Free Web Hacking Course

231,103
0
Published 2022-10-23
Get Proton VPN for free: go.getproton.me/SHWN or get Proton Mail here: go.getproton.me/SHWO

Free Web Hacking Course: youtube.com/c/RanaKhalil101

50% OFF Web Security Academy Course Code: DavidBombal500FF
Academy: academy.ranakhalil.com/

8 hour SQL Injection playlist:    • SQL Injection | Complete Guide  

In this video Rana explains and demonstrates Broken Access Control which is number 1 on the OWASP top 10: owasp.org/www-project-top-ten/

// MENU //
00:00 - Intro
00:25 - Ads
01:38 - Opening
02:36 - Broken Access Control
05:04 - Authentication
06:11 - Session Management
10:31 - Access Control
12:16 - Types of Access Control
18:19 - Broken Access Control Vulnerabilities
23:00 - Rana's Channel
25:03 - Types of Broken Access Control
30:12 - Lab Exercise 1
39:52 - Vertical Privilege Escalation
43:19 - Lab Exercise 2
48:47 - Access Control Vulnerabilities in Multi-Step Processes
51:12 - Lab Exercise 3
59:21 - Prevention
01:04:46 - Rana's Platforms
01:07:43 - Outro

// Labs used in the video //
Lab #1: portswigger.net/web-security/access-control/lab-us…
Lab #2: portswigger.net/web-security/access-control/lab-us…
Lab #3: portswigger.net/web-security/access-control/lab-mu…

// Rana's SOCIAL //
Twitter: twitter.com/rana__khalil
Academy: academy.ranakhalil.com/
Youtube Channel: youtube.com/c/RanaKhalil101
Medium Blog: ranakhalil101.medium.com/
Rana Intigriti Interview:    • Hacker Heroes #5 - @rana__khalil (Int...  

// David's SOCIAL //
Discord: discord.gg/davidbombal
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube Main Channel: youtube.com/davidbombal
YouTube Tech Channel:    / @davidbombaltech  
YouTube Clips Channel:    / @davidbombalofficialclips  
YouTube Shorts Channel:    / @davidbombalshorts  
Apple Podcast: davidbombal.wiki/applepodcast
Spotify Podcast: open.spotify.com/show/3f6k6gERfuriI96efWWLQQ

// MY STUFF //
www.amazon.com/shop/davidbombal

// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: [email protected]

web
web hacking
web hacking course
web hacking tutorial
xss
owasp
owasp top 10
broken access control
http
https
website
web hacking full course
web hacking pro tips
web hacking book
xss
cross site scripting
portswigger
ajax
jscript
javascript
xss attack
xss video tutorial
xss attack tutorial
xss explained
xss attack example
xss bug bounty
xss tutorial
xss vulnerability
xss vs csrf attack
xss example
xsser
xsssa facebook
xsssa
kali linux
penetration testing
ethical hacking
bug bounty
cross site scripting
cross-site scripting
red teaming
cyber security
kali linux install
kali linux 2022
ethical hacker course
ethical hacker
javascript
ajax
jquery
node js
node js hacking
portswigger

Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

Disclaimer: This video is for educational purposes only.

#hack #webhacking #course

All Comments (21)
  • I just started getting into bug bounty and this is perfect for me. Btw yesterday I found my first bug.
  • @MD-tr6sh
    I love how she explains everything in clear understandable language. A true beginner course. 👏
  • @LKpun
    I love her presentation as she is very concise and thorough breaking everything down. Her level of organization is impecable. I don’t know much about hacking or web security. However, I’ve always wanted to learn so I’m definitely signing up for her course. Thank for bringing her on Mr. Bombal. I really enjoy watching your channel and I have been learning quite a lot. Cheers!
  • @Dbean48
    She is a very good teacher, I am glad she is going over the basics.
  • @ArjayLeano23
    very clear and just enough pace on how she explain the topics really makes you listen and understand more of what she's teaching.
  • @shayansec
    This is not only educational, as well as entertaining also. Thanks for doing amazing collabs.
  • @NOPerative
    Awesome introduction to the topic of Web Sec & hacking the web. Good call on spotting Rana to address the topic David - kudos fella! Another topic in the domain I would like to see addressed is exploiting latency to get in the door; latency is exploited in gaming and is very much a real-world technique employed by hackers trying to lull servers into a more time lenient state potentially allowing them (hackers) a larger window of opportunity. Everybody has to deal with latency especially concerning connections over larger WAN and is a growing problem and most likely at the root of governments (globally) addressing connections from outside their countries in a manner that most employ VPN services to bypass. Web Sec is definitely an interesting and very valuable topic for anyone creating anything that consumes anything over a network connection, but many if not all techniques benefit localized application development (like desktop apps). Good vid!!!
  • @noelremasu
    I love the way she explains these concepts so smooth and easy to grasp. We need to see more of her
  • @duscraftphoto
    This was a great segment on BAC. Rana does an amazing job of explaining the issues and the processes to test for said issues.   I sort of equate the Multistep issue to having a building with a security guard, mantrap room, front desk clerk and then a lock on the door of the room with all of the goodies... If all you had was the security guard at the door and nothing else, because you figured that was enough, it would be much easier to get into the room with all the goodies if you managed to trick the security guard. As always, please keep the amazing content coming. Because it's very much appreciated by everyone!
  • @israr5605
    Being a full stack developer I loved this video and her way of teaching is simply awesome.Thanks David for introducing us to such an amazing teachers.
  • A brilliant presentation. Rana has a very good way of explaining things. I particularly liked the way she gave a realife example of the online shopping session management vulnerability.
  • @JohnD0h_IT
    Very good video, really like the way she explains and the way you interacted with her! Hope to see more collaboration between you two a near future, particularly dev stuff!
  • That timer for the ad really makes a difference - makes it feel like my time is respected.
  • @sam7on
    Thanks David for hosting Rana, I toke the chance and used the promotion code :) Thanks Rana for the valuable information and the your ability to simplify the concepts with examples. Regards,
  • I would looooooove an episode covering access control and coding examples, really educational show. I learned a lot! Thank you both!
  • @learnTv1
    i think rana khalil is the best teacher of cyber security on youtube ,,, thanks for her and thank you david for inviting her ,,, keep up the good job both of you
  • It will be awesome if Rana returns on your channel to teach and demonstrate code security. Often than not it is usually not clearly explained. I believe with Rana at the helm of this topic, clarity on this will be assured. Thanks David for all you do for the community.
  • @terrible568
    Thank you David and Rama. I would love to see Rama come back to talk about coding.
  • She's explaining using a very simple terms and easy to understand she's good bring her back
  • Yeah definitely bring Rhanna back she's cool at explaining it in simple terms that easy enough to understand for people like me. Really appreciate it alot! Thank You xx