Тёмный
No video :(

The Bug Hunter's Methodology v4.0 - Recon Edition by  

NahamSec
Подписаться 136 тыс.
Просмотров 147 тыс.
50% 1

Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training
Live Every Tuesday, Saturday and Sunday on Twitch:
/ nahamsec
Follow me on social media:
/ nahamsec
/ nahamsec
twitch.com/nahamsec
hackerone.com/nahamsec
/ nahamsec1
Free $100 DigitalOcean Credit:
m.do.co/c/3236319b9d0b
Signup for HackerOne:
nahamsec.stream/HackerOne
Signup for Hacker101:
nahamsec.stream/H101
Github:
github.com/nahamsec
Nahamsec's Discord:
discordapp.com/invite/ucCz7uh

Опубликовано:

 

18 июн 2020

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 80   
@pentestical
@pentestical 4 года назад
I can't believe how much free content you provide. Thanks!!
@edwinosantos
@edwinosantos 3 года назад
Dominican Republic we have a saying, maybe other places do too, when something is too good to be true usually isnt but maaaaaaan this is good content. Nahamsec you are the man!! thanks for gathering all those super smart dudes and freely allow us to learn from then. Thank you Thank You.
@TheWhaleon
@TheWhaleon Год назад
I will probably watch this five more times. So unbelievable useful information. Thank you!
@andreasMou123
@andreasMou123 4 года назад
YES! I've been waiting for this forever. Thanks for the all the good content naham, you're true legend!
@g33kyf3z
@g33kyf3z 2 года назад
Thanks for all the great information from this keynote. Got some really good notes for my B.B Journey.
@rodgers48
@rodgers48 3 года назад
five minutes of your video guive more information on Recon as opposed of all i have learned in the past, Terrific
@ichigok2594
@ichigok2594 4 года назад
Nice. Always learning new tools from here. 🙏
@angeldev96
@angeldev96 4 года назад
waited for this so much!! Now upload the tomnomnom talk plz.
@JasonGomes140294
@JasonGomes140294 4 года назад
Been Waiting for this.... thanks Ben 🙌
@SICKFREDO
@SICKFREDO 4 года назад
Hell yeah right before the weekend
@rokkamvamsi18
@rokkamvamsi18 5 месяцев назад
00:06 Bug Hunters Methodology V4.0 is split into two parts: Recon and Application Analysis. 02:31 Project tracking is an important part of the bug bounty and pen testing methodology 06:40 Wide recon involves multiple distinct sections of work 08:42 Verizon Media's bug bounty program has a wide scope. 12:58 Automating recon can be risky without proper context 15:27 Using ASN numbers and IP scanning to gather seed domains for recon. 19:34 The Bug Hunter's Methodology v4.0 - Recon Edition by @jhaddix #NahamCon2020! 21:37 Finding related domains and seed domains 25:40 Link discovery using Burp Suite for finding linked assets or links inside a site. 27:49 Passive scanning using Burp and setting advanced scope control with a keyword. 31:24 Using Burp Suite Pro to extract data can be clumsy. 33:24 Different tools and methods for URL crawling and subdomain discovery 37:17 Subdomain scraping is a crucial step for finding more assets 39:13 Methods for finding subdomains include using search engines and subdomain scraping tools like amass and subfinder. 43:05 Twitch uses various cloud technologies and third-party services 45:08 Use the github subdomains dot py tool to find hidden subdomains on github. 49:13 Using subdomain enumeration tools for bug hunting 51:02 Scraping cloud ranges and scanning SSL certificates help in finding hidden dev sites. 55:13 Using a large list of common subdomain names to resolve them and find any successful connections. 57:03 There are two approaches to building word lists: tailored lists and all-encompassing massive lists. 1:00:54 Use custom word lists related to Twitch for DNS subverting to find potential related domains. 1:02:48 Using permutation scanning to find obscure subdomains and bypass web location firewalls. 1:06:42 Use the tool 'masscan' for fast port scanning on IP addresses. 1:08:36 Using en masse scan as a wrapper around mask to resolve domains and perform port scanning. 1:12:50 Bash script to perform Github Dorking and find leaked sensitive information 1:14:45 Utilize automated tools and GitHub for effective reconnaissance. 1:18:37 Subdomain takeover vulnerability can result in the takeover of legitimate traffic of former domains. 1:20:49 Nuclei is a comprehensive scanning framework with subdomain takeover templates. 1:24:52 Interlace and Tom nomnom's tools are useful for automating workflow in bug hunting. 1:26:40 Different tiers of recon frameworks based on automation and workflow 1:30:12 Different tiers of recon methodologies 1:32:06 Intrigue and Assetnote are powerful SAS services for reconnaissance and asset management. 1:36:03 The Bug Hunter's Methodology v4.0 - Recon Edition 1:38:04 Appreciation for the bug bounty and pen test community
@WMarco93
@WMarco93 3 года назад
so much value in this video! thanks :)
@rafajanicki2456
@rafajanicki2456 4 года назад
Super Cool :D Thanks Jason Haddix for this talk and NahamSec for posting this on YT :) Sooo many new tools and techniques to test! You're awesome Guys :)
@nehalahmad11
@nehalahmad11 4 года назад
The contents are amazing. The only problem is video quality, Please atleast 720p
@user-kg9sq3vr8m
@user-kg9sq3vr8m 4 года назад
amazing! Thank you!
@randallcharlestuckermrcyse1479
Thank you for the Methodology, as I am starting out on Bug Hunting and most automated tools are not welcomed, so I was stumped on how to be able to Bug Hunt. I am going to learn from this video and start my Bug Hunting to earn Rep + Money is the bonus.
@bata3258
@bata3258 Год назад
how's the progress going???
@nightninja8128
@nightninja8128 2 года назад
Bro this is amazing!
@Anonymous-ik7nr
@Anonymous-ik7nr 2 года назад
Thanks for the lessons. Will keep learning. Lol
@mazingerzeta2xx788
@mazingerzeta2xx788 4 года назад
This is GReat!, where can get the whole list of the tools, or copy of these sides? thanks
@HassanRaza-ek3mv
@HassanRaza-ek3mv Год назад
"Where can I get these slides?" to "Screenshotted the all slides" Love from Sweden :)
@goebbelsx
@goebbelsx 4 года назад
Awesome!
@sarfraztek
@sarfraztek 3 года назад
you rock ! NAHAMsec
@Better403
@Better403 3 года назад
You are a legend
@albertkentbanico9822
@albertkentbanico9822 3 года назад
Thanks Senpai!
@tommysuriel
@tommysuriel 4 года назад
what about aquatone for subdomain takeover checks?
@KAFOSHY
@KAFOSHY 4 года назад
😍🙏🥺thanks bro
@Alex-oh6lj
@Alex-oh6lj 3 года назад
Is there a pdf or book written for this content?
@muralikumarrr
@muralikumarrr 3 года назад
Your name 'jason haddix' sounds like someone who plays the lead role in an action flix
@AnlStarDestroyer
@AnlStarDestroyer 2 года назад
I’ve been messing around with bug bounty for awhile now but never seriously giving it a go, I usually poke around and do basic manual stuff then if nothing happens in an hour or so then I stop and start from scratch again in a week or two. I think this next time I’m going to pick a program, literally follow along with this video as I go and save all my scan results and notes so I can pick up where I left off with the same program.
@himansh0715
@himansh0715 2 года назад
First try to hunt on Government programs, then Vdps then go for platforms with low users, you will learn a lot👍🏼
@emmanuelchinedum6998
@emmanuelchinedum6998 2 года назад
@@himansh0715 what are the vdps and govt program?
@himansh0715
@himansh0715 2 года назад
@@emmanuelchinedum6998 VDP - Vulnerability Disclosure Program, Govt program - Country government sites ( programs ) like Indian, US, Dutch sites
@emmanuelchinedum6998
@emmanuelchinedum6998 2 года назад
@@himansh0715 thankyou
@emmanuelchinedum6998
@emmanuelchinedum6998 2 года назад
@@himansh0715 I'm new to bug bounty lol…i just finished the sql labs on portswigger so i wanna test out what i know….i think i need to learn recon first right?
@maxicorbs
@maxicorbs 3 года назад
Was the TBHM v4 Application Analysis edition ever released? Can't find a link, thanks
@irph2
@irph2 4 года назад
Nice one, 1080p please :(
@badsharma4413
@badsharma4413 4 года назад
really big thanks @nahamsec love from nepal !!!!
@sail3sh703
@sail3sh703 4 года назад
hora vanya..
@cimihan4816
@cimihan4816 4 года назад
teita
@SankizTime
@SankizTime 3 года назад
Oho, Nepali hackersssssss
@bata3258
@bata3258 Год назад
@@cimihan4816 huff ma 2 barsa late vayexu
@cimihan4816
@cimihan4816 Год назад
@@bata3258 haha
@FredsRandomFinds
@FredsRandomFinds 2 года назад
He mentions a tool for scraping keywords around half way through? anyone know what tool this is?
@hacktivist8457
@hacktivist8457 4 года назад
Direct like ❤
@premprakash6138
@premprakash6138 2 года назад
You are great
@user-ub6xe3zw7o
@user-ub6xe3zw7o 3 года назад
If there is a PPT to provide IU, it will be more nice
@Endermanvevo123s
@Endermanvevo123s 2 года назад
what is happening after recon
@secmind5520
@secmind5520 4 года назад
jason haddix is the best
@miracdasmine
@miracdasmine 4 года назад
I wish those links he showed can be listed here
@MotivationKrishna
@MotivationKrishna 2 года назад
Can we Get TIme Stamp
@hetvikam4754
@hetvikam4754 4 года назад
can i get that ppt
@TheConstantLearnerGuy
@TheConstantLearnerGuy 2 года назад
:)
@sakettestsakettest8009
@sakettestsakettest8009 4 года назад
Plz upload secureinti talk
@hackingetico1
@hackingetico1 Год назад
Oye bro quede en 13:22
@limeeater22
@limeeater22 3 года назад
can we download the slides?
@truthseeker4678
@truthseeker4678 3 года назад
I found the pdf on google, just look for it.
@rodricbr
@rodricbr 2 года назад
docs.google.com/presentation/d/1MWWXXRvvesWL8V-GiwGssvg4iDM58_RMeI_SZ65VXwQ/edit#slide=id.g89b65a088d_1_0
@cbbitv2534
@cbbitv2534 3 года назад
Hi bro can I privately chat with you
@shemot911
@shemot911 4 года назад
TomNomNoms Talk?
@TomNomNomDotCom
@TomNomNomDotCom 4 года назад
ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-W4_QCSIujQ4.html
@bubbanstix841
@bubbanstix841 2 года назад
jason. You have my head. Nice names for your daughters. I hope i will be same as you. Thnks btw.
@cuti7233
@cuti7233 5 месяцев назад
pdf spanish ?The Bug Hunter's Methodology v4.0 - Recon Edition by @jhaddix???
@tamjid0x01
@tamjid0x01 4 года назад
@Siik94Skillz
@Siik94Skillz Год назад
95% of the people in here wont get past installation of all the tools and give up... I know this because that was me when I started
@hackingetico1
@hackingetico1 Год назад
Amigo yo puedo hacer
@Siik94Skillz
@Siik94Skillz Год назад
@@hackingetico1 bueno que tal tu primer bug entonces?
@IMWATCHING501
@IMWATCHING501 3 года назад
One can either be father of 3 or gamer. Not both!
@krshreyansh
@krshreyansh 3 года назад
I am absolutely new to bug hunting and the problem that I am facing is "When I catch a request in burp it is really confusing I can't understand which request to work on and which to not I get really confused" please help if you can .
@cyberpirate007
@cyberpirate007 4 года назад
Indians like here....... Indian hackers show our unity by hitting the like--
@shrirangkahale
@shrirangkahale 4 года назад
This is great But where is Binod & Pls don't put add in betn. the video..... Especially when it is High quality speech Byee Binod
@aadhi5006
@aadhi5006 3 года назад
Hii guys, iam a beginner web application enthusiastic. Who is interested web application security.well, I thought i know some foundation's so, I want to touch a security issues. Iam confused which one is good resource and which one to pick and start.: portswigger notes or owsap top 10 or web application hackers hand book iam stuck could you suggest me to become a good web pentester.
Далее
Daltonik qiz (QVZ 2024)
00:53
Просмотров 146 тыс.
What Should You Do After Recon?!
14:47
Просмотров 27 тыс.
Live Recon: Hacking a Bank (Ethically)
1:48:23
Просмотров 29 тыс.
Solving a REAL investigation using OSINT
19:03
Просмотров 153 тыс.
Raspberry Pi Pico 2: a RISC-V bet!
8:05
Просмотров 72 тыс.
How to Use Amass Efficiently by @jeff_foley #NahamCon2020
1:56:07
The Bug Hunter’s Methodology Jason Haddix @jhaddix
1:16:16