Finding Bugs in Mobile APIs

  Рет қаралды 20,318

InsiderPhD

InsiderPhD

Күн бұрын

Hey everyone! Welcome to another API video, well I promise more didn't I! This week we're going to use the setup from the previous videos on iOS and Android, and actually use it to FIND BUGS! Mobile apps have some AMAZING first bugs, that don't require complex technical skills, but instead perseverance!
Did you know this episode was sponsored by Intigriti? Sign up with my link go.intigriti.com/katie I'm so pleased with everyone's positive response to the Intigriti sponsorship and I'm so pleased you folks are finding bugs and even finding your first bugs! Thank you for being awesome!
- Resources -
A lot of people have told me that they struggle to find APIs to test, so I hope that this will help get you started! If you've only just joined us, here are the videos I recommend!
Top 10 API bugs: • Top 10 API Bugs (and W...
Enumerating APIs: • How To Do Recon: API E...
Finding Your First Bug: APIs: • Finding Your First Bug...
TomNomNom: • Who, What, Where, When...
FFUF: • How to use ffuf - Hack...
- Social Media -
Discord: / discord
Patreon: / insiderphd
Twitter: / insiderphd
- Patreon Shoutouts -
MechaInfoSec
Wardell Castles
rl1k
strongbeard
Lukáš Hájek
Gynvael
Ram
James Clee

Пікірлер: 36
@luckythandel
@luckythandel 3 жыл бұрын
You are doing such a good deed. Many of us are learning a lot from these videos. Thank you for doing it free.
@davicosta4931
@davicosta4931 3 жыл бұрын
Hey Katie, thanks for all your videos, in the last weekend, I found my first bug! A business logic error, thanks to your videos. Unfortunately, was a duplicate, but I'm very happy for this! Thanks again, love from Brazil!
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Nice work! a dupe is a bug, you just weren't quick enough this time! You CAN find bugs though, keep going and you'll get faster!
@user-or9lh2bi6x
@user-or9lh2bi6x 3 жыл бұрын
Hi, top video! Just wanted to ask a question, both Genymotion and Android Studio, emulator does not support a lot of mobile apps because they have a different system architecture, do you guys have any suggestions? I mean cloud or something else?
@nixsonblackstone7900
@nixsonblackstone7900 3 жыл бұрын
Thanks alot Katie and God bless 👍
@learningwithtom4104
@learningwithtom4104 2 жыл бұрын
Hi Katie, You can directly edit from KZbin video editor only & TRIM the final part. It's pretty easy & for a person like you, it should be damn easy. Look at some video if need any clarification. Thanks for this video. Keep up the good work.
@omarelfarsaoui5498
@omarelfarsaoui5498 3 жыл бұрын
great work !
@jeffm623
@jeffm623 3 жыл бұрын
Thank you :) For reference, something i still struggle with.. IDOR - Insecure direct object references
@hydraking8768
@hydraking8768 3 жыл бұрын
Katie Nice Work 👍
@babay-mp4bq
@babay-mp4bq 3 жыл бұрын
is it illegal using free genymotion for bug hunting ?
@abhhibirdawade9657
@abhhibirdawade9657 3 жыл бұрын
katie your amazing!!!!!!!!!!!!!
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Aww thank you so much it means a lot to me!
@user-wd3ng2pt3z
@user-wd3ng2pt3z 3 жыл бұрын
thanks for these videos you are great ^_^ , Can you make video about any tools or programs (VPNs) that secure myself after penetration web site hacking ? thanks again .
@samudrasarma6555
@samudrasarma6555 3 жыл бұрын
Waiting for this video.
@InsiderPhD
@InsiderPhD 3 жыл бұрын
I hope it was worth the wait!
@ahmadgiftred2048
@ahmadgiftred2048 3 жыл бұрын
Nice!
@dasuntheekshana7599
@dasuntheekshana7599 3 жыл бұрын
Great ❤
@avilashnandy9886
@avilashnandy9886 3 жыл бұрын
Hi katie... I would like to thank you so so very much for introducing me to the ios bug bounty setup... I somehow managed to setup my "hacking environment" even though I don't have a mac...and had to browse through a lot of articles for understanding the linux way of settings things up (it took me like 3-4 days to set it up).. I was just curious..could you show some ios specific bugs that a beginner can look for, I read the "read ahead" articles given in the description of the that video..but was not able to understand it properly..and was wondering if you could help me out with it (by making a video or just by referring to any other resources that I could go through)..thanks in advance. much love from India
@InsiderPhD
@InsiderPhD 3 жыл бұрын
FRIDA and webview bugs are great places to start there’s a video I recommend by Dawn Isabel on Bugcrowds channel talking about iOS bug hunting, Spaceracoon also has an article on iOS bugs. But don’t worry we’ll be covering all of that in a later video :)
@avilashnandy9886
@avilashnandy9886 3 жыл бұрын
@@InsiderPhD thank you so much 😃
@Stas1983ful
@Stas1983ful 3 жыл бұрын
Where is graphql link?
@AjayKumar-xl4jc
@AjayKumar-xl4jc 3 жыл бұрын
Wah super
@elsakaydb6271
@elsakaydb6271 3 жыл бұрын
Great
@AjayKumar-xl4jc
@AjayKumar-xl4jc 3 жыл бұрын
Thanks😃girl for this video
@ca7986
@ca7986 3 жыл бұрын
❤️
@ayushxowealth
@ayushxowealth 3 жыл бұрын
Nice
@rajatdutta8365
@rajatdutta8365 2 жыл бұрын
gr8 video
@amyqb117
@amyqb117 3 жыл бұрын
Omg greaaaat
@mr.kn0w1t4ll2
@mr.kn0w1t4ll2 3 жыл бұрын
Yay Mobile !!
@realstar5979
@realstar5979 3 жыл бұрын
Good
@ganeshkhairkar30
@ganeshkhairkar30 3 жыл бұрын
𝗹𝗼𝘃𝗲❤ 𝗙𝗿𝗼𝗺 🇮🇳𝗜𝗻𝗱𝗶𝗮
@tangducbao7309
@tangducbao7309 3 жыл бұрын
Hello from fan, I have a few question - Do you need a rooted phone to perform a bug bounty? - Do bounty platform accept result from a emulation device like Genymotion? - How do you extract .apk from your real phone? with and without root.
@InsiderPhD
@InsiderPhD 3 жыл бұрын
- Yes, usually, because of something called certificate pinning - Yup - You can go on APK downloading sites
@tangducbao7309
@tangducbao7309 3 жыл бұрын
@@InsiderPhD thank you 👍
@321aayushsoni
@321aayushsoni 3 жыл бұрын
Hey Katie, Nice video but last 8 minutes or so are black screen, you must edit that out. after 31:20
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Thanks! I’m not a video editor so mistakes happen!
Burp Suite - Track API of any applications
12:07
TechieQA
Рет қаралды 35 М.
Hunting for bugs in GraphQL APIs (Demo)
50:41
InsiderPhD
Рет қаралды 15 М.
Пранк пошел не по плану…🥲
00:59
Саша Квашеная
Рет қаралды 6 МЛН
ЧУТЬ НЕ УТОНУЛ #shorts
00:27
Паша Осадчий
Рет қаралды 10 МЛН
Slow motion boy #shorts by Tsuriki Show
00:14
Tsuriki Show
Рет қаралды 9 МЛН
3 Real API Bugs I got a bounty for
17:43
InsiderPhD
Рет қаралды 9 М.
How To: Reverse Engineer Any Private API (iOS/Android and Desktop)
11:47
Finding Your First API Bug (NahamCon 2023)
22:10
InsiderPhD
Рет қаралды 10 М.
How to Read API Documentation
7:18
Joshua Schuett
Рет қаралды 7 М.
Мыла наелся
0:21
Pavlov_family_
Рет қаралды 4,7 МЛН
这是王子儿子吗
0:27
落魄的王子
Рет қаралды 9 МЛН
KARMA AT SCHOOL 🏫 Stop time
0:32
dednahype
Рет қаралды 46 МЛН
ПИЩЕВОЙ ВАНДАЛ НАКАЗАН
0:20
МАКАРОН
Рет қаралды 2,9 МЛН