$5,000 YouTube IDOR - Bug Bounty Reports Explained

  Рет қаралды 12,235

Bug Bounty Reports Explained

Bug Bounty Reports Explained

Күн бұрын

📧 Subscribe to BBRE Premium: bbre.dev/premium
✉️ Sign up for the mailing list: bbre.dev/nl
📣 Follow me on Twitter: bbre.dev/tw
This video is about IDOR vulnerability in KZbin that existed in integration of KZbin with Google Ads. It existed in integration with Google Ads platform. The vulnerability was reported to Google VRP bug bounty program.
🖥 Get $100 in credits for Digital Ocean 🖥
m.do.co/c/cc70...
Report:
bugs.xdavidhu....
Reporter's twitter:
/ xdavidhu
Follow me on twitter:
/ gregxsunday
Timestamps:
00:00 Intro
00:22 Hunting for IDORs on KZbin
01:27 Google Ads
02:47 Sign up for the mailing list
03:17 The exploit
#BugBounty #IDOR #GoogleVRP

Пікірлер
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
Welcome to the comment section! First, thanks for watching! Second, make sure you are subscribed if you liked the video! kzbin.info Follow me on twitter: twitter.com/gregxsunday ✉️ Sign up for the mailing list ✉️ mailing.bugbountyexplained.com/ ☕️ Support my channel ☕️ www.buymeacoffee.com/bountyexplained 🖥 Get $100 in credits for Digital Ocean 🖥 m.do.co/c/cc700f81d215
@gigihadijaya5102
@gigihadijaya5102 3 жыл бұрын
thank"s for video
@ayodub
@ayodub 3 жыл бұрын
This format of video is perfect
@amerjarrar1063
@amerjarrar1063 3 жыл бұрын
Great videos man! keep up the good work!
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
Thank you Amer 😉
@imshaiknasir
@imshaiknasir 3 жыл бұрын
Wow amazing explanation. And hats off to the researcher..
@threeMetreJim
@threeMetreJim 3 жыл бұрын
That's a weird one. I've never seen an ad that was private, they always seem to be unlisted so they don't appear in the channel feed. It's sometimes fun to post comments on their page if they've left comments enabled - like for the one with the dog called rumpus, or some bugus scam product (but I had comments deleted on those 😁 )
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
Hahah funny😂 Actually, the ad must be public on unlisted. It was my false assumption that it can be private as well 😕
@threeMetreJim
@threeMetreJim 3 жыл бұрын
@@BugBountyReportsExplained The ads do tell you how many views and when posted, so a very minor information leak. You could maybe work out upper/lower bounds of an advertising budget.
@dhyeychoksi5178
@dhyeychoksi5178 3 жыл бұрын
Nice work dude. Have been following your channel since a long time. Great work
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
Thanks dude for being a loyal viewer. I hope you will be with me for a lot more 😏
@AniltonNeto
@AniltonNeto 3 жыл бұрын
Enjoy :D 0:20
@user3549
@user3549 7 ай бұрын
This was worth more than 5k
@chintangajera1537
@chintangajera1537 3 жыл бұрын
Great explaination keep going man!!!
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
Thanks! I appreciate it!!
@HackerSumitJi
@HackerSumitJi 3 жыл бұрын
Love you bro
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
Thank you Sumit!
@cyberpirate007
@cyberpirate007 3 жыл бұрын
Wow!! Dope find
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
It is! You can also watch another video about hacking Google by the same David Shutz: kzbin.info/www/bejne/o5q0p6KseZiWZpY and the podcast we recorded together: kzbin.info/www/bejne/jmeWk4OwbNenepY
@mohamadtaha9091
@mohamadtaha9091 3 жыл бұрын
Where are you from
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
form Poland
@ANILKUMAR-cc3lb
@ANILKUMAR-cc3lb 3 жыл бұрын
@@BugBountyReportsExplained form🤔
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
@@ANILKUMAR-cc3lb haha didn't notice😂🙄
@mohamadtaha9091
@mohamadtaha9091 3 жыл бұрын
@@BugBountyReportsExplained well done
@ANILKUMAR-cc3lb
@ANILKUMAR-cc3lb 3 жыл бұрын
@@BugBountyReportsExplained 😄😄😄
@eonraider
@eonraider 3 жыл бұрын
Would you be willing to implement an RSS feed for the site? It's better than a mailing list.
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
Sure! First, I will create a site (this is just a landing page generated by mailing service). But I will make sure to add RSS feed then.
@eonraider
@eonraider 3 жыл бұрын
@@BugBountyReportsExplained Awesome, man. Keep up the great work.
@BugBountyReportsExplained
@BugBountyReportsExplained 3 жыл бұрын
Thank you mate!
@oklatasha3359
@oklatasha3359 3 жыл бұрын
Luckily I found dailywebEARNCOM Thank you for helping me with my mounting medical expenses.
@jerrypeckham5171
@jerrypeckham5171 3 жыл бұрын
ill give it a try cuz i need money
@AjayKumar-xl4jc
@AjayKumar-xl4jc 3 жыл бұрын
Nice
@mazzukmachu
@mazzukmachu 3 жыл бұрын
🤤🤤
IDOR - how to predict an identifier? Bug bounty case study
23:55
Bug Bounty Reports Explained
Рет қаралды 17 М.
«Жат бауыр» телехикаясы І 30 - бөлім | Соңғы бөлім
52:59
Qazaqstan TV / Қазақстан Ұлттық Арнасы
Рет қаралды 340 М.
ССЫЛКА НА ИГРУ В КОММЕНТАХ #shorts
0:36
Паша Осадчий
Рет қаралды 8 МЛН
UFC 287 : Перейра VS Адесанья 2
6:02
Setanta Sports UFC
Рет қаралды 486 М.
$3,133.70 XSS in golang's net/html library - My first Google bug bounty
6:10
Bug Bounty Reports Explained
Рет қаралды 10 М.
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,6 МЛН
#NahamCon2024: GraphQL is the New PHP | @0xlupin
26:17
NahamSec
Рет қаралды 9 М.
Bug Hunting is easy if you KNOW this
8:23
Bug Hunter Labs
Рет қаралды 43 М.
"Easiest" Beginner Bugs? Access Control and IDORs
31:46
InsiderPhD
Рет қаралды 24 М.