Finding Your First Bug: Business Logic Errors

  Рет қаралды 63,445

InsiderPhD

InsiderPhD

Күн бұрын

Пікірлер: 103
@tayfun6378
@tayfun6378 5 жыл бұрын
this is pure gold info for the starters like me. and it's inspiring! thank you so much for your efforts and yes we would like to see more like these videos!
@InsiderPhD
@InsiderPhD 5 жыл бұрын
Thank you so much for your comments, my first bug was Business Logic and I really think it's one of the best bugs to find for a newbie
@snoopysaurav
@snoopysaurav 4 жыл бұрын
Just getting started in this field and found your playlist for "Finding Your First Bug" this is a mine of knowledge for me. Thanks for amazing videos.
@sarahconnorh4609
@sarahconnorh4609 2 жыл бұрын
Incredible content. I have done a lot of courses about web, reverse, hacking, passed certifications, but this is REAL hands-on cases! I love it ! Thanks a lot InsiderPhD
@tirtheshpawar1020
@tirtheshpawar1020 4 жыл бұрын
I am going to start taking notes from your videos. This is gold..!!! god bless you.
@athtp4452
@athtp4452 4 жыл бұрын
I'm still get back to this awsome super informative videos ❤️
@w3w3w3
@w3w3w3 5 жыл бұрын
Wow, nice channel, I am just getting into bug bountys from malware lol and I can see myself watching all your videos. I see you know STOK ha, love his videos as well :)
@PlentyRude
@PlentyRude 4 жыл бұрын
Can’t express how beneficial these videos have been in my goal of becoming a sound hacker. This is what the hacking community is all about!
@johnb2654
@johnb2654 3 жыл бұрын
Thank you so much!!!!! Love being able to actually watch you try real stuff.
@InsiderPhD
@InsiderPhD 3 жыл бұрын
You are so welcome!
@arshmansuri4633
@arshmansuri4633 4 жыл бұрын
man, u r such a good teacher... I mean when I first started to read about business logic error I didn't understand a thing but after watching ur video I actually tried n got results...thank u so much for doing this amazing work I really appreciate it
@pranavbankoti
@pranavbankoti 5 жыл бұрын
Absolutely loved it!!! Got so much to learn!! Thank you so much ❤️
@sergiomedeiros5506
@sergiomedeiros5506 5 жыл бұрын
Keep up the great work man, love your videos. I’ve been doing web app pen testing before bug bounties existed and fell out of the scene now I’m getting back into it and videos like these are helpful to update me on new theories and concepts. Keep posting!
@ericcolt8078
@ericcolt8078 5 жыл бұрын
thank you for making these videos you are actually one of the few people how go indept on a "live" target and really go into steps.. Yes sure people use the vulnerable web app or owasp test apps but i don't really feel its the same thing because they where made buggy. So thank you for making these video i learned allot :) !
@ricardotech
@ricardotech 4 жыл бұрын
Thanks for that well explanation Katie!
@borhangherbi8189
@borhangherbi8189 5 жыл бұрын
That's the kind that I've been looking for for a long time So far I have not found bugs because I have relied on types like xss sqli csrf And I became a little frustrated Thank you very much we hope to see more exciting things
@InsiderPhD
@InsiderPhD 5 жыл бұрын
Don't worry! XSS, SQL injection and CSRF are actually really difficult to find especially for someone finding their first. The bugs tend to require mitigation strategies to bypass existing security features and without that experience of what kind of mitigation you might need.
@borhangherbi8189
@borhangherbi8189 5 жыл бұрын
​@@InsiderPhD thank you for this comment bypass restriction require a huge knowledge specially when you face hosts sharing like Akami and cloudflare they use big WAF but I will not give up I will continue to learn more I think I'll interest in APIs and Block chains and repeat special thanks for you see you soon.
@keerahere6645
@keerahere6645 5 жыл бұрын
Thanks for sharing such gold stuff! Really appreaciate your efforts :)
@franklinramirez7550
@franklinramirez7550 4 жыл бұрын
I am here for the cyber mentor recomendation, I came looking for copper and I found gold
@i-speedst3r987
@i-speedst3r987 4 жыл бұрын
Nice rhymes man xD
@zorfteq8074
@zorfteq8074 5 жыл бұрын
TBH this was the most helpfull video of hacking ive ever seen on youtube i knew exactly what you where doing and the explaining was outstanding thanks alot!!! ....:)
@dalidasaad4482
@dalidasaad4482 2 жыл бұрын
your videos are so informative. thank you so much for this series :)
@dhruvkandpal9909
@dhruvkandpal9909 4 жыл бұрын
Ma'am, happy teacher's day. Love from India. :) Awesome video!
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Thank you! Don’t forget to celebrate all the teachers in the hacking community ;)
@mrzickod4035
@mrzickod4035 4 жыл бұрын
Thanks for giving this content. And i'd like also to ask in which order should some follow this playlist
@InsiderPhD
@InsiderPhD 4 жыл бұрын
I have a “new to bug hunting start here” with a suggested order :)
@sanneck
@sanneck 5 жыл бұрын
such an amazing content, thank you so much for this! keep doing it
@sashikant3104
@sashikant3104 4 жыл бұрын
Pure gold content
@vishnudasari6574
@vishnudasari6574 4 жыл бұрын
dude ur great iwas wondering where to start bug bounty from scratch and you made it inspirational and easy loveyou
@ronzz8933
@ronzz8933 5 жыл бұрын
We all know InsiderPhd scores on business logic errors. She has really explained it really well.
@InsiderPhD
@InsiderPhD 5 жыл бұрын
Business Logic errors are my favourite bugs! They are easy to hunt for and they don’t require complex technical explanations! I’ve made good money finding them :)
@ronzz8933
@ronzz8933 5 жыл бұрын
@@InsiderPhD keep going!! :)
@tirtheshpawar1020
@tirtheshpawar1020 4 жыл бұрын
Hey Katie, the only part I didn't understand was 23:36 here, when u changed some input here and said it will be easy to find regex sort of like that. I didn't get what you meant there or was it co-related to this topic we learned. It would be nice if you could clarify that, please. Sorry if I sound too naive.
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Aha! so what I'm doing is just filtering to only show all the *.flurry.com domains, you can do this by going to: 1) Target->Scope->Tick Advanced Scope Control 2) Click Add 3) Protocol: HTTPS 4) ^.+\.DOMAIN\.com$ 5) Port: 443 6) File: ^\..*
@tirtheshpawar1020
@tirtheshpawar1020 4 жыл бұрын
@@InsiderPhD OK noted. Thankyou. :)
@firasfatnassi6891
@firasfatnassi6891 5 жыл бұрын
Such great video i really learned so much from it keep up the good work!
@karthibalaji3817
@karthibalaji3817 5 жыл бұрын
At last found the channel (Goldmine) splendid content!.
@thelasttechnology1532
@thelasttechnology1532 5 жыл бұрын
Thank you very much 💖 We need more
@omarsec3178
@omarsec3178 4 жыл бұрын
OMG!!! very informational 👌👌
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Thanks a lot 😊
@sainathballa
@sainathballa 5 жыл бұрын
yes.we need more videos from you bypass 401, 400, 500 , 403 staus codes
@yunemse48
@yunemse48 5 жыл бұрын
Pretty good sharing and great content, no doubt. I'm a beginner in cyber security and eventhough I've got a private invitation on H1, I couldn't manage to find a bug... However, this video gave me a different perpective and way of think. Therefore, I'm so grateful to you for your sharing :) Btw, I guess you are from UK? I like this accent although I've hard time to understand it :)
@InsiderPhD
@InsiderPhD 5 жыл бұрын
I am from the UK yes, finding your first bug is really really hard so don't get discouraged- there's a big gap between CTFs and real-world systems. This is why I quite like business logic errors because you don't need to know complex mitigation tom get XSS to work.
@yunemse48
@yunemse48 5 жыл бұрын
@@InsiderPhD Thanks for your reply. When I got started in my first program, I got stuck... I didn't know where to start, how to find bugs and where to look for them. It was discouraging but I won't give up.. I'm also following you on Twitter and hope to see more sharings from you. If I can manage to find my first bug, I will write it here :)
@on.alin11
@on.alin11 11 ай бұрын
CCNA courses from M1->M3 will help me with this path ?
@FrenchPirate83
@FrenchPirate83 5 жыл бұрын
I may be wrong, but I don't think your JSON payloads were legal JSON, because you forgot to add a comma before your Intruder position at 30:55.
@InsiderPhD
@InsiderPhD 5 жыл бұрын
Thanks for catching it, I will issue a correction in the description, I really appreciate it!
@FrenchPirate83
@FrenchPirate83 5 жыл бұрын
No bother. Keep up the good work.
@nessun00x81
@nessun00x81 5 жыл бұрын
really cool video!! keep up the good work
@carver0019
@carver0019 2 жыл бұрын
Starting with business logic and Idor in this field,Am I going good as a beginner?
@mostafahamza3106
@mostafahamza3106 Жыл бұрын
can you plz share the slides with us just wanna use it as a mind refresher when I'm back to hunting , you're really doing a great job thank you for this informative videos
@InsiderPhD
@InsiderPhD Жыл бұрын
Ah I'm sorry, I don't typically offer slides for regular videos because people steal them :( I've shared a few on patreon but I had to stop because people stole them. I do share conference slides though.
@mostafahamza3106
@mostafahamza3106 Жыл бұрын
Thanks for your effort , there is a great benefit in summarize it myself thou @@InsiderPhD
@skwtf
@skwtf 5 жыл бұрын
Nice video. Thanks. I didn't quite understand what's the difference between an IDOR and just changing an ID? You mentioned validation, but I'm not sure I understand.
@InsiderPhD
@InsiderPhD 5 жыл бұрын
They are the same thing - the easiest way to find IDORs is to change every ID you can see or remove the cookies and see if an action still works. I have a video coming for more depth on IDORs because I think they are great first bugs
@skwtf
@skwtf 5 жыл бұрын
Thank you for the quick reply. I subscribed and wish you luck. You are easy to listen to and have great things to share. Hope you do a short video about your experience and where you're coming from, because I don't know who I'm listening to :D
@knowledgecrickethub8415
@knowledgecrickethub8415 5 жыл бұрын
Please more videos like this!!
@himanshupandey9303
@himanshupandey9303 4 жыл бұрын
Video was great just the fonts were too small for my eyes to see during the burp tutorial session, can you just increase the font size in future vids? Thanks!!
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Will do thank for you the feedback!
@Akash_us
@Akash_us 4 жыл бұрын
@@InsiderPhD yes mam phone users will suffer a lot
@nabilsalih2898
@nabilsalih2898 4 жыл бұрын
I might be a clueless idiot for asking this but how did you set up Burpsuite for flurry?
@anonymous0807
@anonymous0807 5 жыл бұрын
Thanks a lot 🙂,Keep Supporting ✌🏻
@sagarsjdjfn
@sagarsjdjfn Жыл бұрын
Do you have a course on you configure it ? You are doing it very fast. I understand the things you say and do but the configurations are super fast. Like configuring interceptor and fuzzdb $dddd.
@andreslauga
@andreslauga 4 жыл бұрын
Awesome!
@john6283
@john6283 4 жыл бұрын
As long as we have the Burp Suite we can hunt a bug, does OS matters? I mean in most cases, Linux is being used, so I am wondering if there's any factor in using Linux?
@InsiderPhD
@InsiderPhD 4 жыл бұрын
No OS does not matter! If you want to use Linux you totally can but I use OSX and Windows and I’ve never been in a position that I’ve felt I’ve needed Linux to do something
@OthmanAlikhan
@OthmanAlikhan 9 ай бұрын
Thanks for the video =)
@hasnainabidkhanzada3754
@hasnainabidkhanzada3754 4 жыл бұрын
Business logic is more of like breaking or exploiting the business rules. In this case, a business rule can be to validate the input. Now if someone somehow exploit or break that rule then what it should be called? Business logic error or XSS? How business logic errors differ from other attacks like IDOR, XSS, CSRF etc. Can u please explain it?
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Usually XSS as business logic is more "look I can change the price to a negative number" think more exploiting it working as intended, rather than validation.
@hasnainabidkhanzada3754
@hasnainabidkhanzada3754 4 жыл бұрын
@@InsiderPhD So in short: Bugs not recognized as specific type can be called as business logic errors. Right?
@AnuragKumar-hv1df
@AnuragKumar-hv1df 4 жыл бұрын
very knowledgeable video.
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Glad you think so!
@thedevalweb
@thedevalweb 5 жыл бұрын
Great content!
@ahmedezealdean6189
@ahmedezealdean6189 6 ай бұрын
Bussiness Logic errors are so similar to IDORS, and according the web applications hacker handsbook it a type of IDOR.
@anujkumarpatel2686
@anujkumarpatel2686 4 жыл бұрын
thanks great content ❤
@hanyobied8792
@hanyobied8792 5 жыл бұрын
Many Thanks
@gene495
@gene495 4 жыл бұрын
what if the app is calling other 3rd party services? Does it still make sense to limit the scope?
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Yes, we really don't want to hack a service we don't have permission to be hacking! Also if we do find a bug in that third party stuff we won't be able to report it to recieve a bounty, it's better to focus on the services we have permission to test
@sshouqq
@sshouqq 4 жыл бұрын
Your the best thank u so much
@nikhilprem7998
@nikhilprem7998 4 жыл бұрын
Need some advice I am a newbie in coding and I finished python and am starting Java is it the right time for me to try bug bounties or do I need to learn more
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Nikhil Prem there’s never a right time to learn and there’s not a critical mass of knowledge you need to start. Just start. Just have a go. If you get stuck google what you’re unsure or ask. But you are ready right now I promise you
@shrirangkahale
@shrirangkahale 4 жыл бұрын
Great Content!!!!!!!!!! BTW Plz buy a new MIC audio was horrible BUT the explaination was awesome!!!!
@InsiderPhD
@InsiderPhD 4 жыл бұрын
I solved this in later videos!
@s4dum4
@s4dum4 5 жыл бұрын
Thanks for sharing your knowledge will you continue uploading videos?
@InsiderPhD
@InsiderPhD 5 жыл бұрын
Yes! I'm going to continue this series designed for beginners
@Raj_darker
@Raj_darker 5 жыл бұрын
Awesome !!1 Keep Posting! :)
@DEADCODE_
@DEADCODE_ 2 жыл бұрын
it's cool but katie it's a little bit similar with Data Tampering right
@InsiderPhD
@InsiderPhD 2 жыл бұрын
Yes!
@testingx01
@testingx01 5 жыл бұрын
Thanks a lot Katie ! Keep up with the good stuff :) #InfosecGirls FTW
@sontapaa11jokulainen94
@sontapaa11jokulainen94 5 жыл бұрын
There are a lot of tutorials out there which tell you how you can get in to the community, what tools they use etc. but nobody actually tells any concrete examples.
@steev910
@steev910 5 жыл бұрын
thanks
@paulojr1384
@paulojr1384 2 жыл бұрын
🖖
@0xsunil
@0xsunil 5 жыл бұрын
@abhishekmorla1
@abhishekmorla1 4 жыл бұрын
who else watching this before jump into portswigger labs ?
@gastontimchuk2295
@gastontimchuk2295 4 жыл бұрын
Hi this series are for a completly noob and doesnt know about programming? i really start in BBH
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Yes! No programming knowledge or security knowledge required, just a passion for learning and a determined attitude!
@gastontimchuk2295
@gastontimchuk2295 4 жыл бұрын
InsiderPhD oh so thx so much im very exited to find my first bug i watching your series and im learning a lot thanks for everything
@devdarpan3582
@devdarpan3582 5 жыл бұрын
You are doing great job but i am just having hard time understanding your accent !!!
@InsiderPhD
@InsiderPhD 5 жыл бұрын
Sorry! I'm desperately trying to slow down when I speak, I forget how many non-native English speakers watch!
@danielmcpherson9062
@danielmcpherson9062 4 жыл бұрын
If you need her to talk slower, just slow down the speed of the video :)
@animebros9214
@animebros9214 4 жыл бұрын
i think its more the audio recording setup than the accent. otherwise great work
Finding Your First Bug: Manual IDOR Hunting
33:28
InsiderPhD
Рет қаралды 78 М.
Finding Your First Bug: Choosing Your Target
32:32
InsiderPhD
Рет қаралды 163 М.
I Sent a Subscriber to Disneyland
0:27
MrBeast
Рет қаралды 104 МЛН
Жездуха 42-серия
29:26
Million Show
Рет қаралды 2,6 МЛН
Who is More Stupid? #tiktok #sigmagirl #funny
0:27
CRAZY GREAPA
Рет қаралды 10 МЛН
10.03 Generative Models and the Variational Autoencoder (VAE)
38:03
AutoML Freiburg - Education
Рет қаралды 60
Business Logic Vulnerabilities | Complete Guide
18:58
Rana Khalil
Рет қаралды 9 М.
How I Found My First Bug (and earned $1k!) - Business Logic Tips
19:41
Finding Your First Bug: Goal Setting and Motivation
29:48
InsiderPhD
Рет қаралды 22 М.
Hacking when all the bugs have been found?
18:53
InsiderPhD
Рет қаралды 6 М.
How to Find Your First Bug
23:33
InsiderPhD
Рет қаралды 38 М.
What is Business Logic in Software Development?
5:04
Be A Better Dev
Рет қаралды 34 М.
How much money I made in my 1st year of bug bounty? Bounty vlog #4
17:02
Bug Bounty Reports Explained
Рет қаралды 169 М.