Easy IDOR hunting with Autorize? (GIVEAWAY)

  Рет қаралды 36,792

InsiderPhD

InsiderPhD

Күн бұрын

Пікірлер: 263
@dhruvkandpal9909
@dhruvkandpal9909 3 жыл бұрын
Great video, Katie! Loved it as always. My favourite bug bounty tools are burp suite, all tomnomnom's tools, amass and the ones I developed on my own! (LazyFuzzZ, Wordlist Weaver, Fu-JS) #bbhammer
@gf32768
@gf32768 3 жыл бұрын
Awesome video, as always! Favourite tool - Burp Suite - even if the only features it had were the proxy history and Repeater, it'd still be amazing. ##bbhammer
@Vinayak123-q8p
@Vinayak123-q8p 2 жыл бұрын
amazing, this could be probably one of the biggest information that i have ever been given
@chitraa87
@chitraa87 3 жыл бұрын
Thanks for doing amazing video katie. My fav bug bounty tool is burp ofcourse. I'm looking forward more automation videos like this..#bbhammer
@link-ed
@link-ed 3 жыл бұрын
Thanks for the video! The tool that I use the most is fuff, cause of it's speed and simplicity. Burp is another indispensable tool as well! #bbhammer
@arrheniusangipaelongan8693
@arrheniusangipaelongan8693 3 жыл бұрын
Thanks for all your videos Katie!❤ I got my first bug from your IDOR video. My favorite tool is burp! #bbhammer
@manmohansingh4122
@manmohansingh4122 3 жыл бұрын
Bounty ???
@rami1785
@rami1785 3 жыл бұрын
Thanks for all your videos Katie , My favorite tool is burp #bbhammer .
@wingwing2683
@wingwing2683 2 жыл бұрын
Thanks so much sharing!
@stablewater
@stablewater Жыл бұрын
Thanks for this great knowledge. I am currently learning IDOR and I've been able to use autorize and I got "enforced" in some areas. What next am I to do next. How do I exploit this for bug bounty?
@sangeethaa5101
@sangeethaa5101 3 жыл бұрын
I want more videos explaining bugs with dem websites not just presentations. Thank You, Katie. #bountypls #bbhammer
@brucezhang4967
@brucezhang4967 3 жыл бұрын
Thanks Kate! I want to know more about SSRF and businesss logic.#bountypls And my favourite bug bounty tool is absolutely BurpSuite!!! #bbhammer
@sekmekci
@sekmekci 2 жыл бұрын
Thanks for the video. Information part is starting at 3:49
@sudokom
@sudokom 3 жыл бұрын
My favourite bugbounty tools are FFuF, Dirsearch, and Burpsuite with this extentions such as autorize #bbhammer
@sudokom
@sudokom 3 жыл бұрын
... And also obsidian #bbhammer
@CyberTron08
@CyberTron08 3 жыл бұрын
Thanks for doing so much for the community ❤️ It'll be great to have more videos about DOM based vulnerabilities #bountypls
@saite2560
@saite2560 2 жыл бұрын
nice video i've watched quite a few of em. clear well rehearsed script.. this video actually tries to show us something. well rounded video. i wish more of your videos showed us how to actually do this stuff like this video. you do great on the speaking side of teaching tho, need more hands on tho.
@maapi
@maapi 7 ай бұрын
I'm having an issue with autorize picking up requests that should be out of scope. Anyone else have this issue? This leads to a lot of extra requests to parse through, which really slows me down
@amandabarbosasobrinho5878
@amandabarbosasobrinho5878 3 жыл бұрын
Hey Katie, as always, awesome video! My favorite bug bounty tool is Burp, for sure! #bbhammer
@mohammadisbah1458
@mohammadisbah1458 Жыл бұрын
@Inderderphd Have you find idor vulnerability which leads to privilege escalation? Could you please tell me the scenario.
@InsiderPhD
@InsiderPhD Жыл бұрын
Usually it's permission related - create mutliple accounts with different permission levels, and try and do an admin action as a regular user
@singularityfinale7680
@singularityfinale7680 3 жыл бұрын
You videos are both no bs info and free which is great for broke student like me. Well my favorite tool is Burpsuite #bbhammer And I think I will give Autorize a try.
@webapplicationsecurity1853
@webapplicationsecurity1853 3 жыл бұрын
Thanks for the video, have been using this tool for a while now. This is my favourite tool: Autorize allows to check most of the access Logic tests. #bbhammer
@NafeedAI
@NafeedAI 19 күн бұрын
what is the company says do it without using cookies or tokens of other account?
@InsiderPhD
@InsiderPhD 7 күн бұрын
Account 1 is your victim account 2 is your attacker, you can use the attackers cookies to affect the victim, you don’t need account 1s/victims cookies
@TheConstantLearnerGuy
@TheConstantLearnerGuy 3 жыл бұрын
Started learning following your recon videos. My go to tool for now is Burpsuite community edition. #bbhammer
@gk_eth
@gk_eth 3 жыл бұрын
Mostly there r auth bearer token for APIs which also needs to be add in cookies section?
@meletismichael2495
@meletismichael2495 3 жыл бұрын
You are precious for the community! pls go more in depth on chaining vulnerabilities! #bountypls
@Death_User666
@Death_User666 Жыл бұрын
You are my favorite bug bounty channel
@syedbukhari4761
@syedbukhari4761 3 жыл бұрын
Great video Katie, my favourite tool is Amass & Wireshark; would love to see more videos on Business logic flaws & XXE flaws. #bountypls
@svrajput14
@svrajput14 Жыл бұрын
Really nice tip on how to use tool effectively !!
@ndmath
@ndmath 3 жыл бұрын
Thank you Katie. I'd love to know more about Burp. #bountypls
@ksr608
@ksr608 3 жыл бұрын
Thank you for all your videos! My favourite tool is amass and burpsuite. #bbhammer. It'll be good to see more videos on subdomain takeover with an example. #bountypls
@vikasrushi3714
@vikasrushi3714 3 жыл бұрын
Thanks :) my favourite bug bounty tool are Amass and FFUF #bbhammer
@vanquisherstraveltube
@vanquisherstraveltube 3 жыл бұрын
You are really a great teacher. I am following your videos and learning a lot. Thank you so much! *Burp* is my favorite tool #bbhammer
@roxneil1974
@roxneil1974 2 жыл бұрын
katie, i'm new to bug hunter, i'm still practicing about the web security system, i have joined in ingriti but i don't know what i can and can't do when looking for bugs, can you give a little direction and tips on how to work in intigriti please,,
@DieTeewurst
@DieTeewurst 3 жыл бұрын
Thank you for your great Videos! My favorite Bug bount tool is burp for sure! So much functionality in one tool! #bbhammer
@0xff1337
@0xff1337 3 жыл бұрын
why you're so late katie. i was waiting for this video for so long
@sadabesher2886
@sadabesher2886 2 жыл бұрын
Burp and ffuf is my favorite tool
@amitabhgupta21
@amitabhgupta21 3 жыл бұрын
Started following you Katie and I am blown by the content u and other fellow u tubers are providing by the way my favourite BB tools are - Burp Pro,Rustscan,amass and nuclei #Bbhammer
@ainter216
@ainter216 3 жыл бұрын
Thank you very much for the video! My favourite toos is Burp Suite, it is so powerful and you can do so many things. #bbhammer
@mohammedsaneem4179
@mohammedsaneem4179 3 жыл бұрын
Great video as always. Would love to see videos based on chaining of bugs #bountypls
@VincentOldMark
@VincentOldMark 3 жыл бұрын
My favourite tool is of course burp suite #bbhammer You are great Katie!
@Snoopydogsz
@Snoopydogsz 3 жыл бұрын
My favourite bug bounty tool is ffuf combined with burp. I can bypass the speed limit of Intruder during fuzzing using -replay-proxy in ffuf which gives me the benifit of higher fuzzing speeds of ffuf and all the packets are captured in burp proxy too due to -replay-proxy flag set in ffuf. #bbhammer
@gauravdeore9477
@gauravdeore9477 3 жыл бұрын
#bbhammer According to me burpsuite repeater is the best tool for hacking. We can perform any attack with it.
@RahulKumar-vy4lu
@RahulKumar-vy4lu 3 жыл бұрын
Great video as always. I would love to have more videos about XSS & chaining of bugs. #bountypls
@abhishek-praveen
@abhishek-praveen 3 жыл бұрын
I would love to see more videos on recon methadology for beginners . #bountypls
@jarvis9092
@jarvis9092 3 жыл бұрын
Please never stop creating content like these😍..It would be helpfull if you would increase your volume as i felt the audio is lower than other youtube videos..My favourite tool is BurpSuite #bbhammer
@saminbinhumayun858
@saminbinhumayun858 Жыл бұрын
do we get Cookies from the admin account or the low-privileged account?
@InsiderPhD
@InsiderPhD Жыл бұрын
Low privileged account always! Your low privileged is always your attacker
@iamkaustubh
@iamkaustubh 3 жыл бұрын
Wowww Thanks katie 🔥🔥🔥🔥it really encourages people more thanks for video
@asantoshkumarachary2692
@asantoshkumarachary2692 Жыл бұрын
Thanks for this video Katie
@champagnepete3386
@champagnepete3386 3 жыл бұрын
Great video, good resource!!
@sien1337
@sien1337 3 жыл бұрын
my favorite bb tool is Burp, you can just do so much with it! #bbhammer
@SergeantDaynes
@SergeantDaynes 3 жыл бұрын
Awesome video as usual. As for the types of bugs/hacking I want to learn about…SSRFs, broken access controls, business logic, and APIs! #bountypls
@andymarty80
@andymarty80 3 жыл бұрын
I'd like to see videos on Anti-CSRF bypass, 2FA/MFA bypass or prediction.
@papajohn2821
@papajohn2821 3 жыл бұрын
Mobile application security is what I am practicing for a month now. And videos on that topic will be great to learn from. #bountypls
@deepeshrane8412
@deepeshrane8412 3 жыл бұрын
Awesome video, I love to use Amass and burp suite!! #bbhammer
@IrfanAli-vp5mh
@IrfanAli-vp5mh 3 жыл бұрын
Next video idea suggestion: Burp autorepeater
@ronny_xavier
@ronny_xavier 3 жыл бұрын
Thanks as always Katie. My fav tool is Burp definitely. #bbhammer
@DevilAlpacca
@DevilAlpacca 3 жыл бұрын
Awesome, will definitely use the burp addon. Fav tool #bbhammer #bountypls
@gogreensongesters1800
@gogreensongesters1800 3 жыл бұрын
Thank you Katie for this amazing video. My favourite bug bounty tool is Burpsuite. #bbhammer
@morphsec
@morphsec 3 жыл бұрын
Subdomain takeovers would be nice, saw a lot of good reports but never seemed to fully understand them. #bountypls Burp and Amass is the bread and butter for me. #bbhammer
@th3r5n
@th3r5n 3 жыл бұрын
I like to see more vedios on business logic bugs , like taking a public program and understanding the business logic of the functionalities.#bbhammer #bountypls
@darshannn10
@darshannn10 3 жыл бұрын
Fav bug bounty tools - Burp, amass, nuclei, ffuf #bbhammer
@subhadipnag6028
@subhadipnag6028 3 жыл бұрын
Your video is really awesome :) Always love for Burp Suite tool for damn sure !! #bbhammer
@TechRideGamer
@TechRideGamer 3 жыл бұрын
Thanks for this one its more than awesome. By favourite tool is Amass, fuff and in extensions autorepeater & Param Miner this are lit. #bbhammer
@tomj1883
@tomj1883 3 жыл бұрын
Thanks for the videos!!! My favorite tool is burp for sure #bbhammer
@Silly_lilly926
@Silly_lilly926 3 жыл бұрын
Thanks Kate ❤️ for this giveaway I'm so inspired by you and Aditi Singh and my favourite tool is FFUF love data exposed ❤️ #bbhammer
@kbsavage77
@kbsavage77 3 жыл бұрын
Welcome back! I'd love to learn more about SSRF #bountypls
@TheConstantLearnerGuy
@TheConstantLearnerGuy 3 жыл бұрын
Thank you for the video
@gonzalogermano2312
@gonzalogermano2312 3 жыл бұрын
Thanks Katie my favorite tools is burpsuite #bbhammer
@aechapark4299
@aechapark4299 2 жыл бұрын
Is it ok to use burp suite community edition in real bug bounty hunting? I can't afford to buy professional one. ;)
@kovanbakr
@kovanbakr 3 жыл бұрын
thankyou, My favourite bug bounty tool is Burpsuite. #bbhammer
@Diddy81
@Diddy81 3 жыл бұрын
My favorite BugBounty tool has to be Burp Suite #bbhammer
@pr0xy_
@pr0xy_ 3 жыл бұрын
my favorite bug bounty tools are amass and burp suite. #bbhammer
@don-ce8ig
@don-ce8ig 3 жыл бұрын
Thanks for making content! My favourite bug bounty tool is burpsuite #bbhammer
@kavishshah1988
@kavishshah1988 3 жыл бұрын
Have only used Burp suite till now so I guess that's my favourite tool as of yet #bbhammer
@shameeluddin3563
@shameeluddin3563 2 жыл бұрын
Just found your channel searching for cybersec stuff. My favorite tool so far is burp. #bbhammer
@eraedith696
@eraedith696 3 жыл бұрын
Fav tool is Burpsuite because it has some automation and also manual testing which is good and it's also beginner friendly tool and many more to learn.... Thank you❤ #bbhammer
@tXambe
@tXambe 3 жыл бұрын
Thanks very much for your videos and my favourite tool is burpsuite #bbhammer
@yaroslav8717
@yaroslav8717 11 ай бұрын
Firstly you said katie katie is a victim's account, and then you said it is the attacker's account...
@faique2995
@faique2995 3 жыл бұрын
Thank you for holding my hands and taking me to this level in cyber security, Be healthy and happy😁 #bountypls
@ambsambs2973
@ambsambs2973 3 жыл бұрын
It'll be good if we get videos on web cache related vulnerabilities also once again thanks for making good contents for the community! #bountypls
@italoamaya8230
@italoamaya8230 3 жыл бұрын
thank you so much
@jovensqueprosperam
@jovensqueprosperam 3 жыл бұрын
Thanks for this channel
@matthewhowes6270
@matthewhowes6270 2 жыл бұрын
Burp,Ffuf, Nuclei, Aquatone and Nmap #betterlatethannever #bbhammer
@LeonVQZ
@LeonVQZ 3 жыл бұрын
I would like to know more about CSRF, I haven't been able to understand the impact or what it can lead to if the application is vulnerable to CSRF #bountypls
@pushpinderkaur6570
@pushpinderkaur6570 3 жыл бұрын
Thank you for this video. I would love to know more about cloud security esp AWS. #bountypls
@adamkimbro
@adamkimbro 3 жыл бұрын
#bbhammer My favorite tool burp. Thanks for your videos!!!
@shamim_12
@shamim_12 3 жыл бұрын
Well my favorites are FFUF and Dirsearch #bbhammer
@sandiyochristan
@sandiyochristan 2 жыл бұрын
Thanks Kate ❤ for this giveaway I'm so inspired by you #bountypls #bbhammer
@0xrohit54
@0xrohit54 3 жыл бұрын
I would like to know about GraphQL injection #bountypls
@tajsec
@tajsec 3 жыл бұрын
my favorite tool is burp suite, nmap :)) thanks for great contents #bbhammer
@tommydave2908
@tommydave2908 3 жыл бұрын
I'd like to learn more about SSRFs, and maybe web cache poisoning, sounds cool. #bountypls
@sudarshsaraswathula1401
@sudarshsaraswathula1401 3 жыл бұрын
Thanks a lot for the vid. My favourite tool is ffuf #bbhammer
@fatihburaktoprak769
@fatihburaktoprak769 2 жыл бұрын
My favorite is always Burp Suite! #bbhammer
@user-ov2ll4vc7j
@user-ov2ll4vc7j 3 жыл бұрын
Katie thanks for the video. I would like to learn more about hacking APIs. #bbhammer
@mrpvr
@mrpvr 3 жыл бұрын
I wanted to know more about XXE and SSRF Bugs #bountypls #bbhammer
@vivekkashyap7293
@vivekkashyap7293 3 жыл бұрын
My comment is keep deleting automatically??😭😭? Why #bbhammer stored css that was awesome moment and in September 2021 i got another credentials in API url by your api playlist Then in December 2021 i got IDOR by autorize 😅❤️❤️ (also i would like to see more idor,api etc videos some real live testing on idor,api also videos on career making in hacking how to easily get in bugcrowd,hackerone, integrity etc ) but similarly in all of these is they are not high bounties I'm trying to get good skills , so much thank you for this give away hanks to you and all bug Bounty mentors for sharing their skills with youngsters #bbhammer 😅
@Malware01
@Malware01 3 жыл бұрын
Hey, my favourite bb tools are burpsuite, sql map #bbhammer
@bonenaing333
@bonenaing333 2 жыл бұрын
Thanks for sharing. Burpsuite of course i am just the beginner #bbhammer
@mooreprr8067
@mooreprr8067 2 жыл бұрын
Favorite tools are Burp, Amass, All of Tomnomnom's Tools ,Cariddi #bbhammer
@edoardottt
@edoardottt 3 жыл бұрын
Burpsuite, nuclei, Cariddi, Gau, gxss, ffuf and google dorks #bbhammer
@RahulKumar-vy4lu
@RahulKumar-vy4lu 3 жыл бұрын
My go-to was always Burpsuite. #bbhammer
How to Stop Learning and Start Hacking!
17:13
InsiderPhD
Рет қаралды 31 М.
How I made 1k in a day with IDORs! (10 Tips!)
23:09
InsiderPhD
Рет қаралды 55 М.
24 Часа в БОУЛИНГЕ !
27:03
A4
Рет қаралды 7 МЛН
БОЙКАЛАР| bayGUYS | 27 шығарылым
28:49
bayGUYS
Рет қаралды 1,1 МЛН
I'VE MADE A CUTE FLYING LOLLIPOP FOR MY KID #SHORTS
0:48
A Plus School
Рет қаралды 20 МЛН
Find hidden input using Param Miner BurpSuite Extension
13:20
thehackerish
Рет қаралды 32 М.
Don't test for IDOR's manually, Autorize is so much faster!
6:26
This Bug Got Me A $30,000 Bounty
12:41
NahamSec
Рет қаралды 20 М.
Why Your IDORs Get NA’d, Cookies Explained
20:09
InsiderPhD
Рет қаралды 18 М.
"Easiest" Beginner Bugs? Access Control and IDORs
31:46
InsiderPhD
Рет қаралды 23 М.
Scammers PANIC After I Hack Their Live CCTV Cameras!
23:20
NanoBaiter
Рет қаралды 26 МЛН
I used AI to hack this website...
23:23
Tech Raj
Рет қаралды 152 М.
24 Часа в БОУЛИНГЕ !
27:03
A4
Рет қаралды 7 МЛН