS part 2/2: /youtube/video/UGtrpXk6QVU

00:00 - Introduction

00:37 - Steganography in CTF

01:38 - Dirbuster & Asset Discovery

02:21 - XSS Example (see description)

02:53 - Global Variables in JavaScript

03:21 - The window.name Variable

03:55 - Is this Guessing?

04:20 - Example Solution Walkthrough

06:00 - Benefits of this Challenge

07:20 - The Importance of Scanning

08:19 - Scanning vs. Reading Code

08:57 - Improve Steganography Challenges

10:22 - Summary

11:10 - Outro

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Instagram: https://instagram.com/LiveOverflow/

→ Website: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Introduction
/youtube/video/L1RvK1443Yw?t=0
Steganography in CTF
/youtube/video/L1RvK1443Yw?t=37
Dirbuster & Asset Discovery
/youtube/video/L1RvK1443Yw?t=98
XSS Example (see description)
/youtube/video/L1RvK1443Yw?t=141
Global Variables in JavaScript
/youtube/video/L1RvK1443Yw?t=173
The window.name Variable
/youtube/video/L1RvK1443Yw?t=201
Is this Guessing?
/youtube/video/L1RvK1443Yw?t=235
Example Solution Walkthrough
/youtube/video/L1RvK1443Yw?t=260
Benefits of this Challenge
/youtube/video/L1RvK1443Yw?t=360
The Importance of Scanning
/youtube/video/L1RvK1443Yw?t=440
Scanning vs. Reading Code
/youtube/video/L1RvK1443Yw?t=499
Improve Steganography Challenges
/youtube/video/L1RvK1443Yw?t=537
Summary
/youtube/video/L1RvK1443Yw?t=622
Outro
/youtube/video/L1RvK1443Yw?t=670
LiveOverflow just a wannabe hacker... making videos about various IT security topics and participating in hacking competitions. -=[ ā¤ļø Support me ]=- Patreon per Video: https://www.patreon.com/join/liveoverflow YouTube Membership per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ šŸ“„ Imprint ]=- Security Flag GmbH Celsiusstr. 72 12207 Berlin Germany
/youtube/channel/UClcE-kVhqyiHCcjYwcpfj9w
I’m moving, no videos sorry 17,554 views
/youtube/video/9CS3q0uG1LI
Patreon patreon.com
https://www.patreon.com/join/liveoverflow
CTF video write-ups by LiveOverflow
/youtube/video/MpeaSNERwQA