This is really fruitful content specially when sharing those kind of information. Also when you try to get your first bug it can be little bit hard at beginning. So THANK YOU for giving us your knowledge 😎
@InsiderPhD Жыл бұрын
It IS hard, I think what sets out people who don't find a bug and people who do is literally just perseverance. You get more skilled over time but initially all you have is luck, so you've gotta keep trying!
@popo_hack Жыл бұрын
@@InsiderPhD Hello again, I am very happy to annonce you that I already found my first bug few days ago on Hacker101 Private Program. I want to thank you for your videos and for sharing your knowledge with us. Happy Hack ^^
@Aya11_Gwen Жыл бұрын
@@popo_hackwhat bug is he,How long did it take you to find this bug, I haven't harvested for four months.
@EzequielOsorio4 жыл бұрын
Super informative! Looking to start doing bug bounties; I think this has solidified IDOR’s as a good start.
@mahmoudadel197 Жыл бұрын
How did it go?
@Brutalslayer697 ай бұрын
Did u get good at it ??
@mr.kn0w1t4ll24 жыл бұрын
Yay, another Insiderphd video !!
@InsiderPhD4 жыл бұрын
Sorry! Been moving it’s super stressful 🙏🙏
@dhyeychoksi51784 жыл бұрын
Yo I was hoping today to watch your earlier IDOR video for some hacking hints for IDOR and you uploaded another one :)) Thankssss! Love your content
@santiagosurt38252 жыл бұрын
i absolutly love this video, sharing your methodology is gold valuable for begginers! thanks!
@noelomondi48493 жыл бұрын
Do you mind sharing a spreadsheet with some of your testcases? That would be helpful for us beginners
@nathangriffiths88094 жыл бұрын
Great video Katie!! Cheers!
@dailygamba777 Жыл бұрын
Amazing! by the sound of it you are very young but alot of teachers could be jealous of your teaching skills ! Good job
@hermajaystey Жыл бұрын
I appreciate your content so much! And thank you for sharing your bugs with us lol
@davidt014 жыл бұрын
I found an IDOR + XSS vulnerability, but it was a duplicate :(
@InsiderPhD4 жыл бұрын
Aww that sucks, hopefully you’ll be first next time!
@INJECTED294 жыл бұрын
Got a bug yass Got a dupe yaaasss Keep trying it will get better with time
@jeffer7463 жыл бұрын
@-メAjax he's probably be a prime suspect in the crime since he literally went to the devs and told them he knows this exploit
@Factotum-b7h3 жыл бұрын
You should be happy about finding it, no matter whether you were the first or not. Well done!
@llmpixart4 жыл бұрын
marvelous! Thank you for the upload.
@SrRunsis3 жыл бұрын
Mesmerizing content Kate! Thanks :)
@rajatdutta83654 жыл бұрын
Thanks for sharing. Waiting for more.
@franz3810 Жыл бұрын
thank u Dr for these videos!
@ronetteprinsloo50484 жыл бұрын
I hope I can one day be good enough to find some bugs 😅
@InsiderPhD4 жыл бұрын
Practice, practice, practice. Never stop learning, always try to hack and I’m sure you’ll find something!
@lp49693 жыл бұрын
We're all on the same train let's keep the grind!!
@mahmoudadel197 Жыл бұрын
How did it go?
@Frawkesish Жыл бұрын
@@mahmoudadel197how's it going for you ? 😅
@starlox011 ай бұрын
Me too
@ch1nmqy1324 жыл бұрын
I just started IDORS
@groeneappel78424 жыл бұрын
YEEYYY IDORS, I've been focusing on Idors for my first bug s
@animazing10024 жыл бұрын
Have you found one yet?
@groeneappel78424 жыл бұрын
@@animazing1002 only a dupe
@zoroatokpas87614 жыл бұрын
@@groeneappel7842 still you found < cheers
@vukovic17563 жыл бұрын
did you find any yet
@SecurityGau4 жыл бұрын
Great Video for Beginners Katie keep it up.
@fahadfaisal23833 жыл бұрын
I am 15 . Trying to get my first bounty. Wish you have great days ahead.
@dev__0042 жыл бұрын
Found anybug?
@fahadfaisal23832 жыл бұрын
@@dev__004 bugs for 3k
@dev__0042 жыл бұрын
@@fahadfaisal2383 I started 1 yr ago and learned fpr 2 months stopped and started now again and got 3 duplicates. Any tips for me brother
@fahadfaisal23832 жыл бұрын
Brother, I am not that pro to give advice to you, but I need to automate your tasks avoid duplicates.
@dev__0042 жыл бұрын
@@fahadfaisal2383 got any social media handles and also can u mention some of the tools u use. Thank you brother
@jamesgaray76253 жыл бұрын
Thank you !!! for always making good videos
@ITHD1 Жыл бұрын
Thanks for ur great efforts 🔥
@ultronhack81514 жыл бұрын
Just love the way u present, Love from Bangladesh
@Stinky_room3 жыл бұрын
Can you explain what you mean when you say endpoint? Do you mean the functionality of the webpage? (Update, delete, add, etc..) Or do you mean like a physical device like a server?
@InsiderPhD3 жыл бұрын
Endpoint in this case is URL that does something, now years ago this would mean a file that exists but modern web apps use something called routing so each URL doesn’t necessarily map to a file, hence calling them endpoints
@MooshNj4 жыл бұрын
Kindly create a video about hunting IDORs with Burp Suite Autorize extension
@hoangsatfe2 жыл бұрын
Thank you so much. I really love video for you!
@mageshsal10154 жыл бұрын
Hyy you've given me a good idea for how to look for bugs, since my findings all are duplicate 😅
@diegogomes71792 жыл бұрын
Awesome job!!!
@TheDamoo913 жыл бұрын
Katie I'm new at this. I found in my first week a bug that has no real impact (from my point of view). Changing the parameters on a "delete user request form" from user "A", putting the ID of user "B", it sends the "confirmation to delete user B" mail to user "B". But user B can ignore this mail and nothing happens. Should I report this?
@InsiderPhD3 жыл бұрын
No, this is expected- User B doesn’t have to action it and since it sends an email that provides another layer of security
@hammadzaki75342 ай бұрын
Thats called content❤❤❤❤
@AhmedSalah-fi3dt3 жыл бұрын
Hello Katie, if changing session_id user (a) with session_id with user (b) shows his inbox, is it an IDOR?
@monishbasaniwal16873 жыл бұрын
Nope, session IDs in itself are authentication tokens hence that is just how the website works. Hare supplying As credentials to B
@eduardj-e8x4 жыл бұрын
thanks Katie!
@nelly49213 жыл бұрын
Do you mind sharing a sample of the spreadsheet you use cross out what you've
@akasJha3 жыл бұрын
the chuckles behind base64
@Factotum-b7h3 жыл бұрын
Thank you!
@mohittirkey78894 жыл бұрын
Amazing video Katie specially with those doodles and animations texts, I wanted to ask for test case-4 i.e Firefox Containers , if there is an IDOR with exchanging cookies , how will the attacker steal those cookies from the user until and unless its a XSS . As I submitted 1 bug using the cookies and it was closed as N/A as the triage team asked how the cookies will be stolen from the user.
@InsiderPhD4 жыл бұрын
In this case we use the cookies of account A to make changes to something owned by account B, showing that any user could affect any other user. Sorry if this is unclear it’s a quick way to test if we logged into one account if we could make changes on another! I will make this clearer in a future upcoming video! But to use your example this is a great example of when bug chains can be key to getting a high severity, by, as you say using an XSS, which can be chained into a full account takeover!
@mrvDn2 жыл бұрын
@@InsiderPhD hii Ive got the same question from twitter, asking me how you would get the cookie and csrf token of the victim..
@ashleypursell97024 жыл бұрын
awesome video once again, thanks for the secret sauce
@aswincp40534 жыл бұрын
While doing subdomain enumeration, i got 502 error from cloudfront .Is it possible to do a subdomain takeover in this case?
@sIightIybored4 жыл бұрын
Great Video!
@Alexander007A Жыл бұрын
i fully understand the idor concept but i didn't know where i can put my practical skills?? how i will find bugs? where i can find it? which website i will use for it? no youtube channel tells us how to find actually>>>>
@InsiderPhD Жыл бұрын
Large API! Yahoo, tumblr uber, open sea etc just look for APIs on HackerOne
@Alexander007A Жыл бұрын
@@InsiderPhD Well thank you ma'am.. I'm now learning it.. but can you make a video about it how to find IP in Website through hacker one please coz I'm almost done just need one step closer to real world
@Abhi-kp1fs4 жыл бұрын
Hello, I have a doubt At 8:10 , you need to have access to two cookies so it can only work if both accounts are owned by you right? Is that a vulnerability? Because you are accessing your own account then right?
@InsiderPhD4 жыл бұрын
Yeah, but what we're demonstrating is that we can do something User A's account, while logged onto to User B, so we could use the vulnerability to change any account. We use 2 accounts we own because usually program rules forbid you from accessing any other users account but ones you create. Hope that helps!
@Abhi-kp1fs4 жыл бұрын
Thank you for the reply! But for this to be a potential threat, wouldn't an attacker need to know the victim's cookie?
@InsiderPhD4 жыл бұрын
No because we swap the cookies: Step 1: perform an action on User As account Step 2: repeat or intercept the request Step 3: Change the cookie from User As to User Bs Step 4: Did it work? If yes it’s an IDOR We never use User As cookie apart from to do the action to capture the request in Burp, then we replace it to simulate an IDOR
@Abhi-kp1fs4 жыл бұрын
Oh okay now i understand. Thank you for clarifying! 🙂
@smitpatel58684 жыл бұрын
thanks katie
@WebWonders12 жыл бұрын
Really appreciate
@bradleyadleman24044 жыл бұрын
Great video, thanks for sharing your methodology, it's very helpful!
@psm8764 жыл бұрын
Inspired by you... Been a week finding idors... Didn't found any😅 but still looking... I just hope find one soon... Starting to lose motivation...🤒
@no1sploit5293 жыл бұрын
Any Updates?
@thebrotherhood16754 жыл бұрын
whats the process of contacting the company, they obv must have a VDP in place? (if so, is there a list of companies with VDPs out there that you go through?) and then you simply contact the company and send a report of the vulnerability you have found? also how is payment amount decided? (are the details stipulated in their vdp?) thanks for the vid :)
@InsiderPhD4 жыл бұрын
I would only hack on bug bounty platforms like Intigriti, HackerOne, BugCrowd or Synack- simply because it’s 100% legal and safe. For a list of VDPs try disclose.io
@bharathpatel17573 жыл бұрын
Hi dhidhi ! I started learning about bugbounty from last 3 months I'm on full swing on this thing started doing labs on websecurity academy but i am so afraid dhidhi like to do this things like I am afraid of getting caught . After learning everything Can I implement same thing in intigriti platform and other bug hunting platform ? Is that same what I learnt from web security academy ?? I'm afraid to start hunting in intigriti please suggest some tips to how to stay safe in this ride please
@davidg94694 жыл бұрын
Have you seen the new INE cyber pass? What's your thoughts on it?
@InsiderPhD4 жыл бұрын
I had not seen it, I googled it, here is my reaction: "Oh buy a year get another free? That's pretty good, how much does it cost- JESUS CHRIST that's expensive"
@InsiderPhD4 жыл бұрын
At that price point you're better looking at more established qualifications that specialise you, rather than trying to take every certification you can
@shanehonor24234 жыл бұрын
I'm a 20 yrs old BSIT student, but only know "hello world". 😔 I really want to learn things like this, but it's so hard.
@andreslauga4 жыл бұрын
It's difficult until it's not! So keep pushing! :)
@robinhood38414 жыл бұрын
There are nothing that you cant do We all describe any thing we dont know as a hard thing, untill you know it and understand it you will laugh about your self in the past
@shanehonor24234 жыл бұрын
Thank you so much😊❤️
@nishant88804 жыл бұрын
IDOR...IDOR....IDOR.... HODOR!! edit: this was so offtopic, but I couldn't resist.
@youtubeuser77174 жыл бұрын
Why?
@sirgesound4 жыл бұрын
Love the instruction in your videos..🙂👍🏽👨🏾💻
@0x1h0b4 жыл бұрын
Hey katie.. your videos are amazing ! ....... can you please share the slides? ... thank you
@Mohsinkhan-bh7py4 жыл бұрын
Awesome keep it up :)
@Safvanviber Жыл бұрын
Vertical privilege escalation 😌
@aswincp40534 жыл бұрын
What are the most common vulnerability that gets paid?
@InsiderPhD4 жыл бұрын
HackerOne publishes that data! They posted this in the last few days: www.hackerone.com/top-ten-vulnerabilities Currently XSS is on top, followed by Improper Access Control and Information Disclosure. But the thing to look for is % change, that tells you which bugs are becoming more common: Improper Access Control, SSRFs and IDOR might be the bugs to keep an eye out for in the next few years!
@aswincp40534 жыл бұрын
@@InsiderPhD IDORS are hard to find 😵most probably all of them look for those.
@hacklikeAgbaby9 ай бұрын
A new subscriber
@7he7hief954 жыл бұрын
Katie i love your style. *mau
@RyanGiggs-w7i6 ай бұрын
just be honest. I'm frustrated about bug bounties
@theologos37053 жыл бұрын
Idor with cookies is out of scope for the most companies?
@InsiderPhD3 жыл бұрын
It shouldn’t be? It’s just a easier way to demonstrate an IDOR exists
@alph4byt34 жыл бұрын
we shouldn't forget about the IDOR that weev found in AT&T Ipads that landed him in Jail
@killabite6204 жыл бұрын
What happened to that guy
@tealeaf92604 жыл бұрын
@@killabite620 He's been involved with The Daily Stormer. Far-right, antisemitic, white-supremacist stuff, basically.
@mujtabam2653 жыл бұрын
Please pin the recommended prerequesites in comment or somewhere! ( 1:58 )
@Rashedulcss4 жыл бұрын
Awesome...!
@DEADCODE_2 жыл бұрын
I love you dude
@faique29954 жыл бұрын
loved it
@peter77704 жыл бұрын
how can i follow you o hackerone?
@InsiderPhD4 жыл бұрын
My username is Insiderphd but I mainly hunt on private programs so I don’t have any disclosed bugs yet!
@peter77704 жыл бұрын
@@InsiderPhD ok mam thanks for the reply😇
@RealLilNword Жыл бұрын
Finally a non-Indian guy on KZbin :D
@cyberpirate0074 жыл бұрын
Got an Heart Attack after seeing this video template.... Thank God I'm Alive now x_x
@rafinrahmanchy4 жыл бұрын
Is it worth to find IDORs nowaday?
@InsiderPhD4 жыл бұрын
I found 2 IDORs a month ago for $500 + $250 :)
@rafinrahmanchy4 жыл бұрын
@@InsiderPhD it mostly depend on luck. Since it's easy to find and exploit, it's hard to find. There's high chance of getting duplicate for such basic vulnerabilities.
@0xx0394 жыл бұрын
@@rafinrahmanchy Not all IDOR's are easy to spot some IDOR's requires deep understanding of the application/id's/parameters/enpoint's.
@rafinrahmanchy4 жыл бұрын
@@0xx039 everyone have understanding on them. No need to mention. Still it's hard to make bounties out of it.
@AmitChauhan-sp1cw4 жыл бұрын
I am getting demotivated because I am not getting any bugs.........oh Katty plz help.....:-(
@AnujSharma-yv6gy4 жыл бұрын
Same here bro!😂 But patience and consistency is the key.
@shrirangkahale4 жыл бұрын
*Katie
@ReligionAndMaterialismDebunked Жыл бұрын
weirdness*
@ameer29423 жыл бұрын
She speaks like the algoexpert guy
@AjayKumar-xl4jc4 жыл бұрын
>super content (nice$
@malikimranawan37624 жыл бұрын
love from Pakistan
@j4ck_d4niels3 жыл бұрын
youtube :)
@yashwanthd19984 жыл бұрын
Educative..but don't make people believe finding bugs is easy if its easy everyone will do it...