Пікірлер
@808XAND
@808XAND 11 сағат бұрын
Brabo demais!
@razmjumehdi9069
@razmjumehdi9069 12 күн бұрын
Thanks a lot🎉🎉
@bugbountywithmarco
@bugbountywithmarco 4 күн бұрын
thank you!
@exploitxx3
@exploitxx3 16 күн бұрын
Como voce fez o saque pra conta? Teve que avisar a receita federal e pagar imposto?
@R2Deeznutz
@R2Deeznutz 17 күн бұрын
For Javascript URIs, they used to work for me almost every single time I found an open redirect, but nowadays it never works. I found about 10 open redirects in the past two weeks (not exaggerating) and every time I get a "Browser could not redirect to a URL other than https" or something like that. I can't figure out if its the website or the browsers that's causing the error, but I've tried on all browsers and no luck. Any tips?
@bugbountywithmarco
@bugbountywithmarco 16 күн бұрын
there's 2 different ways to execute a Open Redirect. If the Open Redirect is executed by the Location header of the response, unfortunatly, this vulnerability will not tranform into a XSS If the Open Redirect is executed by the javascript code of the application, then the XSS will be valid in this scenario. A quick way to confirm that is by using curl and getting the response header of the open redirect url, for example: curl -i evil.com/redirect?url=google.com If you locate the header below in the response, XSS is not possible: Location: google.com
@Tinera420
@Tinera420 18 күн бұрын
Pelo sotaque da pra perceber q é br kkkk De todo modo, bom video, legal o canal.
@bugbountywithmarco
@bugbountywithmarco 16 күн бұрын
yes haha
@deepakparkash361
@deepakparkash361 19 күн бұрын
Can you teach me 101 meet
@bugbountywithmarco
@bugbountywithmarco 17 күн бұрын
It wont be possible at the moment, sorry
@GerardOPTCG
@GerardOPTCG 20 күн бұрын
That transition at 3:18 scared the hell out of me lol. Great video! Got a new sub for sure.
@bugbountywithmarco
@bugbountywithmarco 20 күн бұрын
Thanks! Gonna definitely lower down the volume next time
@kittoh_
@kittoh_ 8 күн бұрын
Please don't do that again haha
@imperim
@imperim 20 күн бұрын
Thanks for this video.. As expert bug bounty hunter or ethical hacker how u find bugs can we know they method or way of you? Can u make your journey video of reaching target? I mean first you see programs on hacker one than do start testing.. Than u find vulnerability can we see that journey on your next time? I mean how much ,effort what tools and how u reached thanks in advance..
@bugbountywithmarco
@bugbountywithmarco 20 күн бұрын
i can’t actually record it on a real bugbounty target. But I believe I could record it on some application I developed in the past. Thanks for the idea
@imperim
@imperim 20 күн бұрын
Thanks bro waiting for it 💕👍
@exploitxx3
@exploitxx3 21 күн бұрын
Top!
@bugbountywithmarco
@bugbountywithmarco 21 күн бұрын
hey, thanks for watching my video! Please let me know any themes that you would like to see in a software engineer perspective
@exploitxx3
@exploitxx3 20 күн бұрын
Uma dúvida! Devo ter um conhecimento profundo de programação pra começar a caçar ou só o básico tá ótimo?
@exploitxx3
@exploitxx3 23 күн бұрын
Opa, BR aqui!!!! Me dê uma dica, quero começar a caçar, mas existem muitas falhas, posso pegar só 3 e começar a explorar ou devo focar em várias?
@exploitxx3
@exploitxx3 23 күн бұрын
OBS, não curto usar ferramentas, acredito que mais atrapalha do que ajuda, são tantas também... Seria no manual mesmo.
@bugbountywithmarco
@bugbountywithmarco 22 күн бұрын
en: IMO it’s better to have a minimal knowledge of each vulnerability, and then getting deeper when you are developing your hacking methodology, than studying only 1 vulnerability and start reproducing it anywhere. Each vulnerability has its purpose and there’s applications that one will be more appropriate than other. pt-br: Cara, na minha opinião, mais vale você ter uma base minima de todas as falhas e ir se aprofundando conforme for entendendo sua metodologia de hacking, do que focar apenas em 1 vulnerabilidades e sair tentando aplicar em todo local que vc vê. Cada vulnerabilidade tem seu propósito e local que uma vai ser mais apropriada que a outra
@exploitxx3
@exploitxx3 22 күн бұрын
@@bugbountywithmarco Você escreve direitinho, né? Até isolou o vocativo e o adjunto pra falar comigo.
@exploitxx3
@exploitxx3 22 күн бұрын
Deve ser chat gpt
@bugbountywithmarco
@bugbountywithmarco 22 күн бұрын
not chatgpt at all
@Ranjithkumar.mp4
@Ranjithkumar.mp4 24 күн бұрын
Nice hunter 🪲🔎💥
@bugbountywithmarco
@bugbountywithmarco 23 күн бұрын
thanks!
@SumitYadav-lr5vy
@SumitYadav-lr5vy 25 күн бұрын
After watching this video I think it is not worth it to look for xss zo which vulnerability should i learn apart from improper access control
@bugbountywithmarco
@bugbountywithmarco 25 күн бұрын
my next video will be about some different xss techniques, maybe it can help you
@jackofalltrades200
@jackofalltrades200 27 күн бұрын
😂i remembered my First XSS, i reported it, and after few days someone reported same xss with better exploit,😂 he got paid higher to what i got paid, after years, damn any xss i find, I'll make sure to strip it out untill I'm able to find ATO ,
@bugbountywithmarco
@bugbountywithmarco 27 күн бұрын
that’s the key, reporting a xss with just a alert(1) will be paid way lower than reporting a xss with a 1 click account takeover
@jackofalltrades200
@jackofalltrades200 27 күн бұрын
@@bugbountywithmarco maybe you can do more video sharing your methodologies, that would help lots👍, even though I'm a professional, but I'm Still learning new techniques
@bugbountywithmarco
@bugbountywithmarco 26 күн бұрын
Do you suggest any theme for my next videos?
@tylerharkness7740
@tylerharkness7740 27 күн бұрын
The content of your video is good, but maybe add some visuals to make it more engaging! I’m not sure what but that would improve it a lot
@bugbountywithmarco
@bugbountywithmarco 27 күн бұрын
thanks for the tip. I’m pretty new to content creating, and i’m currently learning how to edit videos. I’ll try it in my next videos
@SumitYadav-lr5vy
@SumitYadav-lr5vy 28 күн бұрын
What types of bugs you hunt for?
@bugbountywithmarco
@bugbountywithmarco 28 күн бұрын
my top 3 most found bugs is: IDOR, Broken Access Control and XSS
@Adarsh.-.
@Adarsh.-. 29 күн бұрын
i can you share that mobile applications APK
@bugbountywithmarco
@bugbountywithmarco 16 күн бұрын
unfortunately I cant
@anandgouda3493
@anandgouda3493 Ай бұрын
Great video!! I am looking for deep finding of hidden parameters , Apart from normal tools like arjun, parmaminer etc.. Can you suggest something on this.
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
i like doing manual searches on this scenario, I try to look into some keywords: bypass, force, admin, etc…
@guilhermeamorim4937
@guilhermeamorim4937 Ай бұрын
Excelente vídeo, não pude deixar de notar que você é brasileiro. Estou começando agora, ainda na busca do meu primeiro bug
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
bons estudos amigo!
@SumitYadav-lr5vy
@SumitYadav-lr5vy Ай бұрын
What future videos are you planning for?
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
i have planned a few: SQL injection in modern web applications How to bypass broken access control And i plan to do a video reading some hacking questions in reddit. Do you suggest anything more?
@starwin1159
@starwin1159 25 күн бұрын
​@@bugbountywithmarco you a my hero
@bugbountywithmarco
@bugbountywithmarco 25 күн бұрын
@@starwin1159 thanks!
@billaGhertz
@billaGhertz Ай бұрын
I already knew you would have another great video since I subscribed to your first one!
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
Nice! Thanks for the support
@panagiotismitkas5526
@panagiotismitkas5526 Ай бұрын
Very nice, i really like your manual approach. So the main goal here is to find hidden endpoints right?
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
Finding hidden endpoint is a good start, but not only that. Some other interesting points to check: xss spots, developers comments, hidden parameters, logical bypasses. Basically, you have almost the complete source code of the application
@exploitxx3
@exploitxx3 21 күн бұрын
@@panagiotismitkas5526 Estava vendo um vídeo do today is new dizendo que se todos usam as mesmas ferramentas, terá mais chances de obter duplicadas, não sei se você concorda.
@josevansantos_
@josevansantos_ Ай бұрын
Nice video bro!
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
Thanks!
@DatBoii2Dizzy
@DatBoii2Dizzy Ай бұрын
Thanks for the video I’m learning so much from this community I can’t wait to give back
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
Thanks! What topic would you like to see next?
@DatBoii2Dizzy
@DatBoii2Dizzy Ай бұрын
@@bugbountywithmarco SQL injections is what I’m on KZbin looking up now
@tpevers1048
@tpevers1048 Ай бұрын
So about doom xss
@PrimordialLegend
@PrimordialLegend Ай бұрын
Thanks, nice work. Keep going!
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
thanks!
@CoveremAll
@CoveremAll Ай бұрын
Recetly found your channel and man you are soo great in bug bounty learning alot from you... I hope I will find my first bug
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
thanks! I hope you will find your first bug either
@shubham_srt
@shubham_srt Ай бұрын
none of your social links are working btw
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
thanks for the tip. I believe this is happening because this channel was just created. You can find the clickable links in my channel page though
@shubham_srt
@shubham_srt Ай бұрын
keep making more videos
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
thanks for the feedback. What topic would you like to see next?
@imperim
@imperim Ай бұрын
hey i have noticied u reported many vulnerabilities in hacker one may i know what kind of those vulnerabilities are? do those are xss? or what
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
my top 3 most reported vulnerabilities is: business logic errors, IDOR, and Improper Access Control
@imperim
@imperim Ай бұрын
@@bugbountywithmarco oh thanks & interesting
@SumitYadav-lr5vy
@SumitYadav-lr5vy Ай бұрын
So as a beginner who just started bug Bounty what types of bugs will you recommend him to hunt for ?
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
@@SumitYadav-lr5vy i would suggest you to start with one of these: IDOR, Business Logic Errors or Broken Authorization. Specially business logic errors, that may not be as popular as the other ones.
@SumitYadav-lr5vy
@SumitYadav-lr5vy Ай бұрын
@@bugbountywithmarco can you recommend me some recourse because business logic error doesn't have good resources?
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
@@SumitYadav-lr5vy actually to find a business logic error vulnerability you need to understand the business of the application you are testing. For example: a dating app allows the user to send messages to another user only when they have a match. But what if the user can actually send messages to a person before the match?
@SumitYadav-lr5vy
@SumitYadav-lr5vy Ай бұрын
@@bugbountywithmarco it is like bac related issues
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
@@SumitYadav-lr5vy a little similar issue
@SumitYadav-lr5vy
@SumitYadav-lr5vy Ай бұрын
Can you start a series in which you explain bugs which a not hunted by many hunter
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
@@SumitYadav-lr5vy of course! I have a scheduled video here about non common vulnerabilities
@poiuymnbvc8339
@poiuymnbvc8339 Ай бұрын
Can you make a series for hunting xss?? Showing how to exploit xss in different ways
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
@@poiuymnbvc8339 that’s something I wanted to do. I have some application that I developed myself that i can use for demonstration
@poiuymnbvc8339
@poiuymnbvc8339 Ай бұрын
Bro great video, i truely love the pace…keep it man..
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
@@poiuymnbvc8339 thanks!
@imperim
@imperim Ай бұрын
Thanks, nice explanation
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
nice to know that! Is there any other vulnerability you would like to see in the perspective of a web software engineer?
@imperim
@imperim Ай бұрын
I am just beginner in this field so just learning from internet Portswigger labs, KZbin, you etc any help appreciate
@bugbountywithmarco
@bugbountywithmarco Ай бұрын
nice to know that, i’ll be posting about other bugs soon
@imperim
@imperim Ай бұрын
Thanks