Тёмный

Finding Your First Bug: Choosing Your Target 

InsiderPhD
Подписаться 83 тыс.
Просмотров 162 тыс.
50% 1

Опубликовано:

 

23 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 108   
@William-B
@William-B 3 года назад
I received my first bounty by targeting a small, relatively unknown, sub domain connected to a large public program. It used to belong to a small company that was recently bought out by the big one so I figured it might be an “untapped resource” if you will.
@KohzmikYT
@KohzmikYT 3 года назад
Not to be intrusive or anything but what bug did you find??? I'm also starting to get into bug bounties and trying to find a good methodology 😁😁😁
@medicineman7894
@medicineman7894 Год назад
Please never stop doing these
@suryanshu15
@suryanshu15 4 года назад
Thanks, that was really informative for me as a beginner
@yunemse48
@yunemse48 4 года назад
That' what I've been expecting for weeks.. Thanks!
@InsiderPhD
@InsiderPhD 4 года назад
:D Glad you like it, I intend to do a bug bounty methdology/approach video as a follow up to this one soon
@S0L4RW4V3
@S0L4RW4V3 4 года назад
Thankyou Queen for being dope, Sharing your material to my newer team members has been a beauty.
@filipesimoes5398
@filipesimoes5398 4 года назад
It was pretty much useful. Thank you very much for your help.
@jaiganesh851
@jaiganesh851 4 года назад
Really doing a great job...Loved IT ..Waiting for more to come..
@InsiderPhD
@InsiderPhD 4 года назад
Thank you so much, next video will be out tomorrow :)
@cyber-man
@cyber-man 2 года назад
I really liked this presentation, will try to take into consideration every point
@muhammedsillah111
@muhammedsillah111 4 года назад
you are absolutely amazing. Really appreciate the information you putting forward.Thanks!!!
@zeecat7109
@zeecat7109 4 года назад
Great job. Thank you. And by the way, are you going to hack in to the pyramid(31:58) as well?. :)
@InsiderPhD
@InsiderPhD 4 года назад
Ahaha my dissertation was on deciphering ancient languages, my wallpaper is a graphic I made for my dissertations, not Egyptian but greek! The writing system is called Linear B
@ali7a-ts492
@ali7a-ts492 4 года назад
Great video! All the scrolling up and down in the last 5minutes made me a bit dizzy, but other than that great content. Thanks a lot 😂✌️
@GameSmilexD
@GameSmilexD Год назад
Starting here and leaving this comment to check on in 12wks and hopefully already have found a a buf by then
@abdonito8254
@abdonito8254 Год назад
?
@thepotatogaming2340
@thepotatogaming2340 10 месяцев назад
So did you find one?
@twinklesonkar3465
@twinklesonkar3465 6 месяцев назад
?
@abdullahtanveer316
@abdullahtanveer316 2 года назад
an amazing video that's exactly what i was so confused about
@danielhemmati
@danielhemmati 4 года назад
I am speechless, thanks. it really helps. I will watch everything content you make you made my day. 😍😍😍😍🙏🙏🙏🙏🙏
@l2m773
@l2m773 4 года назад
Thank you! Now i don't roam around on h1 for 30 minutes then start a program and give up after 5 minutes lol
@InsiderPhD
@InsiderPhD 4 года назад
It might help to force yourself to pick a program and just say "this week I am going to work on X, and I'm going to look for bug type Y and Z" like go deep
@l2m773
@l2m773 4 года назад
@@InsiderPhD indeed!
@vimukthikumarasiri3993
@vimukthikumarasiri3993 3 года назад
It says 'enforces a Signal Requirement'. How I can find bug bounty programs without these requirements or how to fix them?
@pawanlakhera8605
@pawanlakhera8605 4 года назад
can u make a video on spf missing with what type of information should written in it nd proof also. plzz
@wingwing2683
@wingwing2683 2 года назад
Thanks so much!
@taylors4733
@taylors4733 4 года назад
Thanks! Was informative. Keep uploading videos
@peopleyoumustknow1325
@peopleyoumustknow1325 3 года назад
Thank u from Vietnam
@htsec4923
@htsec4923 2 года назад
Thank you, that’s helped me a lot
@RahulYadav-qg9ms
@RahulYadav-qg9ms 4 года назад
Will you also be making practical video's on bug hunting?
@InsiderPhD
@InsiderPhD 4 года назад
R Y I intend to make a full bug bounty methodology/how to approach targets as a follow up to this one :)
@Timm2003
@Timm2003 3 года назад
Thank u that was really useful
@ashrafulalim1272
@ashrafulalim1272 4 года назад
Subscribed just now! your videos are awesome ❤️ please keep sharing
@eed5278
@eed5278 4 года назад
Amazing! What do you think about XSS as first Bug bounty for a Beginner ?
@InsiderPhD
@InsiderPhD 4 года назад
I have mixed opinions, I think a few years ago XSS was great! But now there's a lot involved to finding an XSS bug and most are being found by pros with significantly more expertise in bypassing WAFs. However, other people tell me that this gives beginners a good chance to learn how javascript/hacking can work. So if you ask me XSS is dead or dying for beginners. If you ask others XSS is a good first bug still.
@dees.9636
@dees.9636 4 года назад
Massive thanks 💛
@ggmaxx66
@ggmaxx66 3 года назад
thank you for your work!
@eduarddd7
@eduarddd7 4 года назад
Nicee, thank you for posting this video. It was very helpful
@SankizTime
@SankizTime 3 года назад
You are everywhere bruh😂
@eduarddd7
@eduarddd7 3 года назад
@@SankizTime lol XD
@SankizTime
@SankizTime 3 года назад
@@eduarddd7 bro, sorry! I don't have discord on this phone, so i am not able to talk to uu these days :(
@eduarddd7
@eduarddd7 3 года назад
@@SankizTime Oh, it's okay buddy, text me when u can.
@jonathanyturralde
@jonathanyturralde 4 года назад
Killer video, very useful, Thanks for taking the time to do this. :)
@fictioncentipede9846
@fictioncentipede9846 3 года назад
perfect thanks
@khneo
@khneo 4 года назад
Thanks for the video, very useful !
@manishneupane6070
@manishneupane6070 3 года назад
Thank you so much for sharing it,🙏💞🇳🇵
@Alexander007A
@Alexander007A Год назад
hello.. if i targeted my hacker one then how i will go their website? i will just login to their website through their link they are provided there?
@digvijaysadashivpatil650
@digvijaysadashivpatil650 4 года назад
It's a very helpful and interesting video. thanks
@InsiderPhD
@InsiderPhD 4 года назад
Glad it was helpful! That's very kind of you :)
@nelson32
@nelson32 4 года назад
When showing a webpage.. could you slow down a bit? The constant scrolling doesn't allow the viewer to see what you are seeing.
@InsiderPhD
@InsiderPhD 4 года назад
Thanks for the feedback, I will definitely slow down!
@iitnakanpur..
@iitnakanpur.. 3 года назад
Sounds like aussie accent 😅😅 love your content.
@InsiderPhD
@InsiderPhD 3 года назад
British :)
@CameronNoakes
@CameronNoakes 2 года назад
brilliant video mate.
@CryptoRootz
@CryptoRootz 4 года назад
great video, im motivated.
@inspirationeveryday1175
@inspirationeveryday1175 4 года назад
Excellent Video ...⭐⭐⭐ ⭐⭐ Can we use Kali Linux At live Mode ? or we can just use Windows or MacOs ?
@InsiderPhD
@InsiderPhD 4 года назад
Use Windows or OSX if you’re more comfortable you DONT need Kali to do bug bounties!
@inspirationeveryday1175
@inspirationeveryday1175 4 года назад
@@InsiderPhD thank you madame Katie you are one of my heros
@inspirationeveryday1175
@inspirationeveryday1175 4 года назад
@@InsiderPhD please Make video when you speak about how you enter on Bug Bounty and why we can do to do what you do 🙂
@jessyjill7865
@jessyjill7865 4 года назад
i want practical demonstration of finding bugs of any vulnerabilities step by step ? and how to find the qwebsites having the bugs or not?
@InsiderPhD
@InsiderPhD 4 года назад
You can find this in my Finding Your First Bug series or my video on Live API Hacking, both have step by step guides. To find websites to hack you register on a bug bounty platform like HackerOne, Bugcrowd, Intigriti etc, and choose a target like I'm showing on this video
@coffeehousephilosopher7936
@coffeehousephilosopher7936 3 года назад
Brilliant content
@zeuscybersec659
@zeuscybersec659 4 года назад
Katie pls help.What are the prior knowledge needed for bug bounties? Shoud I do vulnerable web applications?any good books
@InsiderPhD
@InsiderPhD 4 года назад
zeus cybersec 0: How the web works (Web application hackers handbook - free at HackerOne is great for this) 1: How to use burp (my videos + practice) 2: What bugs are out there and the signs of them (my videos) 3: How to exploit these bugs (practice on CTFs /real targets)
@zeuscybersec659
@zeuscybersec659 4 года назад
@@InsiderPhD thing is I am in this field for 1 year.Preparing for oscp and done many oscp like ctfs.I am more of a network guy but I love web security too.I have done dvwa and Over the wire Natas challenge.I have a good idea on advancd used of Burpsuite.What ctfs/books do you recommend for Getting good in web?Also I don't feel confident as I have given most of my time to ctfs be it network or web.Please help me Katie🙁How can I boost my confidence and what web related books/ctfs should I finish before dipping my feet into bug bounty?
@InsiderPhD
@InsiderPhD 4 года назад
I think given your experience you need to START HACKING. It’s always going to be tough but that’s eventually where you want to be so pick a bug, pick a target and just START HACKING. Will it be hard, of course! But nothing worth doing is easy!
@zeuscybersec659
@zeuscybersec659 4 года назад
@@InsiderPhD True.Thanks Katie☺️By the way can I add u on insta?I like connecting to people in the community
@InsiderPhD
@InsiderPhD 4 года назад
I don't have instagram I'm afraid! But you can follow me on twitter and @ me any time if you have questions and I will DM you :)
@Raj_darker
@Raj_darker 4 года назад
Awesome !! Video :D K33p Posting .Thanks
@pentestical
@pentestical 4 года назад
Just subbed. Amazing content!
@InsiderPhD
@InsiderPhD 4 года назад
Thank you!
@bangraph1379
@bangraph1379 3 года назад
Great video ✌🏻✌🏻
@tamjid0x01
@tamjid0x01 4 года назад
Wow great one ..... very help-full
@TXejas19
@TXejas19 3 года назад
This was so good
@fabiosanchez9595
@fabiosanchez9595 4 года назад
thanks!
@cybersecurity3306
@cybersecurity3306 4 года назад
Why does it matter 3:06 4:30 Things to consider 4:30 5:58
@mohamedkaddouri9622
@mohamedkaddouri9622 3 года назад
Can you make a course please ?
@InsiderPhD
@InsiderPhD 3 года назад
Spoilers :) by this is something I’m actively looking into less technical more how to find your first bug and get consistent :)
@reinventingthewheel5603
@reinventingthewheel5603 Год назад
What is “scope”
@InsiderPhD
@InsiderPhD Год назад
That’s the stuff you’re allowed to hack or not allowed, it means if you find a bug in X software they will pay a bounty :)
@reinventingthewheel5603
@reinventingthewheel5603 Год назад
@@InsiderPhD thanks so much
@reinventingthewheel5603
@reinventingthewheel5603 Год назад
Thought it was a tool or something
@hbbss8684
@hbbss8684 4 года назад
best "complete beginner bug"?
@InsiderPhD
@InsiderPhD 4 года назад
hbbss hbbss IDORs for sure, not that technically complex, and you can just methodically test endpoints one by one. Relies more on determination than technical skills
@hbbss8684
@hbbss8684 4 года назад
Sick! Thanks again for your help, love the content!!
@ThushyCyber
@ThushyCyber 3 года назад
Good
@axefallerdelarosa
@axefallerdelarosa 2 года назад
Killer video, very useful, mic sucks
@imcool2791
@imcool2791 4 года назад
lol i got no skills or knowledge about coding how can i do it
@InsiderPhD
@InsiderPhD 4 года назад
Check out the whole series, especially Business Logic and IDORs which I think are great first bugs when you haven't got a lot of technical skills yet. You can also practice with CTFs
@j.a.7724
@j.a.7724 4 года назад
Yankee with no BRIM!!
@prithviraj6529
@prithviraj6529 4 года назад
very low audio volume. had a hard time tbh
@InsiderPhD
@InsiderPhD 4 года назад
I’m unfortunately not a great RU-vidr lmao and it took me a few attempts to get the audio right, for the moment just increase the volume but in the future I have fixed this issue!
@prithviraj6529
@prithviraj6529 4 года назад
@@InsiderPhD i ran it on big speakers used earphones did eq on chrome to boost high end still was quite low. hoping to see a fix soon. thanks for resonding. #ayylmao for life.
@everything6504
@everything6504 2 года назад
Hi what is your age plz
@lightyagami5776
@lightyagami5776 4 года назад
Cute voice
@kallikantzaros
@kallikantzaros 4 года назад
How old are you?
@aashikyadav4439
@aashikyadav4439 4 года назад
Love your voice. so sweet. :)
@aloneking5388
@aloneking5388 2 года назад
Your voice is wery low please chenga your mic
Далее
Finding Your First Bug: Business Logic Errors
37:47
Просмотров 62 тыс.
That was too fast! 😲
01:00
Просмотров 3,4 млн
How I made 1k in a day with IDORs! (10 Tips!)
23:09
Просмотров 53 тыс.
The Truth About Bug Bounties
11:31
Просмотров 39 тыс.
Finding Your First Bug: Manual IDOR Hunting
33:28
Просмотров 77 тыс.
Finding Your First Bug: Finding Bugs Using APIs
43:35
Просмотров 110 тыс.
Finding Your First Bug: Impact and Report Writing
48:10
How to Find Your First Bug
23:33
Просмотров 38 тыс.
That was too fast! 😲
01:00
Просмотров 3,4 млн