How I Found My First Bug (now you can too)

  Рет қаралды 61,226

The Cyber Mentor

The Cyber Mentor

Күн бұрын

Пікірлер: 58
@gerardocovarrubias7610
@gerardocovarrubias7610 Жыл бұрын
The script and integration with discord was really interesting, share more please!
@bigerrncodes
@bigerrncodes 5 ай бұрын
Seconded! Please post a vid on the script!
@WR4lTH
@WR4lTH 9 ай бұрын
Automation seems to be the secret sauce that most hackers don’t want to share because this how they are finding their bugs. A video on setting up basic automations for an overall bug bounty hunter would be appreciated. Thanks for all you do
@UBNA671
@UBNA671 3 ай бұрын
i would like to know more about finding bugs with automation if possible
@kawaiihikari0
@kawaiihikari0 2 ай бұрын
Ehh I kinda agree manual testing will always be superior for “majority" of things. Automated tools bring up errors or false positives when if you tested manually would have been able to tell. I think a mix between the 2 works best not just a one way approach
@UBNA671
@UBNA671 2 ай бұрын
@@kawaiihikari0 I like to think that automated testing is just to find and manual is to confirm so I agree partly with what you say
@dxxp3835
@dxxp3835 2 ай бұрын
​@@UBNA671 If I tell you with my experience Learn Go for mannual testing and make those steps into automation
@sino-wt7pu
@sino-wt7pu Ай бұрын
​@@UBNA671 Well some bug bounty programs also don't allow automatic testing or only within given rules, like imposing rate limits on scans. Or some are completely banning certain scanning tools, for different reasons. I have also seen a program description, where automatic scanning tools were forbidden, except running your own scripts, then with some rate limiting of like 5 requests per seconds. So they don't want like 1000 people automatically scanning for the same vulnerabilities over and over, just stressing the servers.
@Blentux
@Blentux Жыл бұрын
My first "bug" was an IDOR vulnerability on my school's internal website. I found it by accident and I didn't even know what IDOR is back then, I just found it funny being able to access information about every student's profile. My second bug on the other hand was a XSS vulnerability, I again found it by accident. The login form of a website was reflecting the entered username and it wasn't being sanitized. I really don't know much about pentesting, but it was enough for being able to find vulnerabilities 😅
@mayank-ir7tm
@mayank-ir7tm Жыл бұрын
Great video! A tutorial about script writing for automation would be appreciated! I am a bit stomped whenever i need to automate stuff so thank you!
@JohnRodgers7390
@JohnRodgers7390 Жыл бұрын
Would be very interested to see how that script and integration with Discord works. Thank you as always for the in-depth information.
@LoosenRelaxation
@LoosenRelaxation Жыл бұрын
We Want Full Play List
@ronetteprinsloo5048
@ronetteprinsloo5048 Жыл бұрын
Second this
@AM-mv6ro
@AM-mv6ro Жыл бұрын
Please and thank you*
@hyperFOCUS42
@hyperFOCUS42 16 күн бұрын
My first bug was discovered while working as a run-of-the-mill QA engineer: A voice assistant was set up improperly with the insult library (meant to trigger fallbacks in case of rude user behavior) hooked into it stemming from the wrong localization package, so fallbacks from insults in the target user language were never triggered.
@ShaySoFresh777
@ShaySoFresh777 Жыл бұрын
Hey Alex. I myself would love to see a video on that automation tool and discord integration!
@Blecyn
@Blecyn Жыл бұрын
Great topic. I want to see more Bugbounty adventure and would look to check out the TCM api course
@alexandersoltesz8103
@alexandersoltesz8103 Жыл бұрын
Great video, I added your methodology to my to-do on new targets, thanks so much! Also I'd love to see your automation script for analyze, I haven't heard about it but I'll surely check it out and likely integrate it too!
@PeterAdiSaputro
@PeterAdiSaputro 9 ай бұрын
Thanks for the great advices that may useful in all aspects of life, not only hacking or bug bounty.
@breakoutgaffe4027
@breakoutgaffe4027 5 ай бұрын
Yes please to the automation script content - how can one monitor the target for new endpoints without running a heavy scan like kiterunner every x days?
@youcef2851
@youcef2851 Жыл бұрын
thanks Alex this is great
@Z0nd4
@Z0nd4 Жыл бұрын
Great video Alex! I wait for the automation/discord-bot video! Thanks man!
@prabakarj4797
@prabakarj4797 Жыл бұрын
As usual a great stuff! I want more videos on bug bounty🙌🏻🙌🏻
@UBNA671
@UBNA671 3 ай бұрын
i would like to know more about finding bugs with automation if possible
@lauleshmishra6143
@lauleshmishra6143 Жыл бұрын
Want to learn more on how to write scripts and how can we identify if the app is using prepared statements
@GrimComix
@GrimComix Жыл бұрын
Yes on the Discord script 👍🏼
@ssxnet2513
@ssxnet2513 Жыл бұрын
Great video!! I am also on the way to find my first bug..... I was second😂😂
@abdulmannan3454
@abdulmannan3454 Жыл бұрын
Yes, I would like to learn the automation part please
@_CryptoCat
@_CryptoCat Жыл бұрын
Nice! Video on the discord automation would be cool 👍
@nnofficial2414
@nnofficial2414 4 ай бұрын
Great video!
@TheBenJiles
@TheBenJiles Жыл бұрын
Great video. Thanks
@OthmanAlikhan
@OthmanAlikhan 7 ай бұрын
Thanks for the video =)
@mssvbeats4070
@mssvbeats4070 Жыл бұрын
Where do you talk about actually gaining access to a target to attack? I think alot of us have no idea how to join a bug bounty or gain access to a website that we are allowed to attack
@lstr0
@lstr0 Жыл бұрын
Thank you for the great content, but a while ago your videos were showing me with Arabic translation, and then they stopped completely. Can you add the Arabic translation? There are people who are serious about learning from you their language is Arabic❤
@AppSecExplained
@AppSecExplained Жыл бұрын
All the subs are generated by KZbin, we don't add them ourselves. Hopefully it will come up automatically though after a day or two!
@lstr0
@lstr0 Жыл бұрын
​Thanks for your reply, really appreciate your powerful content🖤💻
@akilabejaia8428
@akilabejaia8428 11 ай бұрын
4:13 yes please
@amoh96
@amoh96 Жыл бұрын
we want playlist about bug bounty
@chowdhurytowhidahmed7780
@chowdhurytowhidahmed7780 Жыл бұрын
More bug bounty video
@MFoster392
@MFoster392 Жыл бұрын
Defiantly need script a info in python and bash
@kalendra.ethicalhacker
@kalendra.ethicalhacker 7 ай бұрын
I always getting duplicates
@faizanshaikh2588
@faizanshaikh2588 Жыл бұрын
We want the how to write script video
@sayemjency1304
@sayemjency1304 Жыл бұрын
Please share tutorial about scripting with Discord...
@sourabhpurohit8575
@sourabhpurohit8575 Жыл бұрын
Please make a video on automation using scripts.
@alexadvanceautomechanics
@alexadvanceautomechanics 11 ай бұрын
Can u do one for beginners from scratch at bugcrowd
@UmmeLP
@UmmeLP 7 ай бұрын
i would love to see that discord skript :)
@crazy_pythonist
@crazy_pythonist Жыл бұрын
my first bug-bounty was when I was child and my grandpa was like to say 'hey boy I'm 64 but I'm waking up at 5am every day and feeling as good as my 20ies ' - also my grandpa during whole day 'sleeping at sofa,napping at the table,going bed at 6pm😅😅😅 '
@technicalskillsintelugu2286
@technicalskillsintelugu2286 Жыл бұрын
Hey I want to learn this cource but I don't known can u tell how can I start
@alexadvanceautomechanics
@alexadvanceautomechanics 11 ай бұрын
Do u have automated scripts
@shadowshan125
@shadowshan125 Жыл бұрын
create a video for script and integration with Discord
@mlitzy
@mlitzy 10 ай бұрын
please share the script and integration with discord
@deepaknishad5272
@deepaknishad5272 Жыл бұрын
Pl help mi my Facebook ac hack
@schooltime001
@schooltime001 Жыл бұрын
I want to learn from you, will you help me?
@ruycr4ft
@ruycr4ft Жыл бұрын
First!
@criggyartist
@criggyartist Жыл бұрын
Second 😂
@AbhishekGupta-fz5dn
@AbhishekGupta-fz5dn Жыл бұрын
Great video and yes please make a video on how to make security tools like gobuster and all. Much appreciated.
@mohammedessam7829
@mohammedessam7829 6 ай бұрын
The script and integration with discord was really interesting, share more please!
How much money I made in my 1st year of bug bounty? Bounty vlog #4
17:02
Bug Bounty Reports Explained
Рет қаралды 152 М.
Touching Act of Kindness Brings Hope to the Homeless #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 18 МЛН
when you have plan B 😂
00:11
Andrey Grechka
Рет қаралды 30 МЛН
2023 Path to Hacking Success: Top 3 Bug Bounty Tips
26:37
David Bombal
Рет қаралды 72 М.
Appsec Careers in 2023 (is bug bounty right for you?)
9:40
The Cyber Mentor
Рет қаралды 10 М.
I Played HackTheBox For 30 Days - Here's What I Learned
10:23
Grant Collins
Рет қаралды 397 М.
The Best and Worst of Hack The Box
13:53
The Cyber Mentor
Рет қаралды 6 М.
Easy $500 Vulnerabilities! // How To Bug Bounty
13:19
NahamSec
Рет қаралды 71 М.
How to Access the Dark Web Safely
15:22
The Cyber Mentor
Рет қаралды 1,8 МЛН
Bug Hunting is easy if you KNOW this
8:23
Bug Hunter Labs
Рет қаралды 24 М.
Live Hacking Tutorial: How to Think Like a Bug Bounty Hunter
33:40