Escalating Your Bugs With GDPR Impact

  Рет қаралды 2,800

InsiderPhD

InsiderPhD

Күн бұрын

Пікірлер: 39
@faique2995
@faique2995 2 жыл бұрын
HTTP request smuggling bounce off my head #misunderstoodNA
@shotdregghun8374
@shotdregghun8374 2 жыл бұрын
Self XSS is a bug I'd say is misunderstood. If it's combined with registration CSRF, then it suddenly becomes true XSS via CSRF. Never say self XSS is useless, combine it with other bugs to create attack chains. #misunderstoodNA #bountypls
@SEX_ON_DRUGS
@SEX_ON_DRUGS 2 жыл бұрын
nice video i havent seen a bug bounty video on this topic before
@samh5247
@samh5247 2 жыл бұрын
IDOR - ppl sometimes don’t get the difference between public and private data. #misunderstoodNA
@ordavid3703
@ordavid3703 2 жыл бұрын
One of the misunderstood subjects is How to avoid vulnerabilities by doing secure code reviews, In addition CSRF Subject and how to recognize and use #misunderstoodNA
@gk_eth
@gk_eth 2 жыл бұрын
I guess S3 bucket takeover is misunderstood since some cloud enumeration tools throws 404 buckets which can be created by anyone shows less or null impact.. #misunderstoodNA
@RX_100.0
@RX_100.0 2 жыл бұрын
Rxss and rate limiting, Subdomain take over issues were most misunderstood #misundeestoodNA #bountypls
@devangsolanki4622
@devangsolanki4622 2 жыл бұрын
Most misunderstood bug would be cros misconfiguration #missunderstoodNA
@mahtabmehek
@mahtabmehek 2 жыл бұрын
Low hanging fruits aren't prioritised enough, can you please touch on this topic? #misunderstoodNA #bountypls
@SaiKrishna-eo5tf
@SaiKrishna-eo5tf 2 жыл бұрын
Race condition and CORS misconfiguration #misunderstoodNA
@Kamikaze00ish
@Kamikaze00ish 2 жыл бұрын
Looking forward to seeing more videos from you! XSS doesn't make sense to me because I'm still so new and learning everything. #misunderstoodNA #bountypls
@deepakparmar6863
@deepakparmar6863 2 жыл бұрын
Open Redirect is mostly misunderstood #misunderstoodNA
@mayank-ir7tm
@mayank-ir7tm 2 жыл бұрын
Sensitive information disclosure #misunderstoodNA
@manmoon7396
@manmoon7396 2 жыл бұрын
Application level DOS #misunderstoodNA #bountypls
@kasperskyhackfi
@kasperskyhackfi 2 жыл бұрын
CORS, Web cache poisoning #misunderstoodNA
@Diddy81
@Diddy81 2 жыл бұрын
prototype pollution #misunderstoodNA
@rami3sam
@rami3sam 2 жыл бұрын
Sensitive information disclosure especially if it's done by verbose error messages if they provide rich information about something very useful, when devising your exploits that could be the difference between failed and successful exploitation #misunderstoodNA
@rami3sam
@rami3sam 2 жыл бұрын
sometimes the person who will triage your report wouldn't understand how disclosing that information is dangerous and would only see cryptic messages that doesn't have any meaning
@alexandart2130
@alexandart2130 2 жыл бұрын
Please talk about JWT token #bountypls
@mosaa.mohmed8478
@mosaa.mohmed8478 2 жыл бұрын
web cache poisoning #misunderstoodNA
@marvelmaniac_
@marvelmaniac_ 2 жыл бұрын
rate limiting issues #misunderstoodNA
@bignonbaba5696
@bignonbaba5696 2 жыл бұрын
account takeover #misunderstoodNA
@breakingthroughinside
@breakingthroughinside 2 жыл бұрын
DOM based XSS #misunderstoodNA
@JayCyberSecurity
@JayCyberSecurity 2 жыл бұрын
i bet it's CSRF #misunderstoodNA
@Sumit-yadav806
@Sumit-yadav806 2 жыл бұрын
Dom basses xss #misunderstoodNA
@rohanrajgupta3614
@rohanrajgupta3614 2 жыл бұрын
Dom xss #misunderstoodNA
@liverecon
@liverecon 2 жыл бұрын
one demo your day a day
@dhruvikagarwal6544
@dhruvikagarwal6544 2 жыл бұрын
One of the most misunderstood bug is Weak Input Validation. If an application is accepting special characters like , ? then that is not a weak input validation, unless you have a proof that the same is stored/reflected without any encoding #misunderstoodNA
@manishneupane6070
@manishneupane6070 2 жыл бұрын
👏👏
@behnamdadashi9059
@behnamdadashi9059 2 жыл бұрын
I Would like to learn more about Mass Hunting, also I think HTTP smuggling is one of the most misunderstood bugs. #misunderstoodNA #bountypls
@AsifIqbal-qg8lp
@AsifIqbal-qg8lp 2 жыл бұрын
I think sometimes some bugs like No Rate Limiting in some endpoints misunderstood because clients(not all) think that it will not going to affect their application however it can affect them badly. Like if there is no proper rate limiting set in a forget password endpoint where user gets mail for reset password link then user can be easily flooded with mail which makes a bad impact for that organization. #misunderstoodNA
@Xplo8E
@Xplo8E 2 жыл бұрын
#bountypls i want to know more about graphql Pentesting and Parameter pollution
@shreyapohekar8418
@shreyapohekar8418 2 жыл бұрын
One of the misunderstood bug is subdomain takeover. Seeing those error messages corresponding to different services doesn't really mean that it is a subdomain takeover. People need to do a full poc to prove it. #misunderstoodNA
@Pr4547h
@Pr4547h 2 жыл бұрын
#misunderstoodNA XXE
@pushpinderkaur6570
@pushpinderkaur6570 2 жыл бұрын
Would love to learn cloud security, esp AWS. #bountypls
@zenkoyuri
@zenkoyuri 2 жыл бұрын
Would love to learn more about cloud security #bountypls
@samratgupta8487
@samratgupta8487 2 жыл бұрын
Great One..
@mrblackhat8088
@mrblackhat8088 2 жыл бұрын
1st
Hacking when all the bugs have been found?
18:53
InsiderPhD
Рет қаралды 6 М.
"Easiest" Beginner Bugs? Access Control and IDORs
31:46
InsiderPhD
Рет қаралды 20 М.
Worst flight ever
00:55
Adam W
Рет қаралды 29 МЛН
Inside Out 2: ENVY & DISGUST STOLE JOY's DRINKS!!
00:32
AnythingAlexia
Рет қаралды 12 МЛН
Стойкость Фёдора поразила всех!
00:58
МИНУС БАЛЛ
Рет қаралды 4,5 МЛН
Крутой фокус + секрет! #shorts
00:10
Роман Magic
Рет қаралды 23 МЛН
Which XSS payloads get the biggest bounties? - Case study of 174 reports
28:40
Bug Bounty Reports Explained
Рет қаралды 26 М.
GDPR explained: How the new data protection act could change your life
5:40
When you Accidentally Compromise every CPU on Earth
15:59
Daniel Boctor
Рет қаралды 830 М.
Giving Yourself the Best Opportunity to Find a Bug
36:45
InsiderPhD
Рет қаралды 6 М.
Approaching Large Scope Targets Without Feeling Overwhelmed
20:13
Here are 3 bugs I’ve Found with Recon (and how I hacked them)
16:28
What Can an Attacker Actually Do With a Bug Anyway?
22:46
InsiderPhD
Рет қаралды 1,5 М.
E-commerce Flaws and $500-1000 Bounties
15:53
InsiderPhD
Рет қаралды 4,5 М.
Worst flight ever
00:55
Adam W
Рет қаралды 29 МЛН