Video není dostupné.
Omlouváme se.

POC for CVE-2024-34102 Magento / Adobe Commerce | Bug bounty poc

Sdílet
Vložit
  • čas přidán 16. 08. 2024
  • in this video i am going to show you latest cve of adobe commerce vulnerability that will help you to get bounty in bug bounty programs so motive of the video is to report this bug after finding so they secure there websites and if any youtube team watching this please dont restrict this video it takes so much time and efforts for make such video so people will learn and earn from this after reporting..Thank you
    // Disclaimer //
    Hacking without permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing & bug hunting so that we can protect ourselves against the real hackers..

Komentáře • 202

  • @lostsecc
    @lostsecc  Před měsícem +8

    telegram channel:
    t.me/lostsec

    • @tpevers1048
      @tpevers1048 Před měsícem

      Bro where to find free bounty's like they don't pay you you are just training

    • @tpevers1048
      @tpevers1048 Před měsícem

      Free bug bounty programs?

  • @mrpoison1935
    @mrpoison1935 Před měsícem +6

    Please explain shodan ip grabbing method ❤❤

  • @cameronribeiro9660
    @cameronribeiro9660 Před měsícem

    Example of little key thing: I don’t like to run w11 bare metal because it has black/blue screened on me too many times in the past. So: I like to run everything from a VM so that I can make an updated clone each week. I noticed there is a lot of WSL happening now. If you running w11 as a VM, you’re not gonna get WSL Kali running/working on w11 in any VM software that I know of. If you run w10 in parallels on Mac i9 you can get wsl Kali running if you try 2 or 3 times. Other than that: specifically wsl2 Kali in a w11 VM? Nope.

  • @kenjikakashi
    @kenjikakashi Před měsícem +2

    I always wondered how you have that customized terminal in Win11. Is that WSL?

    • @lostsecc
      @lostsecc  Před měsícem

      yes its wsl2 kali

    • @kenjikakashi
      @kenjikakashi Před měsícem +2

      @@lostsecc Also, after analyzing your shodan script. I think your reason may be because you have your api key with it. P.S. Feel free to remove this comment if I said too much, but if I am correct, I would appreciate an affirmation. Thanks again for another awesome vid, been a subscriber and follower since your early videos.

  • @3bbodal-obaidi602
    @3bbodal-obaidi602 Před měsícem +4

    can you make a video how to CVE-2024-3136?

  • @Pal0vieeee
    @Pal0vieeee Před měsícem +4

    ❤❤❤❤❤ unstoppable man 😊😘

  • @saptamdutta
    @saptamdutta Před měsícem +1

    How do i start my career in bug bounty like You and what type of terminal is that(skulls).

    • @lostsecc
      @lostsecc  Před měsícem +1

      wsl2 kali window terminal

    • @saptamdutta
      @saptamdutta Před měsícem +1

      @@lostsecc how did u get the skulls in the terminal

  • @cameronribeiro9660
    @cameronribeiro9660 Před měsícem

    Hi all: sometimes an easy quick way to learn is an opinion question comparison: Tell me: what is your favorite scanner (amass, dirsearch, aquatone)? Why/why not? What is your favorite proxy (burp, mtmproxy, Caido, zap) why/why not? The idea with question like this: when everyone responds they will probably mention some little key thing that others didn’t know. Hell: what is your favorite platform (hackerone, bugcrowd, intigriti, Immunefi) why/why not?

  • @deathsilva1890
    @deathsilva1890 Před měsícem

    Could you share the payload you used to download the shodan result on the console?

    • @lostsecc
      @lostsecc  Před měsícem +1

      soon share in telegram

  • @wazawanaIT
    @wazawanaIT Před měsícem

    My best channel this year, thanks for the content

    • @lostsecc
      @lostsecc  Před měsícem +1

      my pleasure brother 😇☺️❤️

  • @cameronribeiro9660
    @cameronribeiro9660 Před měsícem

    Hi Lostsec and community: wanted to mention: I love new laptops just like everyone else: But if you’re just running W10 or w11 with wsl2: and you’re trying to save time and speed things up: you probably just need one of these in your current laptop:

    • @lostsecc
      @lostsecc  Před měsícem

      what i did'nt get u bro

  • @akroidofficial
    @akroidofficial Před měsícem

    man, never thought of recon in that way. nice!

  • @user-ne6fy5qg7j
    @user-ne6fy5qg7j Před měsícem

    pls provide the console command to download the results (pls I beg you)

    • @lostsecc
      @lostsecc  Před měsícem

      shodan will patch immidately if i publish

  • @konigrasse9476
    @konigrasse9476 Před měsícem

    Can you do a manual discovery and vulnerability analysis on a site with a firewall and a website firewall? The videos and content are very original and strange, there are no limits, my friend, I expect this from you

  • @Learning.Something.New.Daily.

    👍🏻

  • @Saganax
    @Saganax Před měsícem +1

    what did you use for the linux terminal in windows

  • @anuzravat
    @anuzravat Před měsícem +1

    how will u find which of the domain will bounty and which will not?

    • @lostsecc
      @lostsecc  Před měsícem +2

      use ip to org name convertor tool that i shared in telegram

  •  Před měsícem

    hey man, could you upload some of your templates for nuclei?
    greetings from brazil.

    • @lostsecc
      @lostsecc  Před měsícem

      sure uploading soon..

    •  Před měsícem

      @@lostsecc thank you bro!

  • @Fenasikerimsertsikerim
    @Fenasikerimsertsikerim Před měsícem

    You are the best, Friend.

  • @teknas2157
    @teknas2157 Před měsícem

    I am new in cyber security, plzz help in learning,resources , path

    • @lostsecc
      @lostsecc  Před měsícem

      i shared the path in telegram channel must check out

  • @nonidentified89
    @nonidentified89 Před měsícem +1

    You are GOAT bro 💯🔥

  • @maryjanechukwuma9707
    @maryjanechukwuma9707 Před měsícem

    Bro I'll like to talk to you but your telegram bot I don't no how to go around it, is there another way that I could talk with you

    • @lostsecc
      @lostsecc  Před měsícem

      just msg anything its come to me there

  • @algorethm_
    @algorethm_ Před měsícem

    Learning a lot from you bro

    • @lostsecc
      @lostsecc  Před měsícem

      my pleasure bro ❤️😇

  • @hk416ak-47
    @hk416ak-47 Před měsícem

    Bro you make a very good video, but no one says anything about the fact that you always have a new wallpaper

    • @lostsecc
      @lostsecc  Před měsícem

      ☺️🫂❤️

    • @lostsecc
      @lostsecc  Před měsícem +1

      wait for nextt video ❤️🔥

  • @user-mr6ok9vs2g
    @user-mr6ok9vs2g Před měsícem

    Bro, how do you find target for bug bounty!! are you in any bug bounty program??
    BTW Very nice video.Keep doing it🙂🙂

    • @lostsecc
      @lostsecc  Před měsícem +1

      use hak2ip tool and find these ip org names and report

  • @madhavanrio3210
    @madhavanrio3210 Před měsícem +1

    Awesome ❤❤😊😊😊 and one more it vulnerable also for RCE ?

    • @hexormc5164
      @hexormc5164 Před měsícem

      U know how to do it?

    • @lostsecc
      @lostsecc  Před měsícem

      ❤️🤗

    • @madhavanrio3210
      @madhavanrio3210 Před měsícem

      @@hexormc5164 not in master level just intermediate, I doesn't even find a single eligible bug in hackerone but in other private program find many bugs but not bounty , I am only one who have 99.9% of unlucky🥲

    • @hexormc5164
      @hexormc5164 Před měsícem

      @@lostsecc u know how to perform RCE with exploit?

    • @madhavanrio3210
      @madhavanrio3210 Před měsícem

      @@hexormc5164 i dont know bro, but i think it is posssible when do this refer some youtube channel they do it

  • @user-gc6gp7cm9c
    @user-gc6gp7cm9c Před měsícem

    Sir Allow pasting k bd console men ky kia. please tip share kr den

    • @lostsecc
      @lostsecc  Před měsícem

      shodan will patch immidately if i leak

  • @user-zp2sw8to3i
    @user-zp2sw8to3i Před měsícem

    Great work 🎉🎉🎉🎉🎉🎉❤❤❤❤❤❤

  • @niketpopat
    @niketpopat Před měsícem

    Can you share Console command to download ips from Shodan Facet 3:25 ?

    • @lostsecc
      @lostsecc  Před měsícem

      shodan will patch that immidately

  • @Sidharthas89
    @Sidharthas89 Před měsícem

    Thanks for the video bro❤❤
    You are awesome ❤❤❤

  • @58statment
    @58statment Před měsícem

    3:26 brother, can u pls provide this code that u used here...

    • @lostsecc
      @lostsecc  Před měsícem +1

      shodan will patch it immidately if its leak

    • @58statment
      @58statment Před měsícem

      @@lostsecc Okay no problem.

  • @sarans119
    @sarans119 Před měsícem

    Can u share ip extract from shodan I won't leak it bro pls

  • @Sidharthas89
    @Sidharthas89 Před měsícem

    What is allow pasting.
    How we can use it.
    Dies it required subscription.

    • @lostsecc
      @lostsecc  Před měsícem

      no it does'nt require suscription

  • @Fractal_reComm
    @Fractal_reComm Před měsícem

    Can you play this dork from the shodan console, it would save a lot of time or tell me where I can learn how to direct my js to get the ips in .txt you are really cool

    • @lostsecc
      @lostsecc  Před měsícem

      shodan will patch it if its viral

  • @starlox0
    @starlox0 Před měsícem

    Just awesome 👌 🎉

  • @sarion007
    @sarion007 Před měsícem

    in the browser on the shodan website u blurred some command will u share it? :)

    • @lostsecc
      @lostsecc  Před měsícem

      shodan will patch it immidately bro

  • @tuyulmagelang
    @tuyulmagelang Před měsícem

    please how to upload shell?

    • @lostsecc
      @lostsecc  Před měsícem

      i will post on telegram

  • @viresh222
    @viresh222 Před měsícem

    Bro how can i get combose list free for lecher openbullet

  • @MohiUddin_Shakil
    @MohiUddin_Shakil Před měsícem

    bro, lots of love from Bangladesh. could you please share with us about bug bounty methodology?

    • @lostsecc
      @lostsecc  Před měsícem

      thnq mate ❤️yes u shared all things in telegram channel must check there..

  • @mdjeionmia4118
    @mdjeionmia4118 Před měsícem

    Bro, can you clarify how I found organizations? I know it like org:Meta http.html:blah blah. And one-by-one searches are so time-consuming. Any other method for it? How are you doing it?

    • @lostsecc
      @lostsecc  Před měsícem +1

      i shared in telegram that tool must check there

    • @mdjeionmia4118
      @mdjeionmia4118 Před měsícem

      @@lostsecc hackip2host is it?

    • @ekanshjaiswal9976
      @ekanshjaiswal9976 Před měsícem

      @@lostsecc can you share your telegram group link ?

  • @tomiwafalade5480
    @tomiwafalade5480 Před měsícem

    First!!

  • @moamenyasser6397
    @moamenyasser6397 Před měsícem

    is running kali or any linux distro on wsl better than a VM ? I see you use it alot

    • @lostsecc
      @lostsecc  Před měsícem

      i use wsl kali

    • @moamenyasser6397
      @moamenyasser6397 Před měsícem

      @@lostsecc if you can make a video for your configuration on WSL would be awesome

    • @lostsecc
      @lostsecc  Před měsícem

      i need to delete all this for that ok o will try on old laptop after delete

    • @moamenyasser6397
      @moamenyasser6397 Před měsícem

      @@lostsecc maybe do a writeup instead of video that would be efficient too

  • @menakapathirana5681
    @menakapathirana5681 Před měsícem

    what is the software used as terminal

  • @JoopvdClips
    @JoopvdClips Před měsícem

    ❤‍🔥❤‍🔥❤‍🔥❤‍🔥❤‍🔥

  • @PhvexSeven
    @PhvexSeven Před měsícem +1

    can u give me advice about how learn about hacking ?

    • @lostsecc
      @lostsecc  Před měsícem

      check telegram bro i tell everything in details

    • @PhvexSeven
      @PhvexSeven Před měsícem

      @@lostsecc ok tysm

  • @ZahraNayab-j3f
    @ZahraNayab-j3f Před měsícem

    sir Allow pasting k bd kya likhna

    • @lostsecc
      @lostsecc  Před měsícem

      its hidden bcz of policy

  • @whateveritis0
    @whateveritis0 Před měsícem

    Let me know how u scraping from shodan, just give me a hint!
    I guess its not a better idea to ask the complete script 😌
    All i need is a hint ill take care apart👋🏻

  • @huncking
    @huncking Před měsícem

    So this is only possible for website running majento and Adobe only?

  • @uttarkhandcooltech1237
    @uttarkhandcooltech1237 Před měsícem

    First

  • @spramoda_8979
    @spramoda_8979 Před měsícem

    Thanks for the content 🎉

  • @user-gc6gp7cm9c
    @user-gc6gp7cm9c Před měsícem

    Sir please Mera nuclei ka issue clear kr den .. how can I contact you

    • @lostsecc
      @lostsecc  Před měsícem

      in telegram channel t.me/lostsec

  • @cyberjunk777
    @cyberjunk777 Před měsícem

    I like the look of your terminal, where can I get it? I use kali linux

    • @lostsecc
      @lostsecc  Před měsícem

      from microsoft store

    • @cyberjunk777
      @cyberjunk777 Před měsícem

      @@lostsecc Ooh, I thought you made the terminal yourself bro, WSL is really cool bro

  • @niteshpatel8114
    @niteshpatel8114 Před měsícem

    😎😎

  • @patfire785
    @patfire785 Před měsícem

    Great content ❤

  • @NethaxStark
    @NethaxStark Před měsícem

    Nice Bro!

  • @yousdouse6354
    @yousdouse6354 Před měsícem

    can you provide exploit.

    • @lostsecc
      @lostsecc  Před měsícem

      check telegram channel bro

  • @falanavictor1986
    @falanavictor1986 Před měsícem

    Hello bro , please I run dirsearch when following your guide on approaching a target in bug bounty but I get a lot of 403 in few mins ..is there any mitigations I could apply pls 😢😢

    • @lostsecc
      @lostsecc  Před měsícem

      -fc 403

    • @falanavictor1986
      @falanavictor1986 Před měsícem

      @@lostsecc what does that do please..it kinna look like my requests get dropped and forbidden..I noticed whenever I switch vpn location it works normally but starts malfunctioning after a few secs ..I tried using proxy chains but I couldn't get it to work

    • @PersonalDetails-ig5ex
      @PersonalDetails-ig5ex Před měsícem

      It's due to continuous bruting. The site is protected from Dos​@@falanavictor1986

    • @Not_Just_a_Fan
      @Not_Just_a_Fan Před měsícem

      ​@@lostseccbro can you tell anyway other than payloads to bypass 403 forbidden error ? Please bro ?

  • @mossadgaming9359
    @mossadgaming9359 Před měsícem

    Bro , Totally bounced you are extracting some ips which are vulnerable to the cve and performing the exploit on it , is it correct? if wrong please explain me
    . thank you

    • @lostsecc
      @lostsecc  Před měsícem +1

      not all vulnerable some are only..

    • @mossadgaming9359
      @mossadgaming9359 Před měsícem

      @@lostsecc ok

    • @dineshdhanasekar8982
      @dineshdhanasekar8982 Před měsícem

      Extracting ips are Using That Application vulnerable to cve. Not every ips is vulnerable some of them are patched already.

  • @janiparam7894
    @janiparam7894 Před měsícem

    which extension you are using for ip gathering...?

  • @speedyfriend67
    @speedyfriend67 Před měsícem

    😮

  • @tpevers1048
    @tpevers1048 Před měsícem

    Why you disappeared

    • @lostsecc
      @lostsecc  Před měsícem

      just busy in some other things i will active soon..

  • @HackShiv
    @HackShiv Před měsícem

    Dm me that shodan method you have bro if possible. I won't leak it, and good vid 👍

  • @Hacker_ankit_2025
    @Hacker_ankit_2025 Před měsícem

    Bhai ye konsa tool h jisse ye pata lage ki iss ip ka bug bounty h karke... ?? Tool name kya h

    • @lostsecc
      @lostsecc  Před měsícem

      i shared in my telegram hak2ip

  • @PhvexSeven
    @PhvexSeven Před měsícem +1

    what systme u are using ?

  • @bitdetaglobal
    @bitdetaglobal Před měsícem

    thanx

  • @bugbouty
    @bugbouty Před měsícem

    what is the trick to get all ips from shodan

    • @lostsecc
      @lostsecc  Před měsícem

      shodan will patch if i explose

  • @P45PU7
    @P45PU7 Před měsícem

    amazing..🥰

  • @IBO.ATTACKS
    @IBO.ATTACKS Před měsícem

    🤑🤑🤑

  • @user3549
    @user3549 Před měsícem

    BRO whats the chrome extension you used

  • @cybershadow007
    @cybershadow007 Před měsícem

    thanks man

  • @yahai_
    @yahai_ Před měsícem

    awesome ❤❤❤ name extantion extract only domain

  • @a-man2468
    @a-man2468 Před měsícem

    luv u bro

    • @lostsecc
      @lostsecc  Před měsícem

      love u three bro ❤️🤗

  • @therightvoice6570
    @therightvoice6570 Před měsícem

    Thank u❤

  • @darkmix4192
    @darkmix4192 Před měsícem

    Song name please

    • @lostsecc
      @lostsecc  Před měsícem +1

      dark beach

    • @darkmix4192
      @darkmix4192 Před měsícem

      @@lostsecc Are you very busy man? I'm so many qus and doubts asked to you in telm but didn't response you but, it's ok i don't worry because I'm lostsec family member so spread love....

    • @lostsecc
      @lostsecc  Před měsícem

      sorry bro i am testing other stufss so not checked i will check all

  • @histoire-de-blackhat3346
    @histoire-de-blackhat3346 Před měsícem

    you are a top

  • @netor-3y4
    @netor-3y4 Před měsícem

    how many can you make money in month?? ❤❤

    • @lostsecc
      @lostsecc  Před měsícem

      i love my work more then money

    • @netor-3y4
      @netor-3y4 Před měsícem

      ​@@lostsecc money is important to be alive

    • @lostsecc
      @lostsecc  Před měsícem +1

      when u work on your passion money will be automatic comes..

    • @netor-3y4
      @netor-3y4 Před měsícem

      @@lostsecc yeah exactly why my first question 🙋 🙋

  • @uttarkhandcooltech1237
    @uttarkhandcooltech1237 Před měsícem

    Give console cmd please

  • @aatankbadboy3941
    @aatankbadboy3941 Před měsícem

    Bro how we gonna earn From this 😂

    • @lostsecc
      @lostsecc  Před měsícem +1

      use the ip to org comverter tool from my telegram and report to the org

  • @RajanChoudhary12
    @RajanChoudhary12 Před měsícem

    Hey brother! I want to ask how much time it took you to earn yr first bounty and tell me how much you earn from Bug Bounty.

    • @lostsecc
      @lostsecc  Před měsícem +1

      its totaly depend on your skills and hardwork for someone it takes 3-6 months for sometime it takes 1 year+

    • @RajanChoudhary12
      @RajanChoudhary12 Před měsícem

      @@lostsecc Yeah! Thanks bro.

  • @Krypt0Nu11
    @Krypt0Nu11 Před měsícem

    We want voice over bro 💀

    • @lostsecc
      @lostsecc  Před měsícem

      when setup readyy sure

  • @PrimePixel.444
    @PrimePixel.444 Před měsícem

    How to contact you if I want to talk to you or ask something???

    • @lostsecc
      @lostsecc  Před měsícem

      telegram

    • @PrimePixel.444
      @PrimePixel.444 Před měsícem

      @@lostsecc okay But your Telegram group is already a group, how can I chat with you there?

    • @lostsecc
      @lostsecc  Před měsícem

      just msg me in bot link in discription of that channel

    • @PrimePixel.444
      @PrimePixel.444 Před měsícem

      @@lostsecc okay

    • @PrimePixel.444
      @PrimePixel.444 Před měsícem

      @@lostsecc By the way, you understand Hindi things.????