Тёмный

IBM - Live bug bounty hunting on Hackerone 

gotr00t?
Подписаться 10 тыс.
Просмотров 64 тыс.
50% 1

Bug bounty hunting on Hackerone platform. IBM!
#hacker #hacking #pentesting #cybersecurity #infosec #ethicalhacking

Опубликовано:

 

22 апр 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 147   
@gotr00t0day
@gotr00t0day 2 месяца назад
My videos usually last long processing, that's why you can only see it in 360p, Once it's done processing it will become 4K.
@K-entertainment7570
@K-entertainment7570 2 месяца назад
Can you give your email ? I have some project if you intersted
@K-entertainment7570
@K-entertainment7570 2 месяца назад
Can you give your telegram i have some project if you interested
@Justanormalguy01
@Justanormalguy01 Месяц назад
Hi! Can u make a tutorial on how to install the Spyhunt tool?
@LakeE.
@LakeE. Месяц назад
@@Justanormalguy01Do it yourself that’s how you learn the best 👍🏼
@0xx0xx00x0
@0xx0xx00x0 Месяц назад
i dont understand ANYTHING but i still watched the whole vid lol
@coolhandtrade
@coolhandtrade 28 дней назад
same here
@cyberacademics
@cyberacademics 2 месяца назад
Just found this gem of a channel! Super excited to watch your videos and thank you for your videos!
@hatemaliyan3933
@hatemaliyan3933 Месяц назад
Great, more of live bug bounty methodology videos 🎉
@RichardinSA
@RichardinSA 23 дня назад
No talking just the good stuff? I'm hooked!
@Matheus-tg9op
@Matheus-tg9op 2 месяца назад
More bug bounty live videos pls !! Im Learning so much watching your videos
@sha2964
@sha2964 2 месяца назад
really
@Neonchannel_
@Neonchannel_ 2 месяца назад
Really
@YungKuoo
@YungKuoo 2 месяца назад
Really
@suddently
@suddently 2 месяца назад
really
@XpEcTZz
@XpEcTZz 2 месяца назад
really
@nmmorette
@nmmorette 23 дня назад
nice content! thanks for sharing
@dk70
@dk70 23 дня назад
The music is: Homesteading on my small organic farm by day, hacking IBM during the night
@runmirage
@runmirage 2 месяца назад
well done! do you also use some linux distro or you only main macos
@glyslay4102
@glyslay4102 2 месяца назад
Great video. Make more livestreams.
@funexpressions6498
@funexpressions6498 2 месяца назад
especially for this video i subscribed
@modymohab4549
@modymohab4549 Месяц назад
Where did you learn bug bounty ?
@CatalystClassroom
@CatalystClassroom 2 месяца назад
very good video bro, where are you from?
@cameronrich2536
@cameronrich2536 Месяц назад
Can you help me please i spent luteral days trying to get spyhunt installed properly and now i get a stupid traceback error nomatrer what i name the file im trying to save to
@rebelavie7772
@rebelavie7772 Месяц назад
hi.. what themes or config (figlet?) do you use in your terminal? The fsociety in the background is really cool...
@harc3rz
@harc3rz 28 дней назад
In MacOS you can simply go to terminal settings and change your background to any photo you like (change the blur of the background, opacity etc.). The rest is ZSH.
@aatankbadboy3941
@aatankbadboy3941 2 месяца назад
Bro you can add notes in which you shortly describe your steps
@bugbouty
@bugbouty 2 месяца назад
bro make a video about finding origin ip and after how to find xss,sqli,ssrf etc with that origin ip address
@atlasdevelopment8683
@atlasdevelopment8683 24 дня назад
If you mean origin ip, as in the backend of a website. Use Censys, Fofa, Zoomeye.
@thienngo2953
@thienngo2953 2 месяца назад
god save you. Bug bounty live. Unbelievable!
@user-kf8wc7iv5t
@user-kf8wc7iv5t 13 дней назад
good
@9kk
@9kk 2 месяца назад
Is there a second part?
@andresbarrera3298
@andresbarrera3298 2 месяца назад
im starting to learn i didnt notice you activated vpn before scan.. do u use vpn before starting scans?
@bo_68
@bo_68 Месяц назад
These "attacks" are completely legal. Companies will ask hackerone to connect with hackers to find network vulnerabilities, such as bug bounties
@andresbarrera3298
@andresbarrera3298 Месяц назад
@@bo_68 but the guys i saw using vpn said they use vpn just if the tools to use make blacklisted your main ip while scanning
@bo_68
@bo_68 Месяц назад
@@andresbarrera3298 As you can see, the author has not been blocked by ibm, if he was blocked he would have changed to using VPN. hahaha
@bo_68
@bo_68 Месяц назад
@@andresbarrera3298 It depends on the scanning blocking mechanism set up by each service
@Hvleos
@Hvleos 2 месяца назад
when did u start doing bug bounties? Like when did you feel ready for them?
@gotr00t0day
@gotr00t0day 2 месяца назад
Once you learn the owasp top ten, you can start hunting for the vulnerabilities
@Dani-Zsh
@Dani-Zsh Месяц назад
I'm sorry for my bad English, but I have a question. I know Apple is Unix based and has Zsh as shell, but are you connected via SSH to another pc or those tools can be used in apple?
@brolytim4303
@brolytim4303 Месяц назад
i think the OS doesnt care much, cuz tools are programmed with python, so if ur SO can run python u you wouldnt have problems
@themay2319
@themay2319 Месяц назад
These tools look like they are all ran in python. It doesn't matter if you are on Mac, Windows, or Linux, as long as it can run python, you can do this method.
@lit1numyt_
@lit1numyt_ Месяц назад
Personally I'm using the M1 macbook. It's not about the OS, it's about the structure the computer are based on. Like my macbook using the M1 chip built on ARM structor, I had have quite a hard time running a lot of tool because most of them are all built on x86 structor (most computer and cpu like Intel and AMD uses the x86 structor). My solution so far was to use an old laptop, install ubuntu and ssh into it like @Dani-Zsh, but it has some drawback of only viable through LAN cause I'm a college student and I can't mess with the dorm room network to open a NAT port for remote uses. Another solution that best work for me was to use a AWS cloud computer. They has x86 base and are free for low-end rig (750hours each month for a year. after a year just shut it down and create a new account) and they already has a public ip, PEM key made easy for remote use.
@lit1numyt_
@lit1numyt_ Месяц назад
Older macbook that uses intel chip are fine tho
@Fuadkamalkamal
@Fuadkamalkamal 2 месяца назад
more videos please :)
@ozzysraiyan1096
@ozzysraiyan1096 2 месяца назад
hello , can you help me roadmap study for search bug bounty. Thank you very much
@abdelrahmanfarghly7135
@abdelrahmanfarghly7135 2 месяца назад
what is your hackerone acc???
@tilloevfaridun9135
@tilloevfaridun9135 2 месяца назад
When i install -r requirements i got this -->ERROR: Could not find a version that satisfies the requirement codecs (from versions: none) ERROR: No matching distribution found for codecs How to resolve? Thank you ~
@immo189
@immo189 Месяц назад
cat the requirements, pip install install requirements separately run spyhunter after each install (I am assuming it's spyhunter) see the error and repeat install process for each lib or software etc that is required.
@milanesasconpure2523
@milanesasconpure2523 2 месяца назад
Hola bro, hace un tiempo hago CTFs, pero no me animo a darle al bug bounty y me gustaría poder adquirir experiencia explotando entornos reles, que me aconsejas?? Yo de momento no me e animado por el tema de las limitaciones y de aue no puede hacer fuzzing o cosas asi, entonces no me animo mucho a hacer bug bounty
@gotr00t0day
@gotr00t0day 2 месяца назад
Comience a hacer lo basico en la academia web de Portswiggers, aprendera mucho sobre todas las vulnerabilidades de web.
@milanesasconpure2523
@milanesasconpure2523 2 месяца назад
@@gotr00t0day gracias 👍 muy bueno tu contenido, seguí así Bro 💪
@jameshernandezm.8563
@jameshernandezm.8563 Месяц назад
Dale sin miedo, eso es como cuando empiezas a usar linux, te da miedo la cli pero una vez te tiras ya la agarras ritmo. También estoy empezando al bug bounty pero la única manera de saber mas es practicando.
@milanesasconpure2523
@milanesasconpure2523 Месяц назад
@@jameshernandezm.8563 uh yo no me animo mucho jaja, sobretodo porque en lo que "no está permitido", te ponen muchas restricciones con temas como el fuzzing web o enumeración de sub dominios y la verdad es que eso es necesario hacerlo, sino de que modo podrías encontrar algo?? Me da miedo más que todo el tirar una herramienta para realizar búsquedas porque podría tirar el servidor. Pero acá el amigo le manda sin miedo por lo que veo jaja
@Fractal_reComm
@Fractal_reComm Месяц назад
visão avançada
@potcleanx7693
@potcleanx7693 2 месяца назад
can you explain what your doing like it would much better if you do
@songenjoyer2655
@songenjoyer2655 21 день назад
where can i find the music background?
@brolytim4303
@brolytim4303 Месяц назад
buen video bro, sabes de alguna buena academia en español? o toca traducir jeje saludos desde Argentina!
@gotr00t0day
@gotr00t0day Месяц назад
Puedes encontrar muchas en Google jeje. Solo toca buscar, se que también hay muchos vídeos que enseñan seguridad informática en español en RU-vid. Buena suerte ;)
@moh3507
@moh3507 Месяц назад
please release more videos please
@princebablubiever2593
@princebablubiever2593 Месяц назад
Bro did you customize kali linux to look like mac os or is it actually mac os
@gotr00t0day
@gotr00t0day Месяц назад
It’s actually macOS ;)
@MDKhairulIslamBablu
@MDKhairulIslamBablu 29 дней назад
​@@gotr00t0day How did you do it means Macs can't be used for hacking or penetration testing but how did you do it and do you have any related videos
@gotr00t0day
@gotr00t0day 29 дней назад
@@MDKhairulIslamBablu Mac’s can be used for hacking and coding, not sure why people think otherwise lol ;)
@MDKhairulIslamBablu
@MDKhairulIslamBablu 29 дней назад
@@gotr00t0day brother please upload a video about how can we make our Mac os as a Hacking Machine please 🥺
@gotr00t0day
@gotr00t0day 29 дней назад
@@MDKhairulIslamBablu Ok ;)
@DexCode1337
@DexCode1337 2 месяца назад
fsociety💀💀💀💀
@jaxjaxgaming8033
@jaxjaxgaming8033 2 месяца назад
hello, i would like to know what specs do you have for your mbp, is 18gb enough ?
@gotr00t0day
@gotr00t0day 2 месяца назад
16GB is enough, 512GB SSD with the M3 chip and wireless Magic Keyboard / mouse. ;)
@aritdutta8400
@aritdutta8400 3 дня назад
Are you using M1/M2/M3 or Intel chip processor ??? Use any cloud VM and connect through ssh or the whole lab set up on your original host???
@gotr00t0day
@gotr00t0day 3 дня назад
I’m using the iMAC M3 16GB of RAM and 512 SSD which is awesome
@aritdutta8400
@aritdutta8400 3 дня назад
​@@gotr00t0day I'm using M1! The whole lab set up on your local host??? or Use any cloud VM and connect through ssh???
@aritdutta8400
@aritdutta8400 3 дня назад
@@gotr00t0day I'm using M1. This whole Lab setup on your local system (imac) or u are using cloud vm which you connect through ssh????
@gotr00t0day
@gotr00t0day 3 дня назад
@@aritdutta8400 no
@aritdutta8400
@aritdutta8400 3 дня назад
@@gotr00t0day That's mean you setup the whole lab on your local system (imac) ??
@user-pw5cc6bj4r
@user-pw5cc6bj4r Месяц назад
nice terminal
@natureandskies9140
@natureandskies9140 2 месяца назад
Brother all the tools you use i have already installed but i can't install burpsuite bcoz i am using my phone to do these things,i have installed all the things on my cloud shell,can you tell me any subprogram like burpsuite which i can use on my phone or on my terminal?
@alphacentauri8035
@alphacentauri8035 2 месяца назад
i think mitmproxy can also intercept and modify requests and it's command line based.
@aliuzun8885
@aliuzun8885 10 дней назад
Only recon but its k ty.
@khunjame7
@khunjame7 2 месяца назад
I am using macbook too can you tell me how to get all the tools that you use thanks.
@gotr00t0day
@gotr00t0day 2 месяца назад
You can either brew install them or clone the repo from github
@kamilwielgus4917
@kamilwielgus4917 2 месяца назад
please forgive me total lack of skills and possible nonsense coming out my comment. Great stuff you do here. Right now its black magic for me, im just a guy who enters this industry at the late age....but the stuff you do is great and the music in the background makes it more interesting. If you are willing to write some analytic guideline would be great. What i see you run spyhunt and httpx which you constantly modify on the go to fit the scope, which is great adjustment. I understand you inject some payloads, right ? To check vulnerabilities and adjust your pentesting tools, right ? I see you did something with Burp. I tried once at school to get a cookies info or something. What music you play by the way, some spotify playlist ?:)
@gotr00t0day
@gotr00t0day 2 месяца назад
I write my own tools, that's why you see me modifying spyhunt on the fly. Burpsuite is the go to to intercept traffic and really test the application for vulnerabilities.
@squertalplush6255
@squertalplush6255 17 дней назад
How did you learn how do this and how did u install the kali on mac os
@bangzoel7974
@bangzoel7974 10 дней назад
🫣🫣🫣
@Dramon11
@Dramon11 2 месяца назад
the spyhunt version 1.7 where can i found it ?
@immo189
@immo189 Месяц назад
he has a github page
@aceagiotakrl
@aceagiotakrl Месяц назад
Where did you acquire all this knowledge?
@Memes_Machine344
@Memes_Machine344 Месяц назад
internet
@codewithastrodev
@codewithastrodev 2 месяца назад
Damn Bro your video is 360p and without audio
@gotr00t0day
@gotr00t0day 2 месяца назад
Is processing, its always 4K.
@codewithastrodev
@codewithastrodev 2 месяца назад
Good to hear that continue and btw you are awesome@@gotr00t0day
@therealer_
@therealer_ Месяц назад
how did you installed dirsearch on mac?
@keloo5215
@keloo5215 13 дней назад
x2
@therealer_
@therealer_ 7 дней назад
@@keloo5215 wdym?
@infosx4875
@infosx4875 2 месяца назад
Post more, in the near future I'll start hackerone challenges. I'm studying JAVA, what lang do you code?
@gotr00t0day
@gotr00t0day 2 месяца назад
Python
@gangbang7354
@gangbang7354 Месяц назад
can someone please tell me which OS is this Parrot or Kali? or any other linux distro
@filmrolls3165
@filmrolls3165 Месяц назад
This is just macos & using it's terminal
@0xgreyhound
@0xgreyhound 2 месяца назад
hello
@denverledinosor3694
@denverledinosor3694 Месяц назад
is it legal to share those info ?
@MsIlRusso
@MsIlRusso 25 дней назад
as long as the company is aware of the vulnerability and fix it i think pretty safe.
@zcsz.
@zcsz. Месяц назад
what's with this music bro are you hacking or riding an elevator
@dollaz4647
@dollaz4647 2 месяца назад
I have no idea wtf any of ts is.
@reddress1952
@reddress1952 2 месяца назад
Hahahahahaha
@jaimec5672
@jaimec5672 2 месяца назад
How do u install spyhunt it keeps giving me errors
@gotr00t0day
@gotr00t0day 2 месяца назад
Open an issue request on github and I’ll look at it
@jaimec5672
@jaimec5672 2 месяца назад
@@gotr00t0day done
@alphacentauri8035
@alphacentauri8035 2 месяца назад
This is hypnotizing
@thecarrot1728
@thecarrot1728 Месяц назад
why are so many people so shocked you're using macos lol
@gotr00t0day
@gotr00t0day Месяц назад
Idk lol, only if they knew that MacOS is based on Unix just like Linux.
@atakanyanar18
@atakanyanar18 2 месяца назад
only enum right ?
@gotr00t0day
@gotr00t0day 2 месяца назад
Yeah, is mostly reconnaissance, I don’t like exploiting anything on the live, unless is CTF or something like that
@atakanyanar18
@atakanyanar18 2 месяца назад
@@gotr00t0day i got dude thanks :) keep going on
@bruno-devs
@bruno-devs Месяц назад
github of the tools used in the video?
@gotr00t0day
@gotr00t0day Месяц назад
www.github.com/gotr00t0day/spyhunt ;)
@youtubersnews81
@youtubersnews81 28 дней назад
V1.8
@IRateStuff
@IRateStuff 2 месяца назад
can you provide dirsearch txt?
@smartrahman6245
@smartrahman6245 2 месяца назад
I need your desktop wallpaper and terminal
@gotr00t0day
@gotr00t0day 2 месяца назад
The desktop wallpaper was made by a friend of mine, and the terminal background you can find on google by searching Fsociety ;)
@Ox7H3_L1ON
@Ox7H3_L1ON 2 месяца назад
day this is the error I get when I try and install spyhunt "ERROR: Could not find a version that satisfies the requirement codecs (from versions: none) ERROR: No matching distribution found for codecs " Your assistance will be highly appreciated
@immo189
@immo189 Месяц назад
run apt update first, then run install and if you have errors see my response further up
@luv1099
@luv1099 2 месяца назад
360p 😪
@codewithastrodev
@codewithastrodev 2 месяца назад
FAX
@gotr00t0day
@gotr00t0day 2 месяца назад
Not anymore ;)
@mohmino4532
@mohmino4532 2 месяца назад
here its 4k 🙄
@bitGbit
@bitGbit 2 месяца назад
Music way too distracting
@gotr00t0day
@gotr00t0day 2 месяца назад
Sorry, a lot of people like it with the background music lol
@jesusangelchavezhuaman2543
@jesusangelchavezhuaman2543 2 месяца назад
Can you pass me your Kali Linux style?
@alphacentauri8035
@alphacentauri8035 2 месяца назад
This is not kali, it's macbookpro with macos..
@mohmino4532
@mohmino4532 2 месяца назад
nice vid but i have tried to install ur tool but it doesn't work and i got this error : Found nodejs Found npm Traceback (most recent call last): File "/home/djamelof/bugbounty-tool/spyhunt/install.py", line 34, in command("npm install broken-link-checker -g") NameError: name 'command' is not defined. Did you mean: 'commands'?
@gotr00t0day
@gotr00t0day 2 месяца назад
Fixed, you can pull now to update.
@mohmino4532
@mohmino4532 2 месяца назад
@@gotr00t0day thnx i will give it try again than i will tell u what happend
@CyberTechwithNikhil
@CyberTechwithNikhil 2 месяца назад
Bro your telegram channel link?
@Anonymous-Duniya
@Anonymous-Duniya 2 месяца назад
please share spyhunt repo link
@gotr00t0day
@gotr00t0day 2 месяца назад
www.github.com/gotr00t0day/spyhunt
@Anonymous-Duniya
@Anonymous-Duniya 2 месяца назад
Thanks@@gotr00t0day
@nlegendgaming8324
@nlegendgaming8324 2 месяца назад
Your telegram?
Далее
What Makes Israel So Good at Hacking?
16:28
Просмотров 1,9 млн
Elliot Wins A Hacker Tournament | Mr. Robot
6:59
Просмотров 1,5 млн
Remotely Control Any PC with an image?!
12:42
Просмотров 125 тыс.
3 Levels of WiFi Hacking
22:12
Просмотров 1,6 млн
Tracking Cybercrime on Telegram
23:26
Просмотров 288 тыс.