Nov. 12, 2022, 3:11 p.m. | IppSec

IppSec www.youtube.com

00:00 - Intro
01:00 - Start of nmap
02:30 - Taking a look at the website
03:00 - Searching the PrestaShop github to find a way to fingerprint the website, discovering INSTALL.TXT then finding the commit that contains our version
07:10 - Discovering checkout.shared.htb
08:14 - Examining how the checkout subdomain gets the contents of the shipping cart (cookies), editing the cookie and seeing what happens
09:45 - Testing for SQL Injection within the cookie
12:20 - Failing to use …

hackthebox

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Level 1 SOC Analyst

@ Telefonica Tech | Dublin, Ireland

Specialist, Database Security

@ OP Financial Group | Helsinki, FI

Senior Manager, Cyber Offensive Security

@ Edwards Lifesciences | Poland-Remote

Information System Security Officer

@ Booz Allen Hamilton | USA, AL, Huntsville (4200 Rideout Rd SW)

Senior Security Analyst - Protective Security (Open to remote across ANZ)

@ Canva | Sydney, Australia