Even though most of the time I don't completely understand every bit, I really like your editing and presentation of these (for me) 'complex' topics! Keep it up! You're doing great man!
@reema6306
Жыл бұрын
I've spent a week learning XML and XXE, and your video just summarized 80% of what I learned. Great job!
@fmattia99
5 жыл бұрын
John's voice is equal to IppSec's voice, this blew my mind :D
@abdallahdamnat382
4 жыл бұрын
Fel
@padaloni
3 жыл бұрын
hahahaha not just me that got confused for a second
@Sercan_Yilmaz
3 жыл бұрын
He is ippsec ;) John Hammond
@Yaxqb
2 жыл бұрын
The framework for explaining stuff is amazing. About every other video has a ncat -l 1337 command in it, and it has become a standard practice for me in my own work to use that command. The pwnfunction toolbox feels very versatile👍 Really really nice!
@youssefighzane1668
5 жыл бұрын
Well, well, well !! That's more than AMAAAAAAAAAAAZING !!! I was unable to understand XML and XXE as well until I watch your video. Thank you so much !! RECOMMENDED FOR ALL #BUG_BOUNTY_HUNTERS
@zanidd
5 жыл бұрын
I really like the style of your vids! Keep em coming
@aniceguy2577
4 жыл бұрын
This is pure gold. Thx for the great content
@InfiniteLogins
4 жыл бұрын
I really appreciate your video editing techniques. Make the content easy to follow and engaging.
@dxsp1d3r
5 жыл бұрын
Why didnt i find this before Awesome stuff man Thank you I came to know about this channel from stoks tweets xD
@thedude8503
3 жыл бұрын
I love this channel, the people in it and the people subscribed to it. Thank you for making it simple
@sakyb7
5 жыл бұрын
xxe is just a beginning this line with the background... goosebumps
@iDontProgramInCpp
3 жыл бұрын
3:56 diReRectly
@synthdog2819
3 жыл бұрын
17:06 willbewillbe
@TheZethera
3 жыл бұрын
I just have to say your opening and music are perfect 👌
@DeltaEchoVictor
3 жыл бұрын
It's name is mortals
@FriedMonkey362
3 ай бұрын
I have litterly never heard about this before, this is so cool, i almost tought it was an April fool's video for a second
@joshaprior3699
5 жыл бұрын
first GREAT CHANNEL
@tapank415
5 жыл бұрын
@// Anuj ó_ó
@P4cm4n0x
2 жыл бұрын
Best explanation ever. Very very to the point. Thank you :)
@abdelrhmanali2955
3 жыл бұрын
Your explanation is really AWESOME bro
@seewhatseeabc
4 жыл бұрын
Wow love this style. By the way thanks for the super clear explanation. Especially with the examples, super good clear cut examples.
@petervsjim
Жыл бұрын
THanks for the awesome video and slides! Very clear and knowledgeable
@domss1174
5 жыл бұрын
Loving your channel man, keep up the good work!
@mikekittelberger7947
Жыл бұрын
omg, thank you. This video is so godd :)
@venkaraj
2 жыл бұрын
Such an insightful video. Thanks a ton
@overgrowncarrot1
3 жыл бұрын
I like how John hammond says I have a small youtube channel lol
@janithmalinga5765
2 жыл бұрын
Superb explanation
@HyderAli-hl8mw
4 жыл бұрын
Very informational for beginners. Thank you so much
@rhenaldodelfinugraha9694
4 жыл бұрын
Awesome explanation. It's easy to understand, Thankyou. Please make another cool videos
@Hope-kf1nl
4 жыл бұрын
You're a hero! Thanks my man.
@rahulnair1923
Жыл бұрын
Loved the explanation !!!!!!!!!!🤩
@nuridincersaygili
Жыл бұрын
This is pure gold..
@faizannehal1
4 жыл бұрын
This is the best video on XXE
@stefaunholland6642
2 жыл бұрын
The way you say "parameter" makes me think of a parking meter with a parachute falling out the sky - an American
@pwndumb2903
4 жыл бұрын
Great Video. Thx for share your knowledge.
@coastaldemigod
2 жыл бұрын
my engineering professor taught the first 10 mins. of this video in 1 month
@giospadaccini119
5 жыл бұрын
In Italy xml is use to send invoices to the IRS, and after few day it sand that to you client .... So this video reassuring me..
@SatsJava
5 жыл бұрын
You deserved million subscriber Keep make more videos mate
@PwnFunction
5 жыл бұрын
Well that's a longgggggggggg way. Don't think I could ever hit such crazy numbers, If I hit 10k then I feel like I've accomplished something :) but thanks.
@0xExploitXpErtz
2 жыл бұрын
@@PwnFunction u will surely achieve it IA
@patricksteinmuller8084
Жыл бұрын
Tbh. I wonder why anyone would use DTD anyhow? The reason I am so fond of XML is the existence of XSD and XSLTs. A well defined XML is both human readible and machine readible. Can be validated against an XSD, can be transformed against an XSLT and have XSD, XSLT and both XML input and XML ouput validated against respective XSDs. This is not something that we have for json or yaml. I was to lazy to look ... I somehow suspect that we have similar attack vectors in the X* Suite.
@anonymouseye4892
3 жыл бұрын
Nice explanation 🔥
@devsingh6041
4 жыл бұрын
this video is sufficient to understand XXE. Thanks Pwn You Func well ;-)
@medjassertoubib4467
3 жыл бұрын
great video . we look forward to new videos
@shrirangdiwakar
4 жыл бұрын
Great Explanation !
@r4nd0m25
3 жыл бұрын
god level videos
@kinjalsangale1225
3 жыл бұрын
Please make more videos on different vulnerabilities... explainions are 👌
@heycherry100
5 жыл бұрын
very nice video.
@muhammadadel9537
4 жыл бұрын
Super AWESOME!!
@AkashRaj-ui1pj
5 жыл бұрын
Your videos are a aaaaaaaaaamaaaaaazinggggg
@carloszavaleta
5 жыл бұрын
Awesome content!
@ashleypursell9702
4 жыл бұрын
great video thanks so much
@tanishqsachdev8388
4 жыл бұрын
Amazing video.
@jasonmikinskiwallet4308
3 жыл бұрын
I love the Intro
@uplink-on-yt
2 жыл бұрын
My reaction (comment, not video): eyes open wide, mouth covered with hand, deep breath - AKA "Surprised Pikachu". This is possibly one ofvthe most evil things I've ever seen (yeah... I'm pretty innocent)
@tuttifrutti4184
7 ай бұрын
holy shit this is so hard to understand, but I suppose it's supposed to be this way unless you actually practise using XML for quite some time
@emmanuelafolabi6847
5 жыл бұрын
Great videom your videos has been educative, can you make a video on based XSS?
@PwnFunction
4 жыл бұрын
Next one!
@neadlead2621
Жыл бұрын
thanks bro , I've one question at 18:05 why we need %start and %end why not changing them directely to the value
@BALAKRISHNAN-pf1ol
Жыл бұрын
Can you attatch a link to the xml parser you used in the video
@hydr0nium_
5 жыл бұрын
Never heared of that attack before the video. Soo wow amazing. If you think about it its quite simple actually. Btw is there a way of secure it easiely?
@eshaan7_
5 жыл бұрын
What theme for VScode and terminal are u using? BTW Great video, thanks!
@PwnFunction
5 жыл бұрын
Monokai Pro Terminus - eugeny.github.io/terminus/
@huntit4578
3 жыл бұрын
What software do u use to make these slideshow or animation (Whatever) to explain these attacks in such a interesting way?
@yeasirarafat4261
5 жыл бұрын
awesome
@annomy1493
3 жыл бұрын
voice seems to be known. Is it john harmmond ???
@ArthurBurke-c5n
20 күн бұрын
Heidenreich Walks
@itizazadil9369
5 жыл бұрын
Thanks for the Vedio
@GeordieJuliet
9 күн бұрын
1980 Noble Walk
@CosmoCopulates1
5 жыл бұрын
Dude, your videos are great! What do you use to create the animations?
@PwnFunction
4 жыл бұрын
Adobe animate boi.
@laurinneff4304
2 жыл бұрын
It would've been great if you had included a segment on how to protect against these attacks
@Morgan_iv
2 жыл бұрын
Just don't use XML
@tapank415
5 жыл бұрын
:) Amazing!
@anatolyrapoport2216
3 жыл бұрын
Nice tutorial!
@eduardoandrescastilloperer4810
8 ай бұрын
OMG why was that even encoded into the standard!!!
@patrickslomian7423
3 жыл бұрын
Love your channel Bro !! So I ran into a failure with Dvwa in the section "file upload",I"ve tried to upload an file with the payload. It seems to me that the server (using docker) wont phrase an xml file, can that be true ? Im getting this error :" This XML file does not appear to have any style information associated with it. The document tree is shown below. " Or should I converte that to an html file ?
@IBMboy
5 жыл бұрын
9:47 My name is jeff. Nice meme
@lexibigcheese
2 жыл бұрын
so that's why there's a doctype html. that's what it's for!
@ОлегИгоревич-з1с
5 жыл бұрын
Nice Stuff
@JimmyAugus-b1d
4 сағат бұрын
Boehm Streets
@HarrisonWinston-k5k
22 күн бұрын
Macejkovic Overpass
@aleksandar5323
2 жыл бұрын
How can I disable XML parser resources referencing on say an Apache Server? I don't want XML to be making any requests at all, either internal or God forbid accessing a 3rd party URL! I just want hard-coded data from it...
@aymanrbati531
2 жыл бұрын
why cant u declare the "send" entity directly in the external DTD ? why put it inside 'wrapper' ?
@vijaykumar-hc6jz
4 жыл бұрын
Why DTD is so called ? It could have also been called Entity Defintition or something like that ? Any answer to this is appeciated.
@AndreaScarth-l1f
22 күн бұрын
Ankunding Ridge
@Manabender
3 жыл бұрын
So how does one defend against this? Say I was running the server you were attacking and *didn't* want you reading /etc/passwd, but still wanted to retain as much (safe) functionality of the XML parser as possible. What would I do?
@erdosamangeldin3105
2 жыл бұрын
& sign showing error while referencing an entity. I tried in ascii or hex too, it is not working. Is there any other ways to reference it?
@HobbesRudolf
8 күн бұрын
862 Alfreda Mission
@Pcpiee
5 жыл бұрын
What terminal do you use for the examples? it looks very nice. guessing its cygwin based by the looks of it
@PwnFunction
4 жыл бұрын
Terminus - eugeny.github.io/terminus/
@aidenrhama9147
5 жыл бұрын
what software did you use to make this content ?
@zxuiji
2 жыл бұрын
2:42, already think of JSON as easier, just use a string and escape the quote characters **Edit:** I also prefer lua when I need more than just data capabilities
@helloguy1179
2 жыл бұрын
What should I do if I have to configure a http request to get a file's information, but its content contains special character? We cannot use CDATA in a URL, right?
@Sparkette
3 жыл бұрын
Is it okay to use a '
@LloydAntony-z9w
15 күн бұрын
Ophelia Knolls
@GeorgeLocklear-b6i
18 күн бұрын
Wallace Wall
@CoralEngeman-m2p
22 күн бұрын
Ritchie Parkway
@learnfirst-1
2 жыл бұрын
I hate background color 🤦♂️🤦♂️🤦♂️🤦♂️ change to white color pls But contant is AAmazinggggg👍👍
@prudhvidanyamraju8017
5 жыл бұрын
On a certain java server I’m able to retrieve the data of /sys/power/image_size (basically an number) using OOB xxe but I’m unable to retrieve contents of etc/passwd ; any thoughts?
@alexeecs
6 ай бұрын
So... How do you defend against it?
@PhilipMoss-q5y
18 күн бұрын
Nicholaus Junctions
@JohnsonMirabelle-u2d
11 күн бұрын
Will Street
@AakanshYadav-b6t
11 ай бұрын
hey hey hey sir please tell this theme of zsh. I tried searching all of them but i didn't find anyone like this please do tell.
@EdisonWallace-i7j
14 күн бұрын
Denesik Well
@SimpsonDalton-o5b
16 күн бұрын
Allie Circles
@DeanBaxter-x7d
21 күн бұрын
Naomi Trace
@SatriaAdyPradana
3 жыл бұрын
do you have git repo which collect the scripts and XML files used here?
Пікірлер: 189