0:00 Music 0:06 Reporting. 0:08 Report should include vulnerability itself, how to exploit that vulnerability, how to mitigate that vulnerability, and the mitigation plan. 0:18 So obviously, after remediation is done, specialist is doing retest. 0:28 What is retest? 0:29 Specialist is taking the previous report, which was done like one month ago, and checking each vulnerability. 0:38 If it still exists. 0:40 And after is sending new report, which is called like retest report. 0:46 What is the difference between automatic tools and manual tools and AI tools? 0:53 So basically, some specialists, they are focused on manual testing. 0:59 So some specialists are saying, I'm such a good hacker, so I will be just using like few tools. 1:05 And I will be hiking like manually. 1:08 There is not... 1:11 There is no point to even discuss it. 1:14 It is like, doesn't make any sense. 1:16 You need to do a lot of manual work, but automation, you need to delegate to the software. 1:24 I will give you an example. 1:25 First of all, 1:27 When you are having the website, 1:30 that website can have specific folders. 1:33 And accidentally in that folder, you can drop backup. 1:37 So let me just show you so you will understand what I mean. 1:41 Why manual doesn't make sense. 1:44 Why it should be automatic. 1:50 So. 1:54 So this is example of, you see the amount of lines? 2:02 Are you going to do it manually, really? 2:04 Are you really going to manually go through all those slash log slash all slash image? 2:11 This is automatic stuff. 2:13 So when you are doing audit, you are basically running the tool which will enumerate 2:21 100,000 lines of code. 2:26 lines. 2:28 So this is just one example. 2:30 When you are scanning the website, it has different vulnerabilities. 2:37 And those vulnerabilities can be found by automatic tools. 2:41 So it goes like left and right. 2:43 Left is what you are sending. 2:46 This is payload. 2:47 And right is detector. 2:50 So when you find a vector where you are sending malicious payload, let me show you what is payload. 3:01 I understand it can sound a little bit hard, but this stuff is not easy, unfortunately. 3:08 So this is example of payloads in the JavaScript. 3:12 So people who write in JavaScript, they can easily understand what is this. 3:17 And I will just show you. 3:18 So this one saying. 3:20 Please open pop-up and show one, two, three. 3:24 That's it. 3:25 So if such payload, if I will copy it, I will go here and I will just put it like here, stored. 3:34 So hello, hello guys, right? 3:40 So I'm just writing, hello guys. 3:42 And some guy is doing this. 3:44 I am malicious guy. 3:48 That's it. 3:49 So guy injected his own script into your website. 3:53 This is your website. 3:54 And he was able to inject malicious code. 3:58 Now, let's imagine the guy is not that dumb, right? 4:03 So he created the specific filters, which will allow him to filter. 4:11 This script. 4:13 So if script will be filtered like this, right? 4:17 Nothing, no, something will happen because it was already there. 4:21 So it's already there. 4:23 Clear guestbook, let me clear it and I will show you. 4:27 So I will copy half 4:31 Like this, right? 4:34 Nothing happened. 4:35 Because guy, he removed. 4:39 So when you write comment, if there is filtration, it will remove your ability to run that specific script. 4:48 But you can see there are a big amount of other ones. 4:53 And if you will just go through all of them, 4:56 Potentially, you will be able to find specific payload which will work. 5:02 So that one is about example of how to exploit just a regular, I don't know, guestbook, forum. 5:16 People are writing you the feedback on your website. 5:18 They can just inject malicious code. 5:21 And this is something very interesting. 5:24 From this one, from this stuff, you can collect what? 5:28 You can collect from guy his location. 5:31 You can make the screenshot. 5:32 So if this is not my website and I want to infect it, 5:36 I will create the script and I have it. 5:38 I will be showing it to you. 5:40 So I will input it here. 5:42 I will be able to see the location of guy. 5:44 I can see the screenshot. 5:45 I can copy his clipboard. 5:46 I can use all the JavaScript on this specific page. 5:50 I can get his whatever cookies and much more. 5:56 I can show you just a real time how to explain this stuff. 6:02 So let's do it. 6:06 So we are starting the local server on my computer. 6:11 Now we are deploying this local server to the internet. 6:18 So this is script, malicious script, which I'm hosting on my computer now. 6:25 So I have this guestbook and I'm going to hack this stuff. 6:32 Oh my God, it's not getting through. 6:38 It's too much big. 6:39 Okay. 6:40 Okay. 6:41 Okay. 6:42 Let me stop this. 6:44 Let's see if this one will be enough. 6:49 Let's see. 6:52 Will it be? 6:53 Now I need to think how to get it. 6:56 Let's do like this. 7:04 So now it's going to eat it. 7:11 I hope it will be good. 7:13 So what I did in HTML, I just changed the max length. 7:19 That is easy to kill. 7:22 Usually you can use the proxy for this one, but as a matter of fact, you can do it in browser. 7:28 So I put, look, look what happened. 7:32 XSS, fire capture. 7:34 My software, malicious software is saying somebody is getting caught. 7:41 So somebody is getting caught. 7:45 Is cross-site scripting. 7:46 Cross-site scripting allows you to inject a malicious code inside other websites. 7:55 Okay, so now let's see. 8:00 It fired. 8:03 Wait. 8:05 Just one sec. 8:07 There are like multiple XSS. 8:10 So, hooked browser. 8:12 Now, what we see? 8:14 We see information about this guy. 8:16 So you should understand that what I'm showing you can be your website. 8:21 It's not the website which I just deployed on my computer, and this is all going on on my computer. 8:27 Because you can clearly see, 8:32 that this is external website. 8:34 I just injected external website with hook. 8:39 So it can be your website and I'm injecting from my computer malicious payload. 8:46 So what can I do? 8:47 Now it's interesting part. 8:49 Let's 8:52 just play with the guy. 8:56 Facebook login. 8:57 So he's sitting on his stuff. 9:00 Now he's redirected to Facebook. 9:03 He's like, okay, okay, you know, it's kind of like strange. 9:08 Now he's redirected to Microsoft page. 9:11 So you can play with this guy like a toy now because he accessed a website where you have the controllable JavaScript from your computer. 9:22 What else can you do with the guy? 9:25 So you can just... 9:29 Send him this stuff. 9:32 Let's see. 9:33 You can try to get storage. 9:35 You can try to get cookies. 9:37 You can try to take screenshot. 9:39 You can try to start K-Logger. 9:41 So whatever he's writing, even if he didn't submit, you will get it. 9:46 This is his clipboard. 9:47 For example, clipboard. 9:50 And that clipboard can be from the previous password on the website. 9:54 So you can go to console. 9:58 What we can see? 9:59 Clipboard. 9:59 Clipboard, you see? 10:02 Clipboard. 10:03 This is my clipboard. 10:05 And this is what I was writing. 10:08 So I can see what this guy is doing on your website. 10:13 So I injected my script on your website to see what guy is doing. 10:18 Now, I think it's not enough from the guy. 10:21 I want to see exactly. 10:25 What is going on with his internal network? 10:28 I can scan his network. 10:29 I can check the battery status. 10:32 I want to see if he is at home or he is not at home. 10:35 So 100% battery. 10:38 Or I can do some crazy stuff. 10:41 I can capture a webcam. 10:45 So you see, it asks if you allow or not allow to use this webcam. 10:53 Some websites, like, for example, Zoom or Google, if you find XSS there, you already gave the permission. 11:01 So they will never ask. 11:02 So let's see. 11:04 It should send me that. 11:07 camera. 11:09 Where is that camera? 11:11 It should come in a minute. 11:13 So, record microphone. 11:16 Tab nubbing attack. 11:18 So this one, for example, I will show you. 11:22 So you sit like this on the website, pop up. 11:29 It's a little bit old technology. 11:31 Let me send it again. 11:36 So, top nabbing attack. 11:38 Okay. 11:39 So, the guy is just sitting here. 11:41 You see? 11:42 So, he is redirected here. 11:45 So, you don't even see what is the domain. 11:48 But you can see that the session expired. 11:51 So you can just send something and it will redirect you back. 11:55 So here you can see the credentials, admin password. 12:03 And it was, as you've seen, it was auto input there. 12:09 So I didn't write it. 12:10 It was from the form. 12:12 So if I accidentally click, it's done. 12:16 So you got the point, right? 12:18 Because it opened the browser in the same website and the login and password was the same form. 12:27 It after submitted the same information from the edge. 12:31 And if the guy clicked yes, it goes to you because browser doesn't understand if this is malicious or not. 12:38 It is just the same form. 12:41 So let's see, where is my camera? 12:46 Deep picture. 12:48 It should be done. 12:50 I think it should be done. 12:56 I don't know why it's not there. 12:58 But what else? 12:59 You can also... 13:02 Do like this. 13:05 For example, deploy. 13:08 So the guy is just sitting on here and he is getting the download update for VPN. 13:15 If you know that this guy works in a specific company, if you know his VPN provider, he is cooked. 13:23 So if you hack the company portal, 13:27 And you basically inject that specific payload, which I showed you there. 13:33 You don't need to do anything. 13:34 You just go here, autoload, you do the screenshot, geolocation, you collect his cookies, and you just go to sleep. 13:44 Right? 13:44 And, you know, you can say... 13:48 Like anything here, you know, Amazon, expire, whatever. 13:54 And after VPN update on top of this. 13:58 So if this guy, let's imagine this is new guy, right? 14:03 New guy pop up. 14:05 Oh, no, I need to access it. 14:08 Obviously. 14:09 Admin password. 14:15 So there is new guy. 14:17 So he just accessed it. 14:19 And he is already attacked. 14:21 You see, you see, everything is like moving and changing on his screen. 14:26 So it is asking for his location. 14:28 It is asking him to download some malicious stuff. 14:31 And remind me later. 14:33 Okay, session expired. 14:35 So he is attacked from different angles, right? 14:38 Already. 14:39 And this is new guy. 14:41 And we can see the information about this guy. 14:44 What else? 14:44 So basically, all capabilities of JavaScript can be used against the guy. 14:51 location, internal VPN, his ability to scan surrounding, his keystrokes, his credentials, like his cookies. 15:05 This is the first stuff. 15:08 When you have cookies, just to be clear. 15:10 So, look, guys. 15:12 This is session cookie. 15:15 Session cookie is something that allows you to stay logged in on the website. 15:20 Now the idea here is that a guy can extract your cookies and can access with your cookies and he can become their username admin. 15:32 Because there is nothing else on this website which is distinguishing you from the regular user. 15:39 So cookies are something that is distinguishing you from other users. 15:46 This is one of attacks which I wanted to show you. 15:51 So we talked about brute force. 15:53 It's easy, right? 15:55 And now we talked a little bit about what is the XSS. 16:01 XSS is injecting of JavaScript inside the page. 16:06 Very easy. 16:06 How to find XSS? 16:08 So there is like reflected one. 16:10 One, two, three. 16:12 So if you see hello, one, two, three, right? 16:15 What are the ideas do you have? 16:17 So you can say like, okay, let's make it like this maybe. 16:23 Hello, one, two, three. 16:26 And it is bold. 16:28 So it becomes interesting. 16:31 I created the bold 1, 2, 3. 16:33 So I changed the content for the website using HTML. 16:39 If I can change the content of the website using HTML, I can try to inject JavaScript. 16:45 If I can inject JavaScript, I can use all the capabilities of JavaScript. 16:50 I can host it in my server. 16:52 And after, you know, this guy will be cooked. 16:55 So this is the idea. 16:56 You can just start to find reflection. 16:59 So first of all, when you go, for example, to Google, right, and you write like 1, 2, 3, 4, 5, 17:05 You see, one, two, three, four, five. 17:07 But Google are not dumb. 17:09 They definitely understand that there is no way that they will reflect, you know, 17:17 Text, one, two, three. 17:20 So if you will go here. 17:28 You see that they cut it all. 17:33 It is separated. 17:35 So they are not tags anymore. 17:38 So if Google will have the input like this, which you can just check in the inspector. 17:46 So hello, one, two, three, four, five. 17:50 And you can just try to put like, 17:53 Hello, whatever, B. 17:57 Hello, B, 1, 2, 3, and H1, and font color blue. 18:06 So you're just writing some text, right? 18:08 And you're just checking what will happen. 18:10 Oh, my God. 18:11 Now I can affect the website badly. 18:14 So in the beginning, you try to find reflection. 18:18 After, you analyze if you can inject the simple tag. 18:22 If you can inject the simple tag, you can try to inject something like this. 18:28 Let's see if I can do script alert 123 script. 18:38 So this one. 18:39 Now I can see. 18:40 I can run script. 18:42 If I can run script, I can take external script. 18:46 I can host it in my computer. 18:48 And even if server is not allowing me to send more than like 25 symbols, right? 18:54 I will just try to input that specific payload. 18:59 Because, look, I will just show you how big is that payload. 19:07 How big is Deadpool? 19:12 For you just to understand how big is that payload to be injected. 19:19 Look at this payload. 19:20 There is no way you will inject this stuff in that page. 19:23 No way. 19:24 Server will reject it. 19:26 But you can inject this link to the script. 19:32 So, yeah, you got the point, right? 19:34 That this is one of few vulnerabilities which you need to understand. 19:40 You should always understand the reasoning. 19:42 Why VPN is updating? 19:45 Can I myself update VPN? 19:47 Do I need to contact somebody to verify it? 19:51 So you should be aware of what you can do on computer, what you cannot do on computer.
0:00 Music 0:06 Reporting. 0:08 Report should include vulnerability itself, how to exploit that vulnerability, how to mitigate that vulnerability, and the mitigation plan. 0:18 So obviously, after remediation is done, specialist is doing retest. 0:28 What is retest? 0:29 Specialist is taking the previous report, which was done like one month ago, and checking each vulnerability. 0:38 If it still exists. 0:40 And after is sending new report, which is called like retest report. 0:46 What is the difference between automatic tools and manual tools and AI tools? 0:53 So basically, some specialists, they are focused on manual testing. 0:59 So some specialists are saying, I'm such a good hacker, so I will be just using like few tools. 1:05 And I will be hiking like manually. 1:08 There is not... 1:11 There is no point to even discuss it. 1:14 It is like, doesn't make any sense. 1:16 You need to do a lot of manual work, but automation, you need to delegate to the software. 1:24 I will give you an example. 1:25 First of all, 1:27 When you are having the website, 1:30 that website can have specific folders. 1:33 And accidentally in that folder, you can drop backup. 1:37 So let me just show you so you will understand what I mean. 1:41 Why manual doesn't make sense. 1:44 Why it should be automatic. 1:50 So. 1:54 So this is example of, you see the amount of lines? 2:02 Are you going to do it manually, really? 2:04 Are you really going to manually go through all those slash log slash all slash image? 2:11 This is automatic stuff. 2:13 So when you are doing audit, you are basically running the tool which will enumerate 2:21 100,000 lines of code. 2:26 lines. 2:28 So this is just one example. 2:30 When you are scanning the website, it has different vulnerabilities. 2:37 And those vulnerabilities can be found by automatic tools. 2:41 So it goes like left and right. 2:43 Left is what you are sending. 2:46 This is payload. 2:47 And right is detector. 2:50 So when you find a vector where you are sending malicious payload, let me show you what is payload. 3:01 I understand it can sound a little bit hard, but this stuff is not easy, unfortunately. 3:08 So this is example of payloads in the JavaScript. 3:12 So people who write in JavaScript, they can easily understand what is this. 3:17 And I will just show you. 3:18 So this one saying. 3:20 Please open pop-up and show one, two, three. 3:24 That's it. 3:25 So if such payload, if I will copy it, I will go here and I will just put it like here, stored. 3:34 So hello, hello guys, right? 3:40 So I'm just writing, hello guys. 3:42 And some guy is doing this. 3:44 I am malicious guy. 3:48 That's it. 3:49 So guy injected his own script into your website. 3:53 This is your website. 3:54 And he was able to inject malicious code. 3:58 Now, let's imagine the guy is not that dumb, right? 4:03 So he created the specific filters, which will allow him to filter. 4:11 This script. 4:13 So if script will be filtered like this, right? 4:17 Nothing, no, something will happen because it was already there. 4:21 So it's already there. 4:23 Clear guestbook, let me clear it and I will show you. 4:27 So I will copy half 4:31 Like this, right? 4:34 Nothing happened. 4:35 Because guy, he removed. 4:39 So when you write comment, if there is filtration, it will remove your ability to run that specific script. 4:48 But you can see there are a big amount of other ones. 4:53 And if you will just go through all of them, 4:56 Potentially, you will be able to find specific payload which will work. 5:02 So that one is about example of how to exploit just a regular, I don't know, guestbook, forum. 5:16 People are writing you the feedback on your website. 5:18 They can just inject malicious code. 5:21 And this is something very interesting. 5:24 From this one, from this stuff, you can collect what? 5:28 You can collect from guy his location. 5:31 You can make the screenshot. 5:32 So if this is not my website and I want to infect it, 5:36 I will create the script and I have it. 5:38 I will be showing it to you. 5:40 So I will input it here. 5:42 I will be able to see the location of guy. 5:44 I can see the screenshot. 5:45 I can copy his clipboard. 5:46 I can use all the JavaScript on this specific page. 5:50 I can get his whatever cookies and much more. 5:56 I can show you just a real time how to explain this stuff. 6:02 So let's do it. 6:06 So we are starting the local server on my computer. 6:11 Now we are deploying this local server to the internet. 6:18 So this is script, malicious script, which I'm hosting on my computer now. 6:25 So I have this guestbook and I'm going to hack this stuff. 6:32 Oh my God, it's not getting through. 6:38 It's too much big. 6:39 Okay. 6:40 Okay. 6:41 Okay. 6:42 Let me stop this. 6:44 Let's see if this one will be enough. 6:49 Let's see. 6:52 Will it be? 6:53 Now I need to think how to get it. 6:56 Let's do like this. 7:04 So now it's going to eat it. 7:11 I hope it will be good. 7:13 So what I did in HTML, I just changed the max length. 7:19 That is easy to kill. 7:22 Usually you can use the proxy for this one, but as a matter of fact, you can do it in browser. 7:28 So I put, look, look what happened. 7:32 XSS, fire capture. 7:34 My software, malicious software is saying somebody is getting caught. 7:41 So somebody is getting caught. 7:45 Is cross-site scripting. 7:46 Cross-site scripting allows you to inject a malicious code inside other websites. 7:55 Okay, so now let's see. 8:00 It fired. 8:03 Wait. 8:05 Just one sec. 8:07 There are like multiple XSS. 8:10 So, hooked browser. 8:12 Now, what we see? 8:14 We see information about this guy. 8:16 So you should understand that what I'm showing you can be your website. 8:21 It's not the website which I just deployed on my computer, and this is all going on on my computer. 8:27 Because you can clearly see, 8:32 that this is external website. 8:34 I just injected external website with hook. 8:39 So it can be your website and I'm injecting from my computer malicious payload. 8:46 So what can I do? 8:47 Now it's interesting part. 8:49 Let's 8:52 just play with the guy. 8:56 Facebook login. 8:57 So he's sitting on his stuff. 9:00 Now he's redirected to Facebook. 9:03 He's like, okay, okay, you know, it's kind of like strange. 9:08 Now he's redirected to Microsoft page. 9:11 So you can play with this guy like a toy now because he accessed a website where you have the controllable JavaScript from your computer. 9:22 What else can you do with the guy? 9:25 So you can just... 9:29 Send him this stuff. 9:32 Let's see. 9:33 You can try to get storage. 9:35 You can try to get cookies. 9:37 You can try to take screenshot. 9:39 You can try to start K-Logger. 9:41 So whatever he's writing, even if he didn't submit, you will get it. 9:46 This is his clipboard. 9:47 For example, clipboard. 9:50 And that clipboard can be from the previous password on the website. 9:54 So you can go to console. 9:58 What we can see? 9:59 Clipboard. 9:59 Clipboard, you see? 10:02 Clipboard. 10:03 This is my clipboard. 10:05 And this is what I was writing. 10:08 So I can see what this guy is doing on your website. 10:13 So I injected my script on your website to see what guy is doing. 10:18 Now, I think it's not enough from the guy. 10:21 I want to see exactly. 10:25 What is going on with his internal network? 10:28 I can scan his network. 10:29 I can check the battery status. 10:32 I want to see if he is at home or he is not at home. 10:35 So 100% battery. 10:38 Or I can do some crazy stuff. 10:41 I can capture a webcam. 10:45 So you see, it asks if you allow or not allow to use this webcam. 10:53 Some websites, like, for example, Zoom or Google, if you find XSS there, you already gave the permission. 11:01 So they will never ask. 11:02 So let's see. 11:04 It should send me that. 11:07 camera. 11:09 Where is that camera? 11:11 It should come in a minute. 11:13 So, record microphone. 11:16 Tab nubbing attack. 11:18 So this one, for example, I will show you. 11:22 So you sit like this on the website, pop up. 11:29 It's a little bit old technology. 11:31 Let me send it again. 11:36 So, top nabbing attack. 11:38 Okay. 11:39 So, the guy is just sitting here. 11:41 You see? 11:42 So, he is redirected here. 11:45 So, you don't even see what is the domain. 11:48 But you can see that the session expired. 11:51 So you can just send something and it will redirect you back. 11:55 So here you can see the credentials, admin password. 12:03 And it was, as you've seen, it was auto input there. 12:09 So I didn't write it. 12:10 It was from the form. 12:12 So if I accidentally click, it's done. 12:16 So you got the point, right? 12:18 Because it opened the browser in the same website and the login and password was the same form. 12:27 It after submitted the same information from the edge. 12:31 And if the guy clicked yes, it goes to you because browser doesn't understand if this is malicious or not. 12:38 It is just the same form. 12:41 So let's see, where is my camera? 12:46 Deep picture. 12:48 It should be done. 12:50 I think it should be done. 12:56 I don't know why it's not there. 12:58 But what else? 12:59 You can also... 13:02 Do like this. 13:05 For example, deploy. 13:08 So the guy is just sitting on here and he is getting the download update for VPN. 13:15 If you know that this guy works in a specific company, if you know his VPN provider, he is cooked. 13:23 So if you hack the company portal, 13:27 And you basically inject that specific payload, which I showed you there. 13:33 You don't need to do anything. 13:34 You just go here, autoload, you do the screenshot, geolocation, you collect his cookies, and you just go to sleep. 13:44 Right? 13:44 And, you know, you can say... 13:48 Like anything here, you know, Amazon, expire, whatever. 13:54 And after VPN update on top of this. 13:58 So if this guy, let's imagine this is new guy, right? 14:03 New guy pop up. 14:05 Oh, no, I need to access it. 14:08 Obviously. 14:09 Admin password. 14:15 So there is new guy. 14:17 So he just accessed it. 14:19 And he is already attacked. 14:21 You see, you see, everything is like moving and changing on his screen. 14:26 So it is asking for his location. 14:28 It is asking him to download some malicious stuff. 14:31 And remind me later. 14:33 Okay, session expired. 14:35 So he is attacked from different angles, right? 14:38 Already. 14:39 And this is new guy. 14:41 And we can see the information about this guy. 14:44 What else? 14:44 So basically, all capabilities of JavaScript can be used against the guy. 14:51 location, internal VPN, his ability to scan surrounding, his keystrokes, his credentials, like his cookies. 15:05 This is the first stuff. 15:08 When you have cookies, just to be clear. 15:10 So, look, guys. 15:12 This is session cookie. 15:15 Session cookie is something that allows you to stay logged in on the website. 15:20 Now the idea here is that a guy can extract your cookies and can access with your cookies and he can become their username admin. 15:32 Because there is nothing else on this website which is distinguishing you from the regular user. 15:39 So cookies are something that is distinguishing you from other users. 15:46 This is one of attacks which I wanted to show you. 15:51 So we talked about brute force. 15:53 It's easy, right? 15:55 And now we talked a little bit about what is the XSS. 16:01 XSS is injecting of JavaScript inside the page. 16:06 Very easy. 16:06 How to find XSS? 16:08 So there is like reflected one. 16:10 One, two, three. 16:12 So if you see hello, one, two, three, right? 16:15 What are the ideas do you have? 16:17 So you can say like, okay, let's make it like this maybe. 16:23 Hello, one, two, three. 16:26 And it is bold. 16:28 So it becomes interesting. 16:31 I created the bold 1, 2, 3. 16:33 So I changed the content for the website using HTML. 16:39 If I can change the content of the website using HTML, I can try to inject JavaScript. 16:45 If I can inject JavaScript, I can use all the capabilities of JavaScript. 16:50 I can host it in my server. 16:52 And after, you know, this guy will be cooked. 16:55 So this is the idea. 16:56 You can just start to find reflection. 16:59 So first of all, when you go, for example, to Google, right, and you write like 1, 2, 3, 4, 5, 17:05 You see, one, two, three, four, five. 17:07 But Google are not dumb. 17:09 They definitely understand that there is no way that they will reflect, you know, 17:17 Text, one, two, three. 17:20 So if you will go here. 17:28 You see that they cut it all. 17:33 It is separated. 17:35 So they are not tags anymore. 17:38 So if Google will have the input like this, which you can just check in the inspector. 17:46 So hello, one, two, three, four, five. 17:50 And you can just try to put like, 17:53 Hello, whatever, B. 17:57 Hello, B, 1, 2, 3, and H1, and font color blue. 18:06 So you're just writing some text, right? 18:08 And you're just checking what will happen. 18:10 Oh, my God. 18:11 Now I can affect the website badly. 18:14 So in the beginning, you try to find reflection. 18:18 After, you analyze if you can inject the simple tag. 18:22 If you can inject the simple tag, you can try to inject something like this. 18:28 Let's see if I can do script alert 123 script. 18:38 So this one. 18:39 Now I can see. 18:40 I can run script. 18:42 If I can run script, I can take external script. 18:46 I can host it in my computer. 18:48 And even if server is not allowing me to send more than like 25 symbols, right? 18:54 I will just try to input that specific payload. 18:59 Because, look, I will just show you how big is that payload. 19:07 How big is Deadpool? 19:12 For you just to understand how big is that payload to be injected. 19:19 Look at this payload. 19:20 There is no way you will inject this stuff in that page. 19:23 No way. 19:24 Server will reject it. 19:26 But you can inject this link to the script. 19:32 So, yeah, you got the point, right? 19:34 That this is one of few vulnerabilities which you need to understand. 19:40 You should always understand the reasoning. 19:42 Why VPN is updating? 19:45 Can I myself update VPN? 19:47 Do I need to contact somebody to verify it? 19:51 So you should be aware of what you can do on computer, what you cannot do on computer.