How we made $5000 with this exploit

Sdílet
Vložit
  • čas přidán 9. 09. 2024
  • Hi, thanks for watching our video about the Sandwich Attack !
    In this video we’ll walk you through:
    - How did we find the vulnerability ?
    - What's a UUIDv1 ?
    - The recipe of the Sandwich Attack
    - Struggles and mitigations
    - The CTF Challenge
    LINKS
    sandwich.rb:
    - github.com/Lup...
    More about the Sandwich Attack:
    - versprite.com/...
    HacktivityCon:
    - • Vulnerabilities I've F...
    Underscore_:
    - • On a reçu le hacker qu...
    ABOUT THE CHANNEL
    The channel is about cybersecurity. We cover lots of cool stuff such as bug bounty hunting, cool vulnerabilities and breaking stuff for fun !
    Follow me on Twitter:
    / 0xlupin
    Don’t forget to subscribe !
    CREDITS:
    Produced By: Lupin & Holmes
    Presented by: Roni “Lupin” Carta
    Edited by: Gabriel Jardin
    Artistic Direction: Amandine “Idnamaa” Kohlmuller
    Thumbnail by: Justicia Satria, Amandine “Idnamaa” Kohlmuller
    Outro by: Math “blueish” Dumoulin
    Directed by: Roni “Lupin” Carta
    Written by: Roni “Lupin” Carta
    Guest Star: Stök
    Inspired by: LiveOverflow, InsiderPHD, Stök, Sylvqin, Versprite

Komentáře • 31

  • @foolbazar9176
    @foolbazar9176 Před rokem +4

    Amazing edit and great content ! Thank you for it

  • @computerauditor
    @computerauditor Před rokem

    One of the most super simple and super detailed video🔥🔥🔥
    Great video!!

  • @alainfocom
    @alainfocom Před rokem

    Wow you just did a very great work ^^
    Waiting for more !

  • @shubham_srt
    @shubham_srt Před 7 měsíci

    The production and edit is too good

  • @_CryptoCat
    @_CryptoCat Před rokem

    Cool vuln, great video! 🔥

  • @deadeye1652
    @deadeye1652 Před rokem

    super cool find man. it really makes me wonder how something so arbitrary looking like UUID tokens have so much depth and expose attack surface. would never skip over uuids ever again xD.

    • @0xlupin
      @0xlupin  Před rokem +1

      Thanks a lot for the feedback ! And yes now I check the Version every time haha

  • @bughunter1731
    @bughunter1731 Před rokem

    Cool video man, found you on twitter, I just subscribed!

  • @nithinr5959
    @nithinr5959 Před rokem

    Fantastic!
    Congratulations and thanks for sharing ;)

    • @0xlupin
      @0xlupin  Před rokem

      Thanks for watching ;)

  • @h4ckerR4hul
    @h4ckerR4hul Před rokem

    Thanks for sharing the rb script.. nice one.. like to see similar vids more

  • @baravind719
    @baravind719 Před rokem +1

    Very helpful 😊

  • @user-qj8zb5lu7g
    @user-qj8zb5lu7g Před 7 měsíci

    Incroyable

  • @h4ckerR4hul
    @h4ckerR4hul Před rokem

    can u share how do u ffuf to brute force the UUID.. how do u setup the FUZZ word ??

  • @shubham_srt
    @shubham_srt Před 7 měsíci

    more videos pls!!

  • @NithinJune
    @NithinJune Před rokem +1

    the microphone in the beginning legitimately worried me

    • @0xlupin
      @0xlupin  Před rokem +2

      I love the jokes that my editor added in this video haha

  • @deepm0078
    @deepm0078 Před rokem

    Awsm such a great learn

  • @mohammedshine2372
    @mohammedshine2372 Před rokem

    Awesome find man

  • @H3t4
    @H3t4 Před měsícem

    nice videos

  • @mehdibouhamidi4675
    @mehdibouhamidi4675 Před rokem

    Bravo c'est cool comme idée 😁🤌

  • @crusader_
    @crusader_ Před rokem

    How did you initially identify the timestamp was from Julien calendar?

    • @computertech3986
      @computertech3986 Před rokem +1

      My understanding is that UUIDv1 uses the Julien calendar. The version can be determined from the token string.

    • @0xlupin
      @0xlupin  Před rokem

      In the article of VerSprite they actually wrote about it. I just followed the documentation :)

  • @TomTom-gx1sm
    @TomTom-gx1sm Před 10 měsíci

    Putain tu me donnes envie de me lancer sur YT en Anglais :).

  • @youtubeprenium601
    @youtubeprenium601 Před rokem

    2:35 ?

  • @mavisdavis1997
    @mavisdavis1997 Před rokem

    *promosm*