APPROACHING AN E-COMMERCE TARGET!

  Рет қаралды 19,988

Farah Hawa

Farah Hawa

Күн бұрын

Пікірлер: 175
@vikaransecurity9158
@vikaransecurity9158 4 жыл бұрын
This was one of the most informative videos on bug bounties that I have seen, please upload more content like this
@johnsnow1062
@johnsnow1062 4 жыл бұрын
Best Wishes for the future farah. Good presentation . Hoping to watch more quality vids in the future.
@historichacker2013
@historichacker2013 4 жыл бұрын
i generally dont comment but i have to say your videos very well explained ! awesome keep up the good work
@simranpreetsingh5502
@simranpreetsingh5502 4 жыл бұрын
Amazing content , looking forward to learning more of it ! :)
@carlosmonterrosa4617
@carlosmonterrosa4617 4 жыл бұрын
Very Good video. Really appreciate your willingness to share. Keep it up!
@afifmalghani755
@afifmalghani755 4 жыл бұрын
Both your videos are extremely beginner friendly. It's very difficult to find such content. Thank you for this. Would love to see more.
@0xsunil
@0xsunil 4 жыл бұрын
Much appreciated the effort in editing! Eagerly waiting for part 2!
@therollingambit5222
@therollingambit5222 4 жыл бұрын
Loving the concept behind your videos. Please keep uploading haha. Cheers frm singapore!
@technicalilm8999
@technicalilm8999 4 жыл бұрын
What makes this video different from others is that you use more recent real world examples. Very informative.
@TheWrkCo
@TheWrkCo 4 жыл бұрын
Very informative and easy to understand... Looking forward to more of these videos.. Keep up the good work and Thank You for these tips..
@umessr8456
@umessr8456 4 жыл бұрын
It's clear that your are putting in alot of work in this video's. Keep up 👍
@kamar1380
@kamar1380 4 жыл бұрын
Thnks for this awesome video. I can't wait for your next video....👍
@Hharshit01
@Hharshit01 3 жыл бұрын
Thanks. It's so easy to understand
@M10GAMING-j8y
@M10GAMING-j8y 4 жыл бұрын
I have checked all of your videos and all are best thankyou
@M10GAMING-j8y
@M10GAMING-j8y 4 жыл бұрын
hey can u make a video on tomnomnom tools and also on @1ndian133t gf-pattern tool please
@johnhammond2813
@johnhammond2813 4 жыл бұрын
Thank you. The video was so informative and your way of explanation is too good, please do part2 on ecommerce testing and also keep posting these kind of videos. And also if possible explain how to start with hackerone or bugcrowd bounty programs with the process which will be helpful for beginners.
@utkarshagrawal6060
@utkarshagrawal6060 4 жыл бұрын
Very informative. Good work.
@TheOriginalAryan
@TheOriginalAryan 4 жыл бұрын
A very well articulated video covering the basics and theory. would love more videos covering each point in greater detail. Also, if you can share your background and how you got into bug bounty/infosec other than what you have already covered in your first video, it would inspire other people. Keep up this excellent initiative
@ishanshojha
@ishanshojha 4 жыл бұрын
The tip about changing currency also applies on value of money . Paypal doesn't check that too.
@AlphaCybersecurity
@AlphaCybersecurity 4 жыл бұрын
Very informative. Well Done! Thank You
@hacxpro6206
@hacxpro6206 4 жыл бұрын
Amazing video. Lots of love. Hoping to see more good contents like this.
@cjhackerz
@cjhackerz 4 жыл бұрын
Awesome video, something like series on owasp top 10 vulnerabilities will help lots of new people in infosec.
@FarahHawa
@FarahHawa 4 жыл бұрын
Great idea!
@RX_100.0
@RX_100.0 4 жыл бұрын
awsome content, waiting for part-2 mam
@yukeshkumar9536
@yukeshkumar9536 4 жыл бұрын
Love this video and you !
@inderjeetsingh1340
@inderjeetsingh1340 4 жыл бұрын
Plss make second part... and make similar videos on how you attack today's sites
@malwarecopter4440
@malwarecopter4440 4 жыл бұрын
Nice farah try uploading basic tutorials on bug hunting like finding the idor's in wild, basic xss and so on 👍👍👍
@FarahHawa
@FarahHawa 4 жыл бұрын
Thank you! There are TONS of videos and blogs on those topics. You might want to check out Nahamsec or Stok's channel, you'll find a lot of those.
@BasedCrusades
@BasedCrusades 4 жыл бұрын
@@FarahHawa STOK is fantastic! May I also recommend Hackersploit as well? I play at least one to two videos of HSploit a day during my one hour drive to work.
@itsactuallyaditya
@itsactuallyaditya 4 жыл бұрын
great video so much informative , Are you from India?
@harshalchaudhari7301
@harshalchaudhari7301 4 жыл бұрын
Amazing as last one! Please do the part-II
@akshanshshriwatri8060
@akshanshshriwatri8060 4 жыл бұрын
Content 💯 . Thankyou soo much for this 💕
@ruheenaqureshi5339
@ruheenaqureshi5339 3 жыл бұрын
Keep going amazing videos, 👍
@hiteshpant9868
@hiteshpant9868 4 жыл бұрын
🙏Please tell a practical roadmap for beginners in next video with resources... Thank you. 😊
@slbpriank91
@slbpriank91 4 жыл бұрын
Good video! Keep up the good work!
@himanshushah9471
@himanshushah9471 4 жыл бұрын
Please make video on beginner guide to Cybersecurity/ethical hacking how to start career In cybersecurity like books, courses,programming languages,Top Certification, all stuff, etc. Specially for students/fresh Graduate in CS and IT
@margaritahernandez435
@margaritahernandez435 4 жыл бұрын
Or like me who will love to learn it
@markgacoka9704
@markgacoka9704 4 жыл бұрын
Heyyy, I don't think CardiB has a balance of $0 lol. (3:45) I like your videos btw. Really well explained!
@sumitkumarsingh35
@sumitkumarsingh35 4 жыл бұрын
Farah do make a video on how to get started with cybersecurity career . From learning to getting a job. Atleast how to start learning. I am so much confused. Help me !
@masti2point0
@masti2point0 3 жыл бұрын
Thanku mam for helping me in such a manner😇😊
@Manojkumar__
@Manojkumar__ 3 жыл бұрын
Why u not continue this type of videos
@mjant3069
@mjant3069 4 жыл бұрын
im your #1 Fan 😊
@saibaba7649
@saibaba7649 4 жыл бұрын
Thank you so much sister pls keep making more such videos :D
@rahulprajapat1460
@rahulprajapat1460 4 жыл бұрын
very much good. but code lines are not visible very clear.. .🔥🔥🔥
@adeshranjan8067
@adeshranjan8067 4 жыл бұрын
You video was very informative as expected from the first one... Pls make part 2 of this video... ❤️❤️
@akshaydeodare6149
@akshaydeodare6149 4 жыл бұрын
This just upped my energy🦾! thanks
@yougaincomputers1080
@yougaincomputers1080 4 жыл бұрын
Great content, are you using free version of burpsuite?
@KrakoonGaming
@KrakoonGaming 4 жыл бұрын
for bug bounty what os you are using right now? is it kali linux? you use kali as primary os or on vm and last question what you recommend for using kali as primary os or on vm
@smitsawant7063
@smitsawant7063 4 жыл бұрын
Mam just a small request to you! Like in this video u intercepted the request with burpsuite for price validation bug, please in your next videos do include such hands on .. and also with other tools. Keep posting such bug bounty videos..
@ashishf6
@ashishf6 4 жыл бұрын
If there is a full checklist for the same. Please share.
@allandiego1446
@allandiego1446 4 жыл бұрын
I think so haven't to that vulnerability is better u send id product and with php you send request to paypal.
@Status_Zones.
@Status_Zones. 4 жыл бұрын
I became a world famous fan.......for this content.
@saudia646
@saudia646 4 жыл бұрын
Need second part, love u sis...
@hackerspider1
@hackerspider1 4 жыл бұрын
Congo on 2k subscriber with two videos.
@FarahHawa
@FarahHawa 4 жыл бұрын
Thank you so much!
@KrakoonGaming
@KrakoonGaming 4 жыл бұрын
i sub to your channel and also liked the video. your content is very nice
@jonnydeep3342
@jonnydeep3342 4 жыл бұрын
plz make video on your bug hunter's journey
@vamsikolati
@vamsikolati 4 жыл бұрын
Nice work keep doing it please
@gokulap2251
@gokulap2251 4 жыл бұрын
We need a video series on this topic
@deeshantdhakate3958
@deeshantdhakate3958 4 жыл бұрын
It's legal to change the currency manipulation??
@CristiVladZ
@CristiVladZ 4 жыл бұрын
good job! What do you have on graphql?
@zeuscybersec659
@zeuscybersec659 4 жыл бұрын
My brother Cristi is in love🤣
@trishnoor3763
@trishnoor3763 4 жыл бұрын
Hey very informative video..... and at what age did you started hacking and how much time it took you till you first bug bounty??
@s.h.i.e.l.d5893
@s.h.i.e.l.d5893 4 жыл бұрын
What about path traversal attack? it's pretty 1337 attack . nice video though.
@0xx039
@0xx039 4 жыл бұрын
#justatip try creating video's with slides like @katie does in her youtube channel by doing like that you won't miss anything you wanna say and it would be also good instead you filling the screen we can see info's on screen and maybe your cam on bottom left corner. And this is gud too nice work :)
@vrushabhdoshi5664
@vrushabhdoshi5664 4 жыл бұрын
Please make detail video on IDOR.. with example of your PoCs.
@nightwatch4705
@nightwatch4705 4 жыл бұрын
That was a very informative video. How did you learn all this? Or where did you start? And any idea where to dig deeper for such information. Waiting for part 2.🤟
@FarahHawa
@FarahHawa 4 жыл бұрын
I have another video on where I learnt this and how I started!
@nightwatch4705
@nightwatch4705 4 жыл бұрын
@@FarahHawa I saw that as well. Great video. But I should have clarified that I wanted to how you learnt about these test cases of attacking an e-commerce website. Is it there in the books and resources you mentioned?
@FarahHawa
@FarahHawa 4 жыл бұрын
night watch I read white papers and reports on hackerone
@nightwatch4705
@nightwatch4705 4 жыл бұрын
@@FarahHawa please keep up your good work. Will watch out for more videos from you. Thank you.
@robertfling6173
@robertfling6173 4 жыл бұрын
Great job!
@the_uwd
@the_uwd 4 жыл бұрын
Please tell the accessaries and device need for a beginner 👍
@arbabshehzad6443
@arbabshehzad6443 4 жыл бұрын
I Don't know how but I think I can learn better with you, I've been doing so many paid courses and no one teaches or tells to openly. I Hope this comment will be valuable for you.
@sreyanshmahapatra8730
@sreyanshmahapatra8730 4 жыл бұрын
Can you make some more examples on IDOR (paid access thing ) and even on advance xss .
@Spiderman432
@Spiderman432 4 жыл бұрын
really love your work ❤
@savirsuda
@savirsuda 4 жыл бұрын
Please make a second part
@faysalahmed7251
@faysalahmed7251 4 жыл бұрын
What about practical example?
@emmanuelafolabi6847
@emmanuelafolabi6847 4 жыл бұрын
Thanks for the amazing content, I have always being curious about how race condition is exploited. What tool(s) have you used to successfully exploit race condition?
@FarahHawa
@FarahHawa 4 жыл бұрын
Burp turbo intruder should work!
@emmanuelafolabi6847
@emmanuelafolabi6847 4 жыл бұрын
@@FarahHawa Okay thanks
@vishalmishra1937
@vishalmishra1937 4 жыл бұрын
what was ur first bug bounty amt and for which org?
@azeemahmedkalesha6459
@azeemahmedkalesha6459 4 жыл бұрын
Hi Farah, can you please let me know the hardware specs required to get started into bug bounty?
@FarahHawa
@FarahHawa 4 жыл бұрын
Nothing fancy, just need a laptop, burp suite and a good internet connection. Any laptop will do but if you want do some heavy stuff and use a lot of VMs then I'd suggest Macbook Pro
@azeemahmedkalesha6459
@azeemahmedkalesha6459 4 жыл бұрын
@@FarahHawa somewhere in a decent budget range, any specific suggestion? Example the cpu or GPU capabilities... As we will also have to do some extensive brute forcing, it may require some good computational power, that's the sole reason for the question.. I'm looking to buy a laptop anytime soon, so need some suggestions from professionals like you, in a decent budget range.
@FarahHawa
@FarahHawa 4 жыл бұрын
@@azeemahmedkalesha6459 I don't use brute forcing too much but my HP Pavilion has decent computational power so maybe try that. Also, I'm a beginner too so right now even I'm saving up to buy a better laptop bcz honestly Macbook is the best for the kind of heavy stuff required.
@azeemahmedkalesha6459
@azeemahmedkalesha6459 4 жыл бұрын
@@FarahHawa Jazakallahu Khair ✌️
@boneytech3965
@boneytech3965 4 жыл бұрын
Helpfull video thanks
@cyrexplays5031
@cyrexplays5031 4 жыл бұрын
2nd part baby😍😍
@AkashVaani786
@AkashVaani786 4 жыл бұрын
I've used that thumbnail, it's from Canva😁🤘🏼
@000t9
@000t9 4 жыл бұрын
Dear Farah Hawa! Can you take a video about how to test websites without no input? I am searching how to do that... :)
@kartikaymusic.
@kartikaymusic. 4 жыл бұрын
OK, I have been learning from past 2 months actually 6 months but 4 wasted cuz of studies( man i wanna leave this country) I have read dozens of articles, done everything, please tell me how do you approach a site, make a video in which it shows how to approach a site, that would be of great help, thanks !
@FarahHawa
@FarahHawa 4 жыл бұрын
There’s no single way to approach a site, it depends on too many factors. For an e-commerce site- you can use these methods to approach. But for eg. approaching a mail service app or banking app would be very different
@malikimranawan3762
@malikimranawan3762 4 жыл бұрын
hey great am also a bug bounty hunter .. try to make video on RCE and SSRF
@shreyabanerjee1684
@shreyabanerjee1684 4 жыл бұрын
Hey Farah can u please tell me that is it legal to find bugs on any random website?and if so then how..like should we have to take permission for attacks from the admin of the website?
@FarahHawa
@FarahHawa 4 жыл бұрын
It is illegal if the website doesn’t have a bug bounty policy. You should hunt on programs which have bug bounty/responsible disclosure programs
@shreyabanerjee1684
@shreyabanerjee1684 4 жыл бұрын
@@FarahHawa will you please make a video on how to intercept website in burpsuite legally which will not cause any problem . And how can we use burpsuite for finding bugs in bugcrowd !
@FarahHawa
@FarahHawa 4 жыл бұрын
Shreya Banerjee using burp suite is legal! You just can’t attack websites that haven’t allowed you to. There’s a link in the description of this video which will show you how to use burpsuite!
@quotesmotivation1384
@quotesmotivation1384 2 жыл бұрын
Mam please add subtitles if possible ,... Plz
@surajagarwal3561
@surajagarwal3561 4 жыл бұрын
Plz upload tutorials from very scratch in other series for idiots like me .... Who are totally new in this field plz plz
@mubinamn
@mubinamn 4 жыл бұрын
You rock FARAH
@FarahHawa
@FarahHawa 4 жыл бұрын
@usernotfound6729
@usernotfound6729 3 жыл бұрын
This will not work in major websited
@tejaswagh5743
@tejaswagh5743 4 жыл бұрын
hi, what os are used to find bugs with tool you are perfer...
@jarviselite2542
@jarviselite2542 4 жыл бұрын
Thanks for this video
@adarshs2388
@adarshs2388 4 жыл бұрын
Nice video...👌👌
@BAPSOFFICIAL
@BAPSOFFICIAL 4 жыл бұрын
why you are not reply in twitter?
@MrWalxiLegendx
@MrWalxiLegendx 4 жыл бұрын
really cool vid :)
@bhaweshsharma4894
@bhaweshsharma4894 4 жыл бұрын
I want to be a part
@satyamsaptal9305
@satyamsaptal9305 4 жыл бұрын
Great content ☺️
@factofficial4399
@factofficial4399 4 жыл бұрын
plz make a video on burpsuite😊
@alifaizan8458
@alifaizan8458 4 жыл бұрын
Is it idos???
@Chiragsanikam.
@Chiragsanikam. 4 жыл бұрын
Was waiting for this one!
@ashutoshsoni2359
@ashutoshsoni2359 4 жыл бұрын
Please tell me how can I participate in a program after going in the directory in hackerone . Please help me with that.
@shreyashhire7527
@shreyashhire7527 4 жыл бұрын
Do you hack on hackerone ? Nice video 😄
@FarahHawa
@FarahHawa 4 жыл бұрын
Nope
@dorianvoka5591
@dorianvoka5591 4 жыл бұрын
Helpful indeed
@user-yh9zp
@user-yh9zp 4 жыл бұрын
What is u r age and what age u start hacking ?
@JasonGomes140294
@JasonGomes140294 4 жыл бұрын
is price manipulation and parameter tampering the same ????. Coz i tried it once on one of the e-commerce websites. just for starters (Pun intended) i ordered for a macaroon by entering the lowest amount i could think of. after 20 minutes their customer support later calls up saying that the shop has been closed down and cut the call. LOL .. All in all it was fun 🤣🤣🤣🤣🤣🤣🤣 Also guys dont try this without legal permission from the target. (I know i was stupid enough to this without permission)
@vishnuchandra5042
@vishnuchandra5042 4 жыл бұрын
show live demo in websites or any virtual machines
@noormohammadgagguturi
@noormohammadgagguturi 8 ай бұрын
Thanks a Lot
@sheelachowdary3126
@sheelachowdary3126 4 жыл бұрын
Please do live hunting
@civilengineer493
@civilengineer493 4 жыл бұрын
hotel booking is not clear
HACKING GraphQL FOR BEGINNERS + GIVEAWAY (closed)
8:58
Farah Hawa
Рет қаралды 37 М.
From 0 to Cybersecurity at FAANG
11:02
Farah Hawa
Рет қаралды 37 М.
It works #beatbox #tiktok
00:34
BeatboxJCOP
Рет қаралды 41 МЛН
Sigma Kid Mistake #funny #sigma
00:17
CRAZY GREAPA
Рет қаралды 30 МЛН
My scorpion was taken away from me 😢
00:55
TyphoonFast 5
Рет қаралды 2,7 МЛН
HACKING postMessage() FOR BEGINNERS!
8:57
Farah Hawa
Рет қаралды 34 М.
BYPASSING SAML AUTHENTICATION FOR BEGINNERS!
8:24
Farah Hawa
Рет қаралды 30 М.
HACKING OAuth 2.0 FOR BEGINNERS!
10:26
Farah Hawa
Рет қаралды 44 М.
TIPS TO GET A JOB IN CYBERSECURITY!
5:12
Farah Hawa
Рет қаралды 16 М.
ATTACKING JWT FOR BEGINNERS!
7:39
Farah Hawa
Рет қаралды 56 М.
MY BUG BOUNTY JOURNEY!
5:27
Farah Hawa
Рет қаралды 244 М.
WEB CACHE DECEPTION FOR BEGINNERS!
7:42
Farah Hawa
Рет қаралды 18 М.
E-commerce Flaws and $500-1000 Bounties
15:53
InsiderPhD
Рет қаралды 5 М.
How To Get Started In Bug Bounties
8:36
DC CyberSec
Рет қаралды 111 М.
It works #beatbox #tiktok
00:34
BeatboxJCOP
Рет қаралды 41 МЛН