Easy $500 Vulnerabilities! // How To Bug Bounty

Sdílet
Vložit
  • čas přidán 20. 08. 2024

Komentáře • 243

  • @SyedShayan-yt3in
    @SyedShayan-yt3in Před 9 měsíci +154

    Hey! Would love to see the demo videos on each vulnerablity type.

    • @NahamSec
      @NahamSec  Před 9 měsíci +44

      Noted!🫡🫡

    • @eviI_genius
      @eviI_genius Před 9 měsíci +6

      @@NahamSec yes we want demo, specially it would be great if you explain us XSS in deep like using the dev tools, inspecting the element, give us some deets about how backend XSS works, I really loved ur Bling XSS video :) it would be great if you build up on that

    • @darkalpha2701
      @darkalpha2701 Před 9 měsíci +1

      @NahamSec I would really love to see demo video of IDOR

    • @karthik3387
      @karthik3387 Před 9 měsíci

      Plse do vedio

    • @CruzNateChroniclles
      @CruzNateChroniclles Před 9 měsíci

      Video vulnerability examples would be great.

  • @marcelosmoniz
    @marcelosmoniz Před 9 měsíci +21

    ● [1:41] Prerequisites: HTML, Web Technologies
    ● [1:57] #1 - XSS
    ● [4:03] #1(2) - CSRF
    ● ● [4:11] Burp Suit PRO : "Engagement tools" -> "Generate CSRF PoC"
    ● [6:22] #3 - IDOR
    ● [8:46] #4 - Authorization Issues
    ● [10:34] #5 - Leaked Credentials

  • @minimanimo7636
    @minimanimo7636 Před 9 měsíci +54

    It would be very helpful and interesting to have videos on:
    - How to quickly and efficiently write a bug report (templates, automation, AI and so on...)
    - What are the most common BBPs policies and practices for not breaking them (rate limit, automation limitations)
    - Burp suite: best extensions and when to use
    Thanks mate, love your videos and appreciate your work!

  • @MrFrankenstock
    @MrFrankenstock Před 9 měsíci +21

    Hands-on demo would definitely be a great way to absorb and ultimately solidify this content in the old brain! Thank you, Ben!

  • @MarkFoudy
    @MarkFoudy Před 9 měsíci +24

    Yes please do a demo of the vulnerabilities. Love your encouragement! Your videos always pump me up!

    • @NahamSec
      @NahamSec  Před 9 měsíci +10

      Thanks for watching and thank you for being a channel member! 🙏

    • @MarkFoudy
      @MarkFoudy Před 9 měsíci

      of course! I hope to meet you at defcon in the future. Your content has been so impactful for me. @@NahamSec

  • @mianashhad9802
    @mianashhad9802 Před 9 měsíci +20

    CSRF and IDOR hands-on tutorials would be interesting. Would love to see some handy tricks for when our attacks aren't working.

  • @papafhill9126
    @papafhill9126 Před 9 měsíci +7

    Honestly, I care less about learning the hands-on-tutorials about specific vulns, I would much rather see a tutorial on how to enumerate a target and suggestions on how to learn the technology the target is using. What questions should I be looking to answer about that tech? How to check for previous CVEs on that specific tech? Then maybe most importantly, how can track data flow of the target with that specific tech in mind. The issue with seeing tutorials on specific attack types seems to be trying to attack the same few input fields for hours but ignoring the all the technology used on that webpage that would likely tell me, "Hey, this page is pretty secure, maybe keep digging into other subs/ends."

  • @omarmahmood4209
    @omarmahmood4209 Před 7 měsíci

    Yes, would absolutely love a hands on video on each of all the topics!
    1. XSS
    2. CSRF
    3. IDOR
    4. Auth Issues
    5. Leaked Creds

  • @DavitHayrapetyan-tc1uj
    @DavitHayrapetyan-tc1uj Před 9 měsíci

    this channel is literally a goldmine, don't understand how it's only 105k subscribers

  • @azoosh
    @azoosh Před 9 měsíci +2

    Yes! I would very much want to see more hands on videos on these bugs :) Your videos are awesome always!

  • @user-hm7yd4ql3u
    @user-hm7yd4ql3u Před 9 měsíci +2

    Am planning on being a full time bug bounty hunter this coming January, but my piggy bank is still behind ..if i could i would take your bug bounty course to fortify my skills..,gotta say your vids really motivate me..cheers!! from Botswana

  • @alexandriarichard7671
    @alexandriarichard7671 Před 8 měsíci +1

    Listen $500 is a lot for me and thank you so much for this video! I am going to focus on Blind XSS and start your Udemy course thank you!

  • @bertrandfossung1216
    @bertrandfossung1216 Před 9 měsíci +1

    A hands on version of this video where you can make some labs will be highly appreciated. Thanks for the cool heads up !!

  • @MW-cs8zd
    @MW-cs8zd Před 9 měsíci +2

    I would love more videos like this from you. Very helpful. Thank you

  • @TrailMix324
    @TrailMix324 Před 8 měsíci

    Yes i would genuinely love to see and would definitely watch hands on demo videos of each vulnerability type

  • @VinceOConnor
    @VinceOConnor Před 9 měsíci +1

    Yes, Love the content and would love you to do a demo of the vulnerabilities.

  • @ASecurityPro
    @ASecurityPro Před 9 měsíci +1

    Please do a hands on version of each vulnerability . Thank you man ❤

  • @marijasilentj969
    @marijasilentj969 Před 9 měsíci

    Yes please! You really talanted tutor! It easy to understand and follow you. Thank you a lot xx

  • @sandeeppn1876
    @sandeeppn1876 Před 9 měsíci +1

    Yes demo will be very helpful

  • @prasadande5690
    @prasadande5690 Před 9 měsíci +1

    Yes Ben, Please also provide a demo of all those vulnerabilities :)

  • @nhlimon201
    @nhlimon201 Před 9 měsíci +3

    Hey Ben, It will be better to share step by step resources to learn, master and get confidence of hunting for a specific bug. :) It would be a really awesome content. People like me sometimes get confused how they could master a bug and how to learn that at an insane level to get out of average hackers. So I hope you'll make this content in near future.

  • @rizvanhawaldar
    @rizvanhawaldar Před 9 měsíci

    If I get $500 based on content made available for then I will purchase your course based on that. Good luck to you too!

  • @francisstocktilliii2413
    @francisstocktilliii2413 Před 4 měsíci

    I would love to see a hands-on video of this. That's exciting to hear.

  • @alexaliwarlock
    @alexaliwarlock Před 9 měsíci

    That’d be awesome to see a demo video. Keep up the great and educational content! 🙌

  • @shriyanssudhi4545
    @shriyanssudhi4545 Před 9 měsíci +1

    I'd love to see a video on Authorization issues.
    Though I've found some, but I feel I am missing something.

  • @deekshithkalakotla9024
    @deekshithkalakotla9024 Před 4 měsíci

    We want full video hands on each concept ❤

  • @darealist232003
    @darealist232003 Před 8 měsíci

    Yes, can we get a demo video showing how to look for these vulnerabilities. I just got my Sec+ and have been interested in learning more about bug bounty. Thanks for the video and get up the great work.

  • @IvanIvanov-ix5no
    @IvanIvanov-ix5no Před 9 měsíci +1

    I am looking forward to seeing a demo of those vulnerability types :)

  • @mynameisrezza
    @mynameisrezza Před 9 měsíci

    Gold! Cant wait to see the demo of those vulns, thanks ben!

  • @Z0nd4
    @Z0nd4 Před 6 měsíci

    I like this content. Yes NahamSec, please do more videos. Thank you.

  • @mrashco
    @mrashco Před 9 měsíci +1

    Would love more in-depth videos on each topic mentioned!

  • @Sasquatchbones
    @Sasquatchbones Před 6 měsíci

    Honestly learned a lot really fast, clickbait was worth it 😂

  • @litebulbentertainment
    @litebulbentertainment Před 9 měsíci

    Yes.... The content is really good... Looking for demo video on each vulnerability

  • @Cyber10791
    @Cyber10791 Před 9 měsíci

    Needs brother these types of beginners friendly bugs and how to test for it it's very helpful.
    Looking forward too see these types of videos.

  • @socalledhacker
    @socalledhacker Před 9 měsíci +1

    Now i am waiting for nxt Monday

  • @SHADOW-uk2rq
    @SHADOW-uk2rq Před 9 měsíci +1

    Hands on videos yessssss

  • @kirubakarankalidass6707
    @kirubakarankalidass6707 Před 9 měsíci +1

    not easy, I try for passed 3 years, I didn't find any bugs, I don't why but I learn lot like python, linux, networking. I don't know why i can't able to find anything, they said recon, why we have to perform recon, after recon what will do. If i search for Software Engineering roadmap, it give accurate roadmap to take action. but there is not roadmap for bbh. I don't know lot of things why we have to perform this. please give accurate to correct roadmap to success in bbh and lot of resources is there. i don't what path is correct and which path i need to follow. Please give some resources to help to become find my first bug.

  • @EmmettBrown9
    @EmmettBrown9 Před 9 měsíci

    i want a hands-on version of this. I love these videos.

  • @akshaybhorde3787
    @akshaybhorde3787 Před 5 měsíci

    It was very helpful for me. Good approach and techniques. Share your practical knowledge also.

  • @youssefm5079
    @youssefm5079 Před 9 měsíci +1

    Yeeees hands on videos and thank you so much ffor this content

  • @JoseSanchez-ue9wk
    @JoseSanchez-ue9wk Před 6 měsíci

    Yes Naham we would love to see a hands on demo!

  • @ralphandre4438
    @ralphandre4438 Před 9 měsíci

    This is amazing! I want to find my find my first live bug, paid or not before the year end. I would love the video demo.

  • @GoliTech
    @GoliTech Před 9 měsíci +5

    Hi Ben, thanks a lot for the video, please make hands-on as well.

  • @محمّد.09
    @محمّد.09 Před 9 měsíci +1

    We want demo for each of those five.

  • @Mbro-dq2do
    @Mbro-dq2do Před 7 měsíci

    your videos are great Sec. Thanks for the knowledge

  • @jeremyg737
    @jeremyg737 Před 9 měsíci

    It would be awesome to see a video on encoding. Both from a defensive point of view and as a method of obfuscation.

  • @jkong3553
    @jkong3553 Před 8 měsíci

    Def would love to see the demo. Very informative

  • @shurikenhacks
    @shurikenhacks Před 9 měsíci +1

    Dude, clickbait us all you want. LOVE your videos! ❤‍🔥

  • @user-gn7fq3lu8q
    @user-gn7fq3lu8q Před 5 měsíci

    чувак, спасибо тебе за этот ролик! он полезный , круто! продолжай в том же духе 🤘
    Хотелось бы подробнее с примерами о : SSRF, CSRF.

  • @ivanildofreitas7907
    @ivanildofreitas7907 Před 9 měsíci

    Do a demo. We are eager to see that is possible. Nice and educational video by the way! Thanks.

  • @CuriousByteYT
    @CuriousByteYT Před 6 měsíci

    Yes we do need a hands on explanation :)

  • @umegakweekene
    @umegakweekene Před 9 měsíci

    Yeahh, please do demo vids on them. And practical low hanging fruits

  • @darklord5231
    @darklord5231 Před 9 měsíci

    Yes we would like to see videos on each vulnerability

  • @marlinshanklin-ww7em
    @marlinshanklin-ww7em Před 8 měsíci

    500$ works for me let's get started.

  • @ismailsaid6389
    @ismailsaid6389 Před 9 měsíci

    Man, for god sake i love your content

  • @damavox
    @damavox Před 9 měsíci

    I love ya dude and you do a lot of for the community!
    But as someone who heard the same information from different sources what I would love to see is training, the secret sauce, and technique sharing. I know in bug bounty those things are held close to the chest but for someone stuck in the middle from beginner to practitioner, it would really help all us in that position to advance and level up.
    I would even be willing to pay.
    Thank you my friend
    Let's see that demo!

    • @mugstep
      @mugstep Před 8 měsíci

      You just unlocked how bug bounty hunters really make money.

    • @damavox
      @damavox Před 8 měsíci

      @@mugstep 🤣🤣
      I'm going to assume lots of sarcasm in that comment to which in hindsight.
      I completely agree.

    • @damavox
      @damavox Před 8 měsíci

      @@mugstep I'm sure jason haddix's course is full of information like that.
      At least enough for one to develop their own secret sauce but also I want to hear from different sources.

  • @5checktech357
    @5checktech357 Před 5 měsíci

    Yes, please, the video will be awesome.

  • @baravind719
    @baravind719 Před 9 měsíci

    Yeah practical explanation video needed naham ❤

  • @discount_ChadKroeger
    @discount_ChadKroeger Před 9 měsíci

    I love anything cyber so im in. Especially on current bugs and news....Also duhhh show us the hands on.

  • @prakhar0x01
    @prakhar0x01 Před 9 měsíci

    appreciate Ben, Really amazing content.., well we want more content like this, but missing streams and interviews.

  • @lolononojay9010
    @lolononojay9010 Před 9 měsíci +2

    Yes pls show us a demo

  • @muhammaddanialhazimbinmohd5737

    Hands on video showing how to find these vulnerabilities plsss

  • @Drakan1990
    @Drakan1990 Před 9 měsíci

    Want to see those demos! 🤘🏻

  • @hxmo656
    @hxmo656 Před 9 měsíci +1

    For a new starter which bug bounty platform would you recommend; does it really matter whether we pick H1 / Bugcrowd VS a smaller place like Intigrity with less competition surely? 😊

  • @lukeempty3386
    @lukeempty3386 Před 9 měsíci +1

    Do you think burpsuite pro is worth while if im just starting out. Almost done with the CBBH course from htb and then doing portswigger labs. I need burpsuite pro to do the portswigger certification though and not sure if its worthwhile if im just starting out

  • @breakoutgaffe4027
    @breakoutgaffe4027 Před 2 měsíci

    Yes please to the demos!

  • @panagiotismitkas5526
    @panagiotismitkas5526 Před 9 měsíci

    Yes we want to see the hands on lab videos. About xss do you recommend kxss to see what is reflected?

  • @rahmat_qurishi
    @rahmat_qurishi Před 9 měsíci

    Love these videos❤

  • @Hariom_Singh22
    @Hariom_Singh22 Před 9 měsíci +1

    Theory + Demo 💯

  • @Death_User666
    @Death_User666 Před 9 měsíci

    Yes demos for all of them please please please
    I need to make extra money to afford my bills and I got 4 months left before I run out of money lol 😂
    I want to learn and I want to be good
    Another video idea could be reading bug bounty scope of work properly sometimes they are confusing to understand fully

  • @siddharthtayade3474
    @siddharthtayade3474 Před 9 měsíci

    Yes. Need demo for the vulnerabilities.

  • @farmerAcademyJO
    @farmerAcademyJO Před 3 měsíci

    yes love this content

  • @francisstocktilliii2413
    @francisstocktilliii2413 Před 4 měsíci

    Yes I would love to see a demo

  • @RR-hl6zi
    @RR-hl6zi Před 9 měsíci

    User engagement. Rawr.

  • @user-xw7qi3wx5w
    @user-xw7qi3wx5w Před 9 měsíci

    Thank you for the video. My question is --
    How do we find XSS if X-XSS-Protection header is placed on every page of a webpage?

  • @lucianjohr5569
    @lucianjohr5569 Před 9 měsíci

    Awesome Naham

  • @BoitumeloKhushiSelelo
    @BoitumeloKhushiSelelo Před 9 měsíci

    it would be helpfull if you can share demo on how to find this vulnerabilities, thank you

  • @j4ck_d4niels
    @j4ck_d4niels Před 9 měsíci

    maybe web tech video will be awesome, some common places to look for, like in swagger ui have xss with low-medium impact

  • @PhantasmagoriaVisions
    @PhantasmagoriaVisions Před 9 měsíci

    Hands-on demo would definitely be a great

  • @ArturoGonzalez-uz1by
    @ArturoGonzalez-uz1by Před 8 měsíci

    Demo video please! This is awesome content!

  • @oscarromero1007
    @oscarromero1007 Před 9 měsíci

    Thanks for the video!!

  • @hailelleultesera8643
    @hailelleultesera8643 Před 9 měsíci

    make a video on authorization issues I would definitely watch that

  • @jamesdriscoll1658
    @jamesdriscoll1658 Před 8 měsíci

    Yes please do a demo video.

  • @turtle6337
    @turtle6337 Před 5 měsíci

    Hands on type of this video would be awesome

  • @elkins540
    @elkins540 Před 9 měsíci

    I will like a hands on video of this type of vulnerabilities.

  • @husseindhooma5816
    @husseindhooma5816 Před 9 měsíci

    Hi Ben, awesome video once again, would love for you to post more content on IDORs and Authorization Issues. Just by the way you don't need to click bait me to get to watch your videos, the whole reason I subscribe to you is cos your content is excellent. I would watch it anyways and support you any day. Would some day love to make a $500 Bounty (IA) but it takes a lot of practice and I just need to get my butt away from streaming crap in the evenings and studying. Thank you once again. Keep up the great work. 😉

  • @user-pp3py3yk9j
    @user-pp3py3yk9j Před 9 měsíci

    it will be very much helpful to us, As a beginner we try to understand to of the vulnerability's and lost our most of the time's, If you do the hand's on video, may be it can push us to do more hand's on practice

  • @lakshaysiwach3652
    @lakshaysiwach3652 Před 9 měsíci

    yes absolutely a demo would be great

  • @zukxxxx0
    @zukxxxx0 Před 9 měsíci

    Actually, when played your videos liked them at the very beginning 😅😅😅

  • @haroonrehman8156
    @haroonrehman8156 Před 7 měsíci

    10:10 Yes Please We want to see it

  • @gem0x00
    @gem0x00 Před 9 měsíci

    Can you make videos for mastering a vulnerability or the most vulns needed alot of thinking to make the vuln have more impact

  • @tedwallace5640
    @tedwallace5640 Před 9 měsíci

    Love the vid. Yes, please do demos...

  • @feedomomics8103
    @feedomomics8103 Před 9 měsíci

    Hey great video, I have a question how to get pentests or rather how to get into pen-testing.

  • @hornedgod2873
    @hornedgod2873 Před 8 měsíci

    Yes. Demos please.

  • @aavezsheikh5781
    @aavezsheikh5781 Před 9 měsíci

    Yes demo of all the vulnerabilities plz

  • @josephvelasquez2677
    @josephvelasquez2677 Před 9 měsíci

    yes, please make demos on the mentioned vulns

  • @59girishunawane47
    @59girishunawane47 Před 9 měsíci

    Where to learn all vulnerabilities is anything except portswigger

  • @musictunez7125
    @musictunez7125 Před 9 měsíci

    Hands on video

  • @piusgabula
    @piusgabula Před 9 měsíci +2

    We will need demos

  • @syedamer130
    @syedamer130 Před 9 měsíci

    can't wait to see demo