15:43 pentesterlab, OSCP 16:40 Mayonnaise 18:06 i run NMPA religiously, subdomains brutforcing, active reconnaissance 26:49 I can effectively read code, bash, python, curl 31:30 none of those tools would have caught that 34:58 nmap 36:00 ffuf 37:40 DNS brutforcing , resolution 46:53 bugchain 53:05 reject ? children, inti (securinti) 01:03:20... --------------------------------------------------------------------------------------------------------------- 01:06:17 you want inputs that you can put shits into... to get an ouput which is a bug 01:06:34 extend an attack surface, 01:06:51 find more dynamic content where we can actually throw bullshit into, that we can a response from, 01:07:30 web security fundamentals, burp suite ---------------------------------------------------------------------------------------------------------------- 01:10:19 burp, I use intruder 01:19:31 if you are looking for something for like half an hour or an hour and you are not getting any indicators at all there is a problem, make money, for 8 hours... refine my approach...
I've watched this interview three times already, and I will watch it again, thanks a lot Nahamsec and Naffy
@davidthumbi14633 жыл бұрын
every time I rewatch this interview it feels like its a new one,,, good content here
@SandeepYadav-vm9ur4 жыл бұрын
2 hours passed just like that, had this been for another hour, I would still watch, NOT a single moment of boredom. #Naffy pours his heart out, very upfront.
@TheLizander4 жыл бұрын
Naffy is a real bro, this was a great interview. Thanks to both of you for siting down together and getting into it
@sykotrevize4 жыл бұрын
Thanks Ben, thanks Naffy for your time, this has really been a great interview
@codeworld41723 жыл бұрын
"Just find what makes you happy and just fucking do that thing, like" - Naffy
@davidbarlage51643 жыл бұрын
I see you 2 constantly watch this interview
@dcimre3 жыл бұрын
Wow, these recon sunday interviews are just pure GOLD!
@romeoromeo7002 Жыл бұрын
One of the best interviews and many more to come in near future
@peaceofshed50062 жыл бұрын
i'm so glad for find this interview and this clever man, thank you naham and naffy
@sillydadddy4 жыл бұрын
Thanks naffy ... I searched a lot in nullcon as I heard you were there . Wish I could meet u ...
@eingengraou12884 жыл бұрын
Hey
@mangeshgupta56774 жыл бұрын
Best interview 😉 I was burning out, then I watch this content , now feeling very happy and motivated ☺️. Thank you for everything ❤️
@imshaiknasir4 жыл бұрын
Damn, this video is fully knowledge packed ..
@allurbase2 жыл бұрын
Man this interview is a bomb!
@azsx2994 жыл бұрын
Totally good dude. Cheers to ya both.
@brs2379Ай бұрын
Bro's got some good taste in music
@jarvi54 жыл бұрын
This Interview is 🔥🔥🔥💛
@holdmybeer13373 жыл бұрын
hope to see more interview with Naffy :)
@phpdude4 жыл бұрын
Awesome! Thanks @nahamsec... First to report.. Yee-haw
@blackmrx63194 жыл бұрын
Huge thanks guys 💚
@RN-kl4kp4 жыл бұрын
This is so cool ... naffy is here wowow...!
@sudosuraj2 жыл бұрын
This is pur goldmine ❤️
@karthikkumar68474 жыл бұрын
Legends ❤️
@XeTylerr4 жыл бұрын
wtf is going on in the background of this mans audio
@geekyrajnish4 жыл бұрын
creepy voices
@maxicorbs3 жыл бұрын
This is bugging me and wondering if anyone has the answer - naffy talks a lot about nmapping for ports etc. In my mind this must mean that he is scanning the entire IP range belonging to a company vs doing some subdomain recon and then scanning right? I can't see much value in scanning non-standard web ports for domain names other than the occasional time you might find something else running on a weird port. More likely, it seems he is scanning IPs for forgotten-about stuff hosted on the web that may not have a FQDN?
@6cylbmw4 жыл бұрын
@Nahamsec Im really curious what is the average time watched on these Bug Bounty Talks. I usually watch them fully 2 or 3 times while taking notes and I consider them one of the most valuable thing in the bb community. If the averate time watched in less than 30-50% then some stuff will might make sense for me.
@wi11184 жыл бұрын
Could you plz share your notes?
@6cylbmw4 жыл бұрын
Guys, my notes are really mixed up and incosistent, I personally don't want to share them. For some interview I had 3 lines of writing, when for other I had 200 random lines. I didn't even look at them once since I written them. I promise you that if I will rewatch my notes and organise them will make them public on github. For now, it will be of no use and it feels incomfortable for me to share them.
@IteLuis4 жыл бұрын
Awesome interview bro, as always, a great deal of experience being shared for the community.!!
@ivartorr14694 жыл бұрын
can you start putting timeline in the video?
@sarmedwahab72884 жыл бұрын
one day i will be interviewed👍
@chizzlemo30944 жыл бұрын
he's quite a geezer
@T3chnocr4t10 ай бұрын
Great interview
@technocrats23604 жыл бұрын
16:50 whos the guy thy are talking about?
@jethalalgada11324 жыл бұрын
Mayonaise.
@safisec4 жыл бұрын
@Nahamsec Next Time @Codecancare Thanks For Sharing!
@ricardotech4 жыл бұрын
Insane!
@romeoromeo7002 Жыл бұрын
Guys which nmap command did he type ?
@RN-kl4kp4 жыл бұрын
That's a lit song ....
@manishrana35964 жыл бұрын
good stuff
@phorthalan3 жыл бұрын
Naffy is gangster!
@faizannehal33354 жыл бұрын
Naffy is the real cool guy
@basvenis4 жыл бұрын
Real talk
@UnknownSend3r4 жыл бұрын
Does my guy have porn on the background like it's ASMR
@somebody30149 ай бұрын
41:58 nmap 1:00:00
@wisdomovermoney33942 жыл бұрын
Five accounts man. It's true hackers don't like to pay for stuff. Its about freedom.
@xudongshao89914 жыл бұрын
kzbin.info/www/bejne/i2nXdItojcSoabs Anyone understand that died CNAME bug? Did he mean that the CNAME is died and he just went to the orignal IP address? But how did he get that ip? DNS history? Thanks.
@wdai034 жыл бұрын
smart guy, at least I think so, from his thought process and everything. Not sure about him constantly showing off that shoulder tattoo though lol
@karthikkumar68474 жыл бұрын
I want to be bug bounty Hunter so bad
@shubham_srt Жыл бұрын
whats the update
@hackerstreet47024 жыл бұрын
😍😍😍😍
@kamoso50239 ай бұрын
1:20:00
@shobhitbhosure58914 жыл бұрын
He's talking about elliot alderson right 😂?
@rooney.464 жыл бұрын
Haaay
@tamjid0x014 жыл бұрын
@securidyssecuridy11914 жыл бұрын
What you said about Oscp proxy cert is good but taking India name is not correct Bro, I know lot people in other countries who got all certs but can't even understand basics.
@NahamSec4 жыл бұрын
What are you talking about?
@securidyssecuridy11914 жыл бұрын
@@NahamSec 6:00
@NahamSec4 жыл бұрын
I don't think he was saying it in a negative way. He was saying you can pay someone in another country to take the test for you.