this is pure gold info for the starters like me. and it's inspiring! thank you so much for your efforts and yes we would like to see more like these videos!
@InsiderPhD5 жыл бұрын
Thank you so much for your comments, my first bug was Business Logic and I really think it's one of the best bugs to find for a newbie
@snoopysaurav4 жыл бұрын
Just getting started in this field and found your playlist for "Finding Your First Bug" this is a mine of knowledge for me. Thanks for amazing videos.
@sarahconnorh46092 жыл бұрын
Incredible content. I have done a lot of courses about web, reverse, hacking, passed certifications, but this is REAL hands-on cases! I love it ! Thanks a lot InsiderPhD
@tirtheshpawar10204 жыл бұрын
I am going to start taking notes from your videos. This is gold..!!! god bless you.
@athtp44524 жыл бұрын
I'm still get back to this awsome super informative videos ❤️
@w3w3w35 жыл бұрын
Wow, nice channel, I am just getting into bug bountys from malware lol and I can see myself watching all your videos. I see you know STOK ha, love his videos as well :)
@PlentyRude4 жыл бұрын
Can’t express how beneficial these videos have been in my goal of becoming a sound hacker. This is what the hacking community is all about!
@johnb26543 жыл бұрын
Thank you so much!!!!! Love being able to actually watch you try real stuff.
@InsiderPhD3 жыл бұрын
You are so welcome!
@arshmansuri46334 жыл бұрын
man, u r such a good teacher... I mean when I first started to read about business logic error I didn't understand a thing but after watching ur video I actually tried n got results...thank u so much for doing this amazing work I really appreciate it
@pranavbankoti5 жыл бұрын
Absolutely loved it!!! Got so much to learn!! Thank you so much ❤️
@sergiomedeiros55065 жыл бұрын
Keep up the great work man, love your videos. I’ve been doing web app pen testing before bug bounties existed and fell out of the scene now I’m getting back into it and videos like these are helpful to update me on new theories and concepts. Keep posting!
@ericcolt80785 жыл бұрын
thank you for making these videos you are actually one of the few people how go indept on a "live" target and really go into steps.. Yes sure people use the vulnerable web app or owasp test apps but i don't really feel its the same thing because they where made buggy. So thank you for making these video i learned allot :) !
@ricardotech4 жыл бұрын
Thanks for that well explanation Katie!
@borhangherbi81895 жыл бұрын
That's the kind that I've been looking for for a long time So far I have not found bugs because I have relied on types like xss sqli csrf And I became a little frustrated Thank you very much we hope to see more exciting things
@InsiderPhD5 жыл бұрын
Don't worry! XSS, SQL injection and CSRF are actually really difficult to find especially for someone finding their first. The bugs tend to require mitigation strategies to bypass existing security features and without that experience of what kind of mitigation you might need.
@borhangherbi81895 жыл бұрын
@@InsiderPhD thank you for this comment bypass restriction require a huge knowledge specially when you face hosts sharing like Akami and cloudflare they use big WAF but I will not give up I will continue to learn more I think I'll interest in APIs and Block chains and repeat special thanks for you see you soon.
@keerahere66455 жыл бұрын
Thanks for sharing such gold stuff! Really appreaciate your efforts :)
@franklinramirez75504 жыл бұрын
I am here for the cyber mentor recomendation, I came looking for copper and I found gold
@i-speedst3r9874 жыл бұрын
Nice rhymes man xD
@zorfteq80745 жыл бұрын
TBH this was the most helpfull video of hacking ive ever seen on youtube i knew exactly what you where doing and the explaining was outstanding thanks alot!!! ....:)
@dalidasaad44822 жыл бұрын
your videos are so informative. thank you so much for this series :)
@dhruvkandpal99094 жыл бұрын
Ma'am, happy teacher's day. Love from India. :) Awesome video!
@InsiderPhD4 жыл бұрын
Thank you! Don’t forget to celebrate all the teachers in the hacking community ;)
@mrzickod40354 жыл бұрын
Thanks for giving this content. And i'd like also to ask in which order should some follow this playlist
@InsiderPhD4 жыл бұрын
I have a “new to bug hunting start here” with a suggested order :)
@sanneck5 жыл бұрын
such an amazing content, thank you so much for this! keep doing it
@sashikant31044 жыл бұрын
Pure gold content
@vishnudasari65744 жыл бұрын
dude ur great iwas wondering where to start bug bounty from scratch and you made it inspirational and easy loveyou
@ronzz89335 жыл бұрын
We all know InsiderPhd scores on business logic errors. She has really explained it really well.
@InsiderPhD5 жыл бұрын
Business Logic errors are my favourite bugs! They are easy to hunt for and they don’t require complex technical explanations! I’ve made good money finding them :)
@ronzz89335 жыл бұрын
@@InsiderPhD keep going!! :)
@tirtheshpawar10204 жыл бұрын
Hey Katie, the only part I didn't understand was 23:36 here, when u changed some input here and said it will be easy to find regex sort of like that. I didn't get what you meant there or was it co-related to this topic we learned. It would be nice if you could clarify that, please. Sorry if I sound too naive.
@InsiderPhD4 жыл бұрын
Aha! so what I'm doing is just filtering to only show all the *.flurry.com domains, you can do this by going to: 1) Target->Scope->Tick Advanced Scope Control 2) Click Add 3) Protocol: HTTPS 4) ^.+\.DOMAIN\.com$ 5) Port: 443 6) File: ^\..*
@tirtheshpawar10204 жыл бұрын
@@InsiderPhD OK noted. Thankyou. :)
@firasfatnassi68915 жыл бұрын
Such great video i really learned so much from it keep up the good work!
@karthibalaji38175 жыл бұрын
At last found the channel (Goldmine) splendid content!.
@thelasttechnology15325 жыл бұрын
Thank you very much 💖 We need more
@omarsec31784 жыл бұрын
OMG!!! very informational 👌👌
@InsiderPhD4 жыл бұрын
Thanks a lot 😊
@sainathballa5 жыл бұрын
yes.we need more videos from you bypass 401, 400, 500 , 403 staus codes
@yunemse485 жыл бұрын
Pretty good sharing and great content, no doubt. I'm a beginner in cyber security and eventhough I've got a private invitation on H1, I couldn't manage to find a bug... However, this video gave me a different perpective and way of think. Therefore, I'm so grateful to you for your sharing :) Btw, I guess you are from UK? I like this accent although I've hard time to understand it :)
@InsiderPhD5 жыл бұрын
I am from the UK yes, finding your first bug is really really hard so don't get discouraged- there's a big gap between CTFs and real-world systems. This is why I quite like business logic errors because you don't need to know complex mitigation tom get XSS to work.
@yunemse485 жыл бұрын
@@InsiderPhD Thanks for your reply. When I got started in my first program, I got stuck... I didn't know where to start, how to find bugs and where to look for them. It was discouraging but I won't give up.. I'm also following you on Twitter and hope to see more sharings from you. If I can manage to find my first bug, I will write it here :)
@on.alin1111 ай бұрын
CCNA courses from M1->M3 will help me with this path ?
@FrenchPirate835 жыл бұрын
I may be wrong, but I don't think your JSON payloads were legal JSON, because you forgot to add a comma before your Intruder position at 30:55.
@InsiderPhD5 жыл бұрын
Thanks for catching it, I will issue a correction in the description, I really appreciate it!
@FrenchPirate835 жыл бұрын
No bother. Keep up the good work.
@nessun00x815 жыл бұрын
really cool video!! keep up the good work
@carver00192 жыл бұрын
Starting with business logic and Idor in this field,Am I going good as a beginner?
@mostafahamza3106 Жыл бұрын
can you plz share the slides with us just wanna use it as a mind refresher when I'm back to hunting , you're really doing a great job thank you for this informative videos
@InsiderPhD Жыл бұрын
Ah I'm sorry, I don't typically offer slides for regular videos because people steal them :( I've shared a few on patreon but I had to stop because people stole them. I do share conference slides though.
@mostafahamza3106 Жыл бұрын
Thanks for your effort , there is a great benefit in summarize it myself thou @@InsiderPhD
@skwtf5 жыл бұрын
Nice video. Thanks. I didn't quite understand what's the difference between an IDOR and just changing an ID? You mentioned validation, but I'm not sure I understand.
@InsiderPhD5 жыл бұрын
They are the same thing - the easiest way to find IDORs is to change every ID you can see or remove the cookies and see if an action still works. I have a video coming for more depth on IDORs because I think they are great first bugs
@skwtf5 жыл бұрын
Thank you for the quick reply. I subscribed and wish you luck. You are easy to listen to and have great things to share. Hope you do a short video about your experience and where you're coming from, because I don't know who I'm listening to :D
@knowledgecrickethub84155 жыл бұрын
Please more videos like this!!
@himanshupandey93034 жыл бұрын
Video was great just the fonts were too small for my eyes to see during the burp tutorial session, can you just increase the font size in future vids? Thanks!!
@InsiderPhD4 жыл бұрын
Will do thank for you the feedback!
@Akash_us4 жыл бұрын
@@InsiderPhD yes mam phone users will suffer a lot
@nabilsalih28984 жыл бұрын
I might be a clueless idiot for asking this but how did you set up Burpsuite for flurry?
@anonymous08075 жыл бұрын
Thanks a lot 🙂,Keep Supporting ✌🏻
@sagarsjdjfn Жыл бұрын
Do you have a course on you configure it ? You are doing it very fast. I understand the things you say and do but the configurations are super fast. Like configuring interceptor and fuzzdb $dddd.
@andreslauga4 жыл бұрын
Awesome!
@john62834 жыл бұрын
As long as we have the Burp Suite we can hunt a bug, does OS matters? I mean in most cases, Linux is being used, so I am wondering if there's any factor in using Linux?
@InsiderPhD4 жыл бұрын
No OS does not matter! If you want to use Linux you totally can but I use OSX and Windows and I’ve never been in a position that I’ve felt I’ve needed Linux to do something
@OthmanAlikhan9 ай бұрын
Thanks for the video =)
@hasnainabidkhanzada37544 жыл бұрын
Business logic is more of like breaking or exploiting the business rules. In this case, a business rule can be to validate the input. Now if someone somehow exploit or break that rule then what it should be called? Business logic error or XSS? How business logic errors differ from other attacks like IDOR, XSS, CSRF etc. Can u please explain it?
@InsiderPhD4 жыл бұрын
Usually XSS as business logic is more "look I can change the price to a negative number" think more exploiting it working as intended, rather than validation.
@hasnainabidkhanzada37544 жыл бұрын
@@InsiderPhD So in short: Bugs not recognized as specific type can be called as business logic errors. Right?
@AnuragKumar-hv1df4 жыл бұрын
very knowledgeable video.
@InsiderPhD4 жыл бұрын
Glad you think so!
@thedevalweb5 жыл бұрын
Great content!
@ahmedezealdean61896 ай бұрын
Bussiness Logic errors are so similar to IDORS, and according the web applications hacker handsbook it a type of IDOR.
@anujkumarpatel26864 жыл бұрын
thanks great content ❤
@hanyobied87925 жыл бұрын
Many Thanks
@gene4954 жыл бұрын
what if the app is calling other 3rd party services? Does it still make sense to limit the scope?
@InsiderPhD4 жыл бұрын
Yes, we really don't want to hack a service we don't have permission to be hacking! Also if we do find a bug in that third party stuff we won't be able to report it to recieve a bounty, it's better to focus on the services we have permission to test
@sshouqq4 жыл бұрын
Your the best thank u so much
@nikhilprem79984 жыл бұрын
Need some advice I am a newbie in coding and I finished python and am starting Java is it the right time for me to try bug bounties or do I need to learn more
@InsiderPhD4 жыл бұрын
Nikhil Prem there’s never a right time to learn and there’s not a critical mass of knowledge you need to start. Just start. Just have a go. If you get stuck google what you’re unsure or ask. But you are ready right now I promise you
@shrirangkahale4 жыл бұрын
Great Content!!!!!!!!!! BTW Plz buy a new MIC audio was horrible BUT the explaination was awesome!!!!
@InsiderPhD4 жыл бұрын
I solved this in later videos!
@s4dum45 жыл бұрын
Thanks for sharing your knowledge will you continue uploading videos?
@InsiderPhD5 жыл бұрын
Yes! I'm going to continue this series designed for beginners
@Raj_darker5 жыл бұрын
Awesome !!1 Keep Posting! :)
@DEADCODE_2 жыл бұрын
it's cool but katie it's a little bit similar with Data Tampering right
@InsiderPhD2 жыл бұрын
Yes!
@testingx015 жыл бұрын
Thanks a lot Katie ! Keep up with the good stuff :) #InfosecGirls FTW
@sontapaa11jokulainen945 жыл бұрын
There are a lot of tutorials out there which tell you how you can get in to the community, what tools they use etc. but nobody actually tells any concrete examples.
@steev9105 жыл бұрын
thanks
@paulojr13842 жыл бұрын
🖖
@0xsunil5 жыл бұрын
@abhishekmorla14 жыл бұрын
who else watching this before jump into portswigger labs ?
@gastontimchuk22954 жыл бұрын
Hi this series are for a completly noob and doesnt know about programming? i really start in BBH
@InsiderPhD4 жыл бұрын
Yes! No programming knowledge or security knowledge required, just a passion for learning and a determined attitude!
@gastontimchuk22954 жыл бұрын
InsiderPhD oh so thx so much im very exited to find my first bug i watching your series and im learning a lot thanks for everything
@devdarpan35825 жыл бұрын
You are doing great job but i am just having hard time understanding your accent !!!
@InsiderPhD5 жыл бұрын
Sorry! I'm desperately trying to slow down when I speak, I forget how many non-native English speakers watch!
@danielmcpherson90624 жыл бұрын
If you need her to talk slower, just slow down the speed of the video :)
@animebros92144 жыл бұрын
i think its more the audio recording setup than the accent. otherwise great work