Cracking Websites with Cross Site Scripting - Computerphile

Cracking Websites with Cross Site Scripting - Computerphile

Computerphile

10 лет назад

1,521,701 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

CrazyArchon
CrazyArchon - 08.08.2023 14:15

that's why i tried breaking things lol

Ответить
Osama Mustafa
Osama Mustafa - 10.07.2023 14:20

The best and simplest explanation ever in XSS :)

Ответить
A Sperm Whale Spontaneously Called Into Existence
A Sperm Whale Spontaneously Called Into Existence - 05.07.2023 07:07

The ending <computerphile> doesn't have a dash because you are supposed to binge the next 20 computerphile videos after it...

Ответить
xcmon3yx777
xcmon3yx777 - 05.01.2023 12:53

I saw a video where someone explained how to gain (control) of /root; using this method on the most secure linux systems through a stack buffer overflow (overloading the system memory in a way that lets them right whatever they choose). /root on a systme = god

Ответить
GhostMiner
GhostMiner - 20.12.2022 00:42

Discord forgot about XSS on their new servers page and someone used it to steal accounts 😂

Ответить
Abhijith A S
Abhijith A S - 24.10.2022 06:24

Run JavaScript! Run!

Ответить
Radio
Radio - 14.08.2022 18:07

I want these guys to talk about what the hell we experienced on the internet with 2020

Ответить
faizan shariff
faizan shariff - 07.08.2022 08:29

Watching this in 2022 and this still feels so relevant.

Ответить
DORIME
DORIME - 06.08.2022 04:50

🤓

Ответить
seyu
seyu - 05.08.2022 07:51

My god...Tom Scott is GOAT

Ответить
Valery0p 5
Valery0p 5 - 06.04.2022 18:35

I wish I saw this video years ago

Ответить
Noël
Noël - 10.03.2022 17:37

I just accidentally crashed the website of my mothers business. I thought searching for "<i>kast" (dutch for closet) wouldn't do anything...turns out it did, and the site is down Edit: turns out it's only on the wifi that i'm on (I guess it has something to do with IP-adresses?) so that's a relief.

Ответить
w0lm7b
w0lm7b - 22.02.2022 20:33

Nice

Ответить
Ariadne
Ariadne - 30.12.2021 20:46

Looking at his pseudo-code: “That’s vaguely sensible” // ❤️

Ответить
Tom Hacker
Tom Hacker - 30.12.2021 03:22

great explanation

Ответить
Piyush Mohite
Piyush Mohite - 02.08.2021 09:03

Did he use Rick Astley 7 years ago?

Ответить
danman6669
danman6669 - 19.06.2021 06:27

"Someone comes along and invents JavaScript."
It would be nice if you gave him credit. It was Brendan Eich.

Ответить
Nitro Zeus
Nitro Zeus - 09.05.2021 06:06

Nice

Ответить
asmit kumar
asmit kumar - 16.03.2021 13:10

Am i too late?

Ответить
Abdullah Mahmood
Abdullah Mahmood - 04.02.2021 15:23

I will learn it

Ответить
Orion Conner
Orion Conner - 30.12.2020 16:15

JavaScript is Dangerous 😬

Ответить
Jason C.
Jason C. - 14.11.2020 10:31

does this work <b> hello </b>

Ответить
Benjamin Cox
Benjamin Cox - 23.07.2020 05:33

It’s 2020 is css still the biggest vulnerability of websites?

Ответить
SHIVAM SUNDRAM
SHIVAM SUNDRAM - 16.07.2020 06:37

<b> text </b>

Ответить
Rathin Sen
Rathin Sen - 09.06.2020 10:16

<b> wow </b>

Ответить
mohamed elgamal
mohamed elgamal - 18.03.2020 14:23

so basically this is SQL injection but with javascript

Ответить
nimitzufo
nimitzufo - 12.01.2020 19:37

you should know this

Ответить
Inoculum - A Tribute To TOOL
Inoculum - A Tribute To TOOL - 16.12.2019 21:42

Written on DOT MATRIX paper! Brilliant! :)

Ответить
Mr Mr
Mr Mr - 27.10.2019 17:17

no

Ответить
Ur subscriber
Ur subscriber - 07.10.2019 13:54

<script>alert("hello")</script>

Ответить
PCPMTI Serviços
PCPMTI Serviços - 06.10.2019 23:35

Amazing explanations Tom. Thank you very much dude.

Ответить
Charles Derek
Charles Derek - 21.08.2019 17:34

How would you address the company? Would you tell them upfront, or mention something needs to be fixed?

Ответить
Yasir Zubair
Yasir Zubair - 30.07.2019 20:31

So who else tried typing <i> on google ?

Ответить
Iyad
Iyad - 14.07.2019 19:56

what about css

Ответить
Preston Ferry
Preston Ferry - 07.07.2019 20:51

Tom “You should know this” Scott

Ответить
Soitisisit
Soitisisit - 07.07.2019 19:49

<marquee>Wheeeeeee</marquee>

Ответить
Daniel Chéquer
Daniel Chéquer - 02.07.2019 08:06

This channel makes me feel like a numberphile from another dimension has crashed into ours

Ответить
Mitchell Lloyd
Mitchell Lloyd - 28.06.2019 06:27

nice

Ответить
David R. Flores
David R. Flores - 17.04.2019 22:51

Great explanation. Thanks!!

Ответить
averasko
averasko - 26.03.2019 06:17

I would also tell a bit about other ways javascript can get into your page like ads and etc

Ответить
iDevilous BHO
iDevilous BHO - 04.03.2019 11:18

I'm a BS Physics student(first year) I really want to learn more about Cyber Security, I want to shift but I would waste my scholarship so yeah I'm watching your videos...Thank you!

Ответить
Nigel Gilbert
Nigel Gilbert - 07.02.2019 09:41

Well explained, but he didn't specify any concrete technique for executive such an attack (possibly intentional).
Though, explains the mechanics well enough that one could figure it out. ☺️

Ответить
imagede zach
imagede zach - 03.02.2019 09:38

Tom explains this in 8 mins better than my Network security professor in an entire lecture

Ответить
Youngsun An
Youngsun An - 15.01.2019 01:56

i + 1 = 2

Ответить
leapingblackcat
leapingblackcat - 14.01.2019 00:28

The three ugly sisters of software development:
* HTML
* CSS
* JavaScript

Ответить
Sylvie C
Sylvie C - 11.01.2019 12:01

It is so easy to forget (to end/close a tag), or they do it on purpose ... and not for free ...

Ответить
BlackZero Rs
BlackZero Rs - 07.01.2019 02:46

Oooooorrrr, you can command JavaScript to create web upload form and upload a php file with your filemanager shell and you can modify, add, or delete contents on the pages! 😁

Ответить
Oj. B.
Oj. B. - 21.12.2018 11:20

This works

Ответить
Tospaa
Tospaa - 20.12.2018 17:29

let's try it
woah it worked!

Ответить