2023 Path to Hacking Success: Top 3 Bug Bounty Tips

  Рет қаралды 74,850

David Bombal

David Bombal

Күн бұрын

Пікірлер: 112
@davidbombal
@davidbombal Жыл бұрын
He made $100K in 2 months from Bug Bounty! Learn from one of the best! Big thanks to Brilliant for sponsoring this video! Get started with a free 30 day trial and 20% discount: brilliant.org/DavidBombal Ben (Nahamsec) hacks platforms legally and with their permission! He gives us his top 3 Bug Bounty tips for 2023. // Websites recommended by Ben // * hackerone.com * www.bugcrowd.com/ * picoctf.org/ * portswigger.net/web-security * www.intigriti.com/ * www.hacker101.com/ * www.synack.com/ // Ben’s Social // Twitch: www.twitch.tv/nahamsec KZbin: kzbin.info Github: github.com/nahamsec Instagram: instagram.com/nahamsec Twitter: twitter.com/NahamSec Website: nahamsec.com/ // Videos mentioned // Ben's $100K video: kzbin.info/www/bejne/inysdouthMiVnMU Kali Linux Nethunter Android Install in 5 minutes (Rootless): kzbin.info/www/bejne/gamyeKyrfNZjitU // KZbin channels recommended by Ben// @InsiderPHD: www.youtube.com/@InsiderPhD @FarahHawa: www.youtube.com/@FarahHawa @STOKFredrik: www.youtube.com/@STOKfredrik @phd_security: www.youtube.com/@phd_security @_JohnHammond: www.youtube.com/@_JohnHammond @IamJakoby: www.youtube.com/@IamJakoby @HackerSploit: www.youtube.com/@HackerSploit @BugBountyReportsExplained: www.youtube.com/@BugBountyReportsExplained // Recommended Books // Atomic Habits by James Clear: amzn.to/46D8yDE Hacking API’s by Corey J. Ball: amzn.to/3NRTafh Bug Bounty Bootcamp by Vickie Li: amzn.to/3JAPZWS The Web Application Hacker’s Handbook 2 by Daffyd Stuttard and Marcus Pinto: amzn.to/3XvNmLp // MENU // 00:00 - Coming up 01:00 - Brilliant sponsored segment 02:31 - Making $100K in 2 months with bug bounty 04:43 - Top 3 tips for starting with bug bounty 06:15 - Top 3 technical tips for bug bounty 08:10 - "Don't learn to hack, hack to learn" // Consistency is key 11:32 - Top 3 free learning platforms for bug bounty 12:47 - Top 3 bug bounty platforms 15:08 - Vulnerability Disclosure Programs // How VDPs can open doors to opportunities 19:55 - Top 3 recommended KZbin channels 21:27 - Top 3 recommended books 22:17 - Top 3 technologies to understand 23:45 - Helping others // Twitch, KZbin & Twitter 25:35 - Conclusion // MY STUFF // www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
@rxtechandtrading
@rxtechandtrading Жыл бұрын
i made 10million dollars in 1 year forex trading- do you beleive me??? is there any proof that this man actually made 100k in 2 months!!! if so, can u send me a link?? I mean this guy is making some pretty outrageous claims, mabey 20years ago he could of made that, but now, with ALL the compitition out there!! highly doubtfull man!!
@V.WalkingTours
@V.WalkingTours 6 ай бұрын
I am 37 and I want to change the industry that I work! Great information!! Thank you for inviting him!
@CyberGhost-y2p
@CyberGhost-y2p Жыл бұрын
David, I must express my deep appreciation and enjoyment for your videos. I've had the pleasure of watching around 30 to 40 of them, and with each one, I've gained valuable insights and knowledge. Your collaborations with other influential creators have been truly inspiring as you mutually support and uplift one another. I also want to mention that Ben's content is excellent; I hadn't come across him before, but now I'm eager to explore his videos as well. Your dedication and passion in creating these videos fuel my own aspirations, providing me with the inspiration and motivation I need to pursue my goals. I want to extend my heartfelt gratitude for everything you do for all of us. Thank you! You are a legend!
@mattbaker1683
@mattbaker1683 Жыл бұрын
New sub! Thanks both. Circumstances changed for me in December, been looking for a complete change so my lifelong fascination with computers is now becoming the focus with a view to getting into IT, and this is definitely a field of interest. Currently doing the basics, A+ net+ and hopefully sec+ but more with a view to filling in the blanks rather than to get a help desk job. It's a journey not a destination so learning a little every day. Thanks for the great content.
@spongedaddy315
@spongedaddy315 Жыл бұрын
Wow! That was so informative and encouraging. I started on the bug bounty path earlier this year and became quickly overwhelmed and discouraged. This video (David's insightful questions and Ben's thoughtful answers) has prompted me to reset, reassess, and start over with a more positive outlook. Many thanks to both Ben and David -- and yes, I've subscribed to both.
@badxcode
@badxcode Жыл бұрын
I've been following you ever since I got into hacking. I gotta say it, these interviews that you are doing is pretty amazing and nothing like the content you've made before. Always brings something new and interesting to the table. Please, keep it up. Looking forward to seeing more amazing guys soon.
@lucaszecat
@lucaszecat Жыл бұрын
Would you advise any specific cert ?
@rationalbushcraft
@rationalbushcraft Жыл бұрын
Subscribed. I see bug bounty as my retirement plan for extra cash. I have been doing IT and cyber security work since 95 and this may be a good way to keep me sharp and earn a few extra dollars. It will be nice not having to work except when I want to.
@belalal1902
@belalal1902 Жыл бұрын
I felt alot of what he said, especially as a bjj competitor you learn that everything needs consistency and teamwork
@davidbombal
@davidbombal Жыл бұрын
Agreed.
@BERTDELASPEED
@BERTDELASPEED Жыл бұрын
My man 🤜🏾🤛🏾
@muhannedbelaid8849
@muhannedbelaid8849 Жыл бұрын
Been waiting for such interview a lot. Hope u do more videos like this in the future 🙏🙏. Really appreciate what u r doing for the community David❤❤ .
@davidbombal
@davidbombal Жыл бұрын
Thank you! And you're welcome!
@Vlosyros
@Vlosyros Жыл бұрын
Very informative video! Thanks a ton for all the valuable information, looking forward to starting my journey
@kapzvara5732
@kapzvara5732 Жыл бұрын
Great advice thanks for this guys :) Something i am doing is Hack The Box Academy with walkthrough videos if i get stuck and then going to be doing Hack The Box guided mode after the academy as want to change from sysadmin to Cyber Security. I am 42 and was inspired by one gentleman who was 50 and got into hacking :)
@servantofgod3058
@servantofgod3058 Жыл бұрын
I recently turned 17 and about two years ago I made around 8k of off web hacking I get very frustrated when I spend days on target and I don't find anything, that's why I'm switching to web3 and smart contract hacking tbh, at least you're investigating your time with something worth the effort
@orbitmouf
@orbitmouf Жыл бұрын
Where can I find more info on this? I would love to start doing this in addition to learning solidity, any discords or similar bug bounty groups I can look at?
@myboy1625
@myboy1625 Жыл бұрын
Great video... Really motivated me a lot... I would also suggest another guy kinda in the pentesting side that's Sabyasachi. His explanation is awesome. Though he's new to content creation but still has valuable content. 🤗
@PR-wb3ol
@PR-wb3ol Жыл бұрын
Thanks David for the interview. It's informative and gives confidence.
@verlaine_devnet
@verlaine_devnet Жыл бұрын
Insightful 👌 it gives me more energy to learn
@davidbombal
@davidbombal Жыл бұрын
Happy to hear that!
@h5e
@h5e Жыл бұрын
Thats one of the most informative videos ive ever seen
@jsmith85151
@jsmith85151 Жыл бұрын
Bug Bounty program saturation is a thing... And in my opinion it's the most important thing to bear in mind when looking at the profitability of your time in a bounty program.
@TheBenchPressBoss
@TheBenchPressBoss Жыл бұрын
true
@loneranger5928
@loneranger5928 Жыл бұрын
David 👌 its absolutely true that interactive hands on is the best way to learn .personally its my preferred choice. Great content David and Ben 👍👍
@davidbombal
@davidbombal Жыл бұрын
Thank you! Glad you enjoyed the video :)
@rdx8122
@rdx8122 Жыл бұрын
THE FREAKING INTERVIEW / VIDEO / COLLAB WE NEEDED ON THIS CHANNEL !!! LOVE YOU BOTH MENTORS !! 🙏🙏🙏🙏💖💖💖💖🔥🔥🔥🔥❤‍🔥❤‍🔥❤‍🔥❤‍🔥
@davidbombal
@davidbombal Жыл бұрын
Thank you so much! Ben is amazing!
@rdx8122
@rdx8122 Жыл бұрын
@@davidbombal you both are like blessing to me 🙏🙏❤❤
@camelotenglishtuition6394
@camelotenglishtuition6394 Жыл бұрын
A great guest, I love his channel.
@davidbombal
@davidbombal Жыл бұрын
Agreed! Ben posts amazing content!
@camelotenglishtuition6394
@camelotenglishtuition6394 Жыл бұрын
@@davidbombal As do you David :)
@davidbombal
@davidbombal Жыл бұрын
Thank you :)
@timcyb
@timcyb Жыл бұрын
Nice to see ben here. Thank you
@davidbombal
@davidbombal Жыл бұрын
Thank you for watching! Agreed - great to have Ben back :)
@KenKen-bn3dz
@KenKen-bn3dz Жыл бұрын
Thanks David Bombal ❤❤❤
@romanx71
@romanx71 Жыл бұрын
Thank you for the Great content with amazing badass guest! Keep on rocking! 👏🤘🔥🔥
@gamereditor59ner22
@gamereditor59ner22 Жыл бұрын
Interesting topic you presented and keep it up. 😎
@davidbombal
@davidbombal Жыл бұрын
Thank you. You can learn so much from Ben!
@geetchavan9749
@geetchavan9749 Жыл бұрын
Thank u david for this video !!Love from india 🇮🇳
@nosystemissaf3
@nosystemissaf3 Жыл бұрын
the only thing that matters in bug bounty is that how much your are consistent to work on
@omkarm.9340
@omkarm.9340 Жыл бұрын
Awesome ❤❤❤
@davidbombal
@davidbombal Жыл бұрын
Thank you!
@tyrojames9937
@tyrojames9937 Жыл бұрын
GOOD INFO. 😎👍🏾
@funkymonk2254
@funkymonk2254 Жыл бұрын
Thank You David for another informative interview.
@boris55
@boris55 Жыл бұрын
Brilliant interview as always !
@Batool-g4q
@Batool-g4q Жыл бұрын
The best Chanel ever!
@generalreevis1734
@generalreevis1734 Жыл бұрын
Amazing knowledge
@zsu-glz-sql
@zsu-glz-sql Жыл бұрын
Du bon contenu, comme d'habitude continue comme ça.
@davidbombal
@davidbombal Жыл бұрын
Thank you!
@wandering-jew
@wandering-jew Жыл бұрын
The video idea is brilliant
@davidbombal
@davidbombal Жыл бұрын
All credit to Ben :)
@icecoldnoob6719
@icecoldnoob6719 Жыл бұрын
Great content again from mr Bombal. here's a suggestion, maybe DevOps next?
@kallbacks9677
@kallbacks9677 Жыл бұрын
Cool content David as always
@mihai.ciorobita
@mihai.ciorobita Жыл бұрын
Thank you David for bringing value people into your interviews as always
@MFoster392
@MFoster392 Жыл бұрын
I've learned so much from your channel and Ben's you guys are helping others everyday :-)
@DreamlandDuo
@DreamlandDuo Жыл бұрын
#davidbombal ....two legends in one video 💫😇🔥🔥
@my-rules
@my-rules Жыл бұрын
Ty
@davidbombal
@davidbombal Жыл бұрын
You're welcome!
@michaeltully2332
@michaeltully2332 Жыл бұрын
Great content as usual David. Thank you
@iainmaois595
@iainmaois595 Жыл бұрын
Good day sir Mr Davidbombal. He talked about the E1-ELITE behind him is that also a book we could read or probably I could read speaking for myself and if years I'm finding it difficult to get the book Thanks
@ChrisAkpabey-jg2sn
@ChrisAkpabey-jg2sn Жыл бұрын
Thanks David for aspiring we the up coming hackers 🎉❤
@name-n2h
@name-n2h Жыл бұрын
id really love to get into hacking , is there any specific way or concept to start with ? because it is really overwhelming :( im still an engineering student so if there is any way to start learning this (preferably for free ) i would really appreciate any kind of help . thanks for the cool content
@donjohnson7746
@donjohnson7746 Жыл бұрын
Just a weird question but when your doing the bug bounty are you grabbing boot leg to check the software? Asking for a friend
@thatguyidk123
@thatguyidk123 Жыл бұрын
I think my problem is just writing the reports lately and then when I find it and it work out I try to go longer looking for more and I eventually loose what I had found.
@RealCoachingCo
@RealCoachingCo Жыл бұрын
If it ain’t easy, it’s because it’s worth doing.
@lraq.107
@lraq.107 Жыл бұрын
حلقه مميزه❤
@radijaye7435
@radijaye7435 Жыл бұрын
Nice nahamsec here
@davidbombal
@davidbombal Жыл бұрын
Agreed. Great to have Ben back again :)
@armotxa124
@armotxa124 Жыл бұрын
Gone try 👍
@davidbombal
@davidbombal Жыл бұрын
All the best!
@Code_Creator123
@Code_Creator123 Жыл бұрын
Great 👍
@kal-el_21
@kal-el_21 Ай бұрын
Is that too much matter called - "TALENT" !!
@michaelnorwood7722
@michaelnorwood7722 Жыл бұрын
Do you have access to the algorithm or something cause I’m literally learning ethical hacking and I want to do bug bounty
@islem_23
@islem_23 Жыл бұрын
amazing
@davidbombal
@davidbombal Жыл бұрын
Glad you think so! Make sure you subscribe to Ben's KZbin channel :)
@islem_23
@islem_23 Жыл бұрын
@@davidbombal Of course, I'm a subscriber, you're the best I've ever had 🇩🇿Greetings to you from Algeria
@M4R5RoCK
@M4R5RoCK Жыл бұрын
good👍
@davidbombal
@davidbombal Жыл бұрын
Thank you!
@kukuchuchu8340
@kukuchuchu8340 Жыл бұрын
Good
@davidbombal
@davidbombal Жыл бұрын
Thank you!
@omkarm.9340
@omkarm.9340 Жыл бұрын
What is VDS ???
@davidbombal
@davidbombal Жыл бұрын
Vulnerability Disclosure Programs (VDPs) - more detail here: www.hackerone.com/vulnerability-management/bug-bounty-vs-vdp-which-program-right-you
@omkarm.9340
@omkarm.9340 Жыл бұрын
@@davidbombal Thank you so much David sir 🥰
@SNSISNSJISEJSJS
@SNSISNSJISEJSJS Жыл бұрын
DAVID PLS REPLY ME. A lot of us have watched your videos specially the one video that you use WiFi adapter to hack WiFi or to do 4 way handshake. I but I know that a lot of us who are new to hacking or are green hat hackers. We can't find that adapter which supports monitor mode 😩🤔 sooo is there an other way to get the job done and do 4 way handshake using other methods ? Like maybe using python or other tools in Linux or using the powerful module scapy from python ? I'm saying that a lot of us can't get that WiFi adapter which supports monitor and injection modes. So what can we do it we can't literally find the WiFi adapter? Other ways to do the job ? Plsss reply me I'm a big fan and this is very useful information if you can help it would be great;)
@maphadiletsoalo8095
@maphadiletsoalo8095 Жыл бұрын
I know a South African when i hear one😂
@alirezaghulamsakhi6097
@alirezaghulamsakhi6097 Жыл бұрын
PhD security 😊
@Ehtisham_Akhter
@Ehtisham_Akhter Жыл бұрын
Are cyber security jobs in danger due To Ai. Sir supposed you are a beginner in IT in this era would you like to enroll yourself in cyber security field?
@c0smoslive391
@c0smoslive391 Жыл бұрын
Don't get fooled by the apparent intelligence of LLMs (and the hype train), they're cool but limited and we'll still need humans for a long time !
@Ehtisham_Akhter
@Ehtisham_Akhter Жыл бұрын
@@c0smoslive391 so i can choose cyber security without any hesitation?
@taiquangong9912
@taiquangong9912 Жыл бұрын
I have been thinking about bug bounties, but what if I am slow learning and it takes months to get up to speed, should I still pursue web hacking???
@batista98854
@batista98854 Жыл бұрын
would be difficult.
@Poopiesson
@Poopiesson Жыл бұрын
The more you learn, the less you have to to learn. Persistence is key, I've never seen anyone fail at doing what they love to do.
@akashgoswami6698
@akashgoswami6698 Жыл бұрын
Helo sir plz Help me i am buying a leptop but very confused plz suggest a under 35k laptop for programming .
@pwl.lumbama
@pwl.lumbama Жыл бұрын
i found a way to put kali on an sd card
@rami.0092
@rami.0092 Жыл бұрын
❤🎉
@theoceanman8687
@theoceanman8687 Жыл бұрын
Bug bounty is at best a side gig; a scam at worst. The payout depends on the company, and such companies want to pay as little as possible for the bounty.
@rxtechandtrading
@rxtechandtrading Жыл бұрын
i really wonder how much of wat u say is BS , or the truth?? prob a mixture of both
@lraq.107
@lraq.107 Жыл бұрын
Is there an Arabic language? I hope there is an Arabic language in this application
@adhensec
@adhensec Жыл бұрын
Ippsec is my favorite... He is so good in Linux command and I love how he prevesc
@michaelmueller5211
@michaelmueller5211 Жыл бұрын
you forgot networkchuck!
@iainmaois595
@iainmaois595 Жыл бұрын
Or it's probably H1-elite =Hackerone elite !!
@rxtechandtrading
@rxtechandtrading Жыл бұрын
so i did some automated api endpoint enumeration testing (via feroxbuster) and managed to get into the /etc/passwd file on my friends web server he allowed me to hack-BUT - this was the contents of the file: root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin bin:x:2:2:bin:/bin:/usr/sbin/nologin sys:x:3:3:sys:/dev:/usr/sbin/nologin sync:x:4:65534:sync:/bin:/bin/sync games:x:5:60:games:/usr/games:/usr/sbin/nologin man:x:6:12:man:/var/cache/man:/usr/sbin/nologin lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin mail:x:8:8:mail:/var/mail:/usr/sbin/nologin news:x:9:9:news:/var/spool/news:/usr/sbin/nologin uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin does anybody know how i can ACTUALLY get a hold of the password hashes for each user here in the second field after the first : ????????
@yaswanthkumar409
@yaswanthkumar409 Жыл бұрын
You forgot to mention @LiveOverflow #LiveOverflow
@playboicartihey
@playboicartihey Жыл бұрын
NIGGA WE SHOULD GATEKEEP IT
@muhannedbelaid8849
@muhannedbelaid8849 Жыл бұрын
We forget to mention the one of best in web hacking and the most humble one #Rana_Khalil ❤️❤️ @Ranakhalil101
@davidbombal
@davidbombal Жыл бұрын
Thanks for sharing! Rana is amazing!
To Brawl AND BEYOND!
00:51
Brawl Stars
Рет қаралды 17 МЛН
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 700 М.
UFC 310 : Рахмонов VS Мачадо Гэрри
05:00
Setanta Sports UFC
Рет қаралды 1,2 МЛН
Be Invisible Online and Hack like a Ghost
54:09
David Bombal
Рет қаралды 366 М.
DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
32:30
DEFCONConference
Рет қаралды 52 М.
Next Gen Hacker?
43:03
David Bombal
Рет қаралды 236 М.
2024 Roadmap to Master Hacker
54:38
David Bombal
Рет қаралды 198 М.
The Blueprint to Your First $1,000+ Bounty
12:14
NahamSec
Рет қаралды 33 М.
Hacker101 - JavaScript for Hackers (Created by @STOKfredrik)
24:17
2024 Guide: Hacking APIs
20:21
NahamSec
Рет қаралды 24 М.
Top 3 Cybersecurity Career Tips (from Ex-NSA Hacker)
1:07:39
David Bombal
Рет қаралды 105 М.
New methods of recon with OrwaGodfather
42:00
Bugcrowd
Рет қаралды 13 М.
Free Hacking API courses (And how to use AI to help you hack)
53:46
David Bombal
Рет қаралды 121 М.
To Brawl AND BEYOND!
00:51
Brawl Stars
Рет қаралды 17 МЛН