Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
So, for example, what we're seeing is an application that just features the source code for any website,
so if you put in Google dot com, it actually fetches it and gives you the source code for the whatever
web page.
We've given it before us to make sure there's Matsusaka fear.
The first thing we want to do is we want to spin up a net counter.
Can you see?
I'll show you both of Winnicott.
We cover this in our How to set up your own lab section of the course.
But what are we doing with that cat is we're telling it, hey, I want you to listen and open on put
a thousand.
So now that we have a port 8000 open, I know the iPad just for my box.
I'm going to put that in here and I'm going to make it HTP request and I'm going to head Port 8000 because
that's the port we opened up here.
And we want to see what we want to see who is making that request.
Is this being made on the server side or is it being made on the client side to clients?
I being my browser, if my iPad just shows up in the request, that means my browser is doing this and
not the server itself.
As you can see here with the IP just coming back, it's one for two ninety three thousand forty nine.
I know my personal IP address and I know that's not it.
So that's the IP address that belongs to the server.
So what we can do next is we know that the request has been made is from this IP address.
This is not our servers.
So it means there's something in the background, some work that's being done by the server.
It's rendering and fetching data on the server side.
And I want to start messing with it now.
I want to see if we can actually access any local networks or any other sensitive data that could give
us some sort of impact.
So the first thing we can do is we can use a file wrapper.
We can say, hey, news file, give me the ETSI password content.
That was pretty easy.
This case, it came back.
This is still very, very common in bug bounties when it comes back and says, OK, here's the data.
You asked for it and as easily giving it to us.
If that doesn't work, we also look for localhost.
So every machine that's running some sort of a Web server could be accessible within its own machine
and network by going through localhost.
So if you're not familiar with this, I highly recommend looking into it and getting familiar with how
private networks work.
What is a localhost or even going as far as setting up your own localhost with some Apache in Mexico
in the background for this case, we're going to give it localhost that comes back.
It's a status, OK, which means that we're accessing a local private network that wouldn't have been
accessible without this SRF.
Again, we also talked about an SSR.
The most important thing that a lot of hackers go after, especially with bug bounties, is looking
for metadata.
So the first step to do is we want we want to do is we want to go to one six nine to five four one six
nine to five for this as a universal IP address, the most cloud service providers offer that just gives
you some metadata.
In some cases, it might give you keys, it may give you some extra information that you can use as
a part of your privacy.
So in this case, we hit this first URL.
It comes back and says not found.
We're going to try and do metadata V1.
And this comes back and gives us some data so we can actually query for additional information like
the public keys, we can look for the DNS information again is metadata.
In some cases there are keys available where you can actually use them for HWC or whatever the cloud
service instance provider is and you can get additional access.
And it's your privilege to be doing more like Arcy from your SRF.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.