after 1 mouth studying I decided to really look for the bugs and in 1 one mouth I found 3 types of bugs in one website, and today I found another in other site, if you study everyday and really look for the bugs you'll find it
@senlin94145 ай бұрын
You found the bug after only studying in cybersecurity for a month?
@YuriFsilva205 ай бұрын
@senlin9414 Yeah, it's really easy to find, actually. Start with simple bugs that they forget to look for because they think it's not so important
@senlin94145 ай бұрын
@@YuriFsilva20 thank you!
@GMk__4 ай бұрын
@@YuriFsilva20 bro i just started too. can i reach u from somewhere? maybe we can collaborate and share our knowledge to each other
@aspirant-uy8lv4 ай бұрын
@@YuriFsilva20hey actually i am a total newbie to this. I wanna become a bug bounty hunter. I am at square 0. Can you pls give me a roadmap to follow or rather what you did??
@ransomhades4 жыл бұрын
Man this dude is speaking the truth that everyone needs.
@sul3y4 жыл бұрын
Damn right, he literally know every aspect of this topic.
@WildberryAB4 жыл бұрын
I had no idea what a bug bounty was. I was in the bathtub when this video came on and I didn't want to get out so I just listened. What ensued is hands down the best and most useful psychological and motivational advice I have ever heard in my life. So while I may never be a bug bountier, I want to thank you so much for your words. You are brilliant. I have been procrastinating forever and will not start anything, but now I know how to begin for real.
@hakluke4 жыл бұрын
Wow that is so great. I really appreciate you leaving this comment. It's made my day! If you like that, I've posted some other non-bug-bounty stuff on my KZbin channel that you'll probably like also!
@trieulieuf93 жыл бұрын
Dude, lol.
@azersd67782 жыл бұрын
@@whatevermusiciwant I don't think he did xd. anyway I'll leave this here so hopefully in one year someone will comment and check on my state like u did to @WildBeerry xd I'm starting my journey in bug bounty now 2022/05/06 with no 0 experience I'm a computer science student, All I know is just some coding and Linux. Wish me luck passengers ;)
@amit-mishra2 жыл бұрын
@@azersd6778 Ok I like this idea I would also do a date punching let's see what happens one year later. Date 7/08/2022
@maheshchaudhari58692 жыл бұрын
@@azersd6778 2 months left make it happen
@hakluke4 жыл бұрын
Hey!
@hackersden68174 жыл бұрын
Osm man i love it ❤
@wrx-qs8be4 жыл бұрын
Thank you so much for this :) ! And thanks to the community
@shrirangkahale4 жыл бұрын
Hey!!
@amitabhmondal12984 жыл бұрын
Such an amazing video, the depth that you go into for these topics really adds a human touch to this content. Thank you :)
@BabarKhan-nv9es4 жыл бұрын
Thanks mate for the time and experience sharing
@majamoore62092 жыл бұрын
Your whole point on the fear of starting was so well articulated. I have been suffering from this, but have not been able to identify and articulated it. Thanks for the pep talk!
@DashDapper2 жыл бұрын
5 minutes in and this is exactly what I needed to hear.
@jenniferwood49163 жыл бұрын
I'm just gonna save the pep talk at the beginning for all the times I get down on myself lol
@oghenejivwe36054 жыл бұрын
Thanks for this talk..I learnt alot. I started bug bounties in Jan, doing it part time though.. haven't gotten any bounty yet! But contents like this keeps me going
@rwa95733 жыл бұрын
Now do you get any bounty or not?
@metua3 жыл бұрын
What about now?
@oghenejivwe36053 жыл бұрын
@@metua lool.. been off for a while bcus of cryptocurrencies.. if I get back to bounties now, the motivation would be fun not money
@shockblockjohnson45992 жыл бұрын
One thing that doesnt get discussed is the legal risks involved in doing bug bounty. How do you protect yourself legally?
@orionblu32 жыл бұрын
@@shockblockjohnson4599 stay in scope
@i_am_ahacker4 жыл бұрын
The talk i desperately needed thanks Luke and everyone..
@lukejstephens4 жыл бұрын
Awesome :) No worries!
@ethisfreedom2 жыл бұрын
@@lukejstephens imposter
@domss11744 жыл бұрын
I wish luck to all the future bug bounty hunters. it is a tough road. I've spent 1 year trying my best to get bounties but only got dupes, Idk if I'll get at it again, it takes a LOT of time xD
@perrymaclamjr27114 жыл бұрын
Would you do it the same way you have been, or would you do something different?
@hakluke4 жыл бұрын
If you decide to get back into it - I think I know what would help, DM me somewhere :)
@TJay1453 жыл бұрын
1 year later, I'm in a similar situation. I want to start again but it seems so daunting
@deshyvin Жыл бұрын
Dupes mean you did find a vuln though. Keep your head up. The first year or two are all about training and exp. That same vuln might not have been found yet on a newer app. As well as if it's a simple exploit you can cross it off your list of capabilities and start to progress on more complex pursuits
@vincenthan81564 жыл бұрын
This is the best talk I have found on KZbin! Thanks.
@hakluke4 жыл бұрын
Thank YOU!
@vijaynariyal98183 жыл бұрын
i think , my starting goes wrong before viewing this. such a inspiration video for me to build my bug bounty career.
@Timm20033 жыл бұрын
Thanks, it helped me a lot! Its more motivational than any of these business guys who tell to start with anything and get rich fast.
@binswifa33734 жыл бұрын
I was shocked when he say " log out from KZbin and turn off your phone" i was like telling me " drop out from university " All in all good stuff bro, as always
@hakluke4 жыл бұрын
Thanks Bin!
@KeithLburns4 жыл бұрын
Well if say drop out of university
@hydroflows4 жыл бұрын
I've been comfortably and consistently doing bug bounty related work for two straight weeks now for 10+ hours a day. I'm starting my third week with a realistic glimpse into the world I'm diving into :) I'm in love with this work. It's incredibly fun and it compliments my insatiable need to figure something out. Not to mention, security research is exactly why I got into computing in the first place and that was in 2015. I've worked for so long to learn the basics and now I'm finally here soaking everything up like a kid at Disney World. Like I said, I'm in love, and I can't get enough of it. I'm excited for the year ahead.
@hakluke4 жыл бұрын
I know the feeling you're describing :) It's great! Ride the wave!
@nickthiru3 жыл бұрын
You are actually describing me and my situation! haha. It's a great feeling, yes! Congrats! When you mention the basics that you were learning from 2015, could you share what you were learning? Thanks!
do you have the video for the application analysis by jason hadix
@ThingEngineer3 жыл бұрын
One possible way to avoid burnout, diversify. I find that freelancing developing web applications is a great distraction and it gives you the chance to apply your unique skill set as well as learn more about your targets. Then you can turn right around an offer cyber security services to your new web application client.
@mianashhad9802 Жыл бұрын
Great idea! That's what I have got in mind as well. I want to make some income alongside completing my degree.
@immortalgaming32283 жыл бұрын
I came to learn how to get started with bug bounty but in addition to it I ended learning how to live a life.
@shantanudash74 жыл бұрын
Really good talk. Was really motivated and provided a lot of guidance.
@user-su7fr5jv5t4 жыл бұрын
Very good and informative talk. Thank you for taking the time to make it.
@hakluke4 жыл бұрын
Anytime :)
@AndrejMoharWeb4 жыл бұрын
Beautiful talk! Extremely informative ideas, the automation part really got me thinking...
@hakluke4 жыл бұрын
Thanks Andrej :)
@himanshuchavda98524 жыл бұрын
great
@himanshuchavda98524 жыл бұрын
great
@himanshuchavda98524 жыл бұрын
great
@himanshuchavda98524 жыл бұрын
great
@TomHimanen2 жыл бұрын
Thanks for reminding me of Netflix. I was gonna start bug hunting but then I remembered that I just need to bingewatch the last season of The Queen of South. 😎
@GrinderLewis5 ай бұрын
Damn, he is spitting the fact🔥 Thanks, g!
@Bugcrowd4 ай бұрын
🙌
@razorednight4 жыл бұрын
He said "Turn off KZbin," so I turned it off... and now I don't know what he said next!! 🙃
@TheJacampb4 жыл бұрын
"Forget everything you know about slip covers!" so I did!
@maven60934 жыл бұрын
Ran to comments to say this but u beat me there :(
@udayshelke214 жыл бұрын
🤣🤣
@MokshitKalRa2 жыл бұрын
How did you wrote the comment !! 🙃
@ToThoseWhoVanished2 жыл бұрын
Then you turned yt on n wrote this comment.
@humanflybzzz45684 жыл бұрын
Hey there, thanks for sharing guys..... Could you give us newbs some advice about how not to drift out of scope during a bounty hunt? I realy think that would be valuable to a lot of folks.
@hakluke4 жыл бұрын
If you're using burp suite, you can set the scope there. That's a good start.
@aporcescu2 жыл бұрын
Great speach, everything was explained nice an clear. However, may be I missed it, how do you actually monetize your findings ? Was explained where to start, to be consistent.. but didn't quite understand, what do you do with your findings ? For example, you are scanning an application for vulnerabilities. You found one. What do you do with it ? Do you sell it (where !?), do you publish it somewhere and wish somebody just pays you, you alert the application company and pray for a paycheck ?(what if they were not ok with you sniffing around :) ) A little bit more explanation on this topic would be wonderful
@deshyvin Жыл бұрын
Feel like utube is not letting me answer you
@batuhanbatuhan64453 жыл бұрын
I have been listening to the guy for 42 minutes he said from zero to expert at the beginning yet he didn't explain what does a bug bounty hunter actually do to get paid. He talked super confident about the income I don't get it. Isn't each bug custom? How can you automate it? If it is as easy as what an automated piece of software get it why don't do companies do it? I thought you would do recon and try break something in a way the developers couldn't think of and then break it in a way that would concern the company enough to pay you for keeping quiet until they fix it. How can you automate that? I was expecting to hear about different kinds of attacks and attack surfaces etc. He hasn't touched the core of it yet. Give us the honey bro. Dealing with where to keep the logs of the recon is vanilla.
@cywer59202 жыл бұрын
The honey is that you have to search it for yourself. Being a bug hunter is all about research and researching should be one of the things on top of the list. He mentioned PentestersLabs and other resources and people to learn from but the bread and butter all begins with you doing your research on what works for you.
@Inexizp5 күн бұрын
he basically gave you the mindset.. and some tips. like learning to automate some bugs into your recon phase on the target. the honey is everywhere you just have to get it hackers on twitter LinkedIn and info-sec community they keep on sharing great tips you'll have to connect the dots of course But how can you do that when you burn out or run away from the things you don't know and yet procrastinate repeatedly. blogs write-ups bug reports are everywhere BUT the Support and the feeling of being able to learn from them and build your own way through it is what makes great from average
@aleph_prime4 жыл бұрын
Those "phases" are totally a matter of perspective. The guy didn't predict anything at all. Also, being Bugcrowd employees it's hard to really take all this information and run with it. I mean he even says he hit his goal after getting employed by Bugcrowd. I'm sure cows think milk is great.
@gickygackers3 жыл бұрын
I think this is the attitude of a 6 figure salary
@محمّد.093 жыл бұрын
Automation of happy birthday was funny.
@true_tamilan3 жыл бұрын
you truly. motivated and ironically it still lasts after 4 hrs
@weldmaster804 жыл бұрын
Hackers always have the best names
@AustoAU4 жыл бұрын
I like that the sign keeps getting flipped haha
@KeithLburns4 жыл бұрын
Same
@tisper12 жыл бұрын
That was bloody sensational
@stevejones3712 жыл бұрын
Wow - what an honest presentation of your knowledge! Thank you and God bless ALL of your endeavors.
@Najumulsaqib4 жыл бұрын
Kudos Hakluke. You nailed it!
@hakluke4 жыл бұрын
Thanks Najam!!
@zer0k4ge4 жыл бұрын
Slow and steady wins the race.
@محمّد.093 жыл бұрын
I realised it very late.
@Thiago1337 Жыл бұрын
That's a duplicate
@geronimoswolf4 жыл бұрын
thanks mate, wish you all the best!
@hakluke4 жыл бұрын
Same to you :)
@sinwolf55394 жыл бұрын
Great talk Luke !!!
@hakluke4 жыл бұрын
Hey! Thanks SinWolF I hope you're well
@NicholasMarkovich4 жыл бұрын
Fantastic guide. Could be bolstered with some additional resources to guide newcomers on how to do the things you've recommended.
@SamarthVerma1884 жыл бұрын
Thanks hakluke for the video I got a great guidance from you
@hakluke4 жыл бұрын
That's awesome! no problem!
@nickdelgado14 жыл бұрын
Great talk...very informative and helpful!
@tomdwane78213 жыл бұрын
Such a beautiful soul. Thank you Luke
@rushi123ful4 жыл бұрын
Thank you Very Much for this Video..its really great and informative..keep it coming :)
@hakluke4 жыл бұрын
Thanks Rushi!
@ritiktrivedi37893 жыл бұрын
I don't need money from this field I just love to do so I'm learning ❣️
@Man0fSteell3 жыл бұрын
thats cute. send me the money then if dont want it :)
@fearzzzz2 жыл бұрын
Nice one, good talk.
@h4ck0rman4 жыл бұрын
This guy did his target audience research
@hakluke4 жыл бұрын
:)
@anas1r2 жыл бұрын
Great talk. By the way how many of us noticed @cje at 1:14:41 lol :)
@Thescienceworld6522 жыл бұрын
hey , i started this video right now ,. before that i want to tell u i am exploring this field since last 2 years but did not get a single vulnerbility in any target website.
@ralphruiz77843 жыл бұрын
Thank you so much for sharing!!!!
@abdullahtanveer3162 жыл бұрын
everything you said about "fear of starting" I'm experiencing almost all these things these days.. I always think is it worth to invest my time in this or I should do something else that can help me earn handsome amount to bare my educational expenses. I'm just stuck at starting point..
@techsahabi17252 жыл бұрын
THANKS #HAKLUKE...Amazing suggestions....I am starting from may 12 ,2022....Let's see what I got...
@parthdeshpande67678 ай бұрын
Hows it goin dude
@cassling28913 жыл бұрын
Nice weed plant 😙☁️
@DLEET.Channel2 жыл бұрын
Great video Man
@marios4275Ай бұрын
Στην υγεια σας.
@rooney.464 жыл бұрын
Love you man 💕
@hakluke4 жыл бұрын
Aw shucks! Love you too!
@steez47784 жыл бұрын
ive seen the pfp in some homebrew community i swear
@n1yesuh8094 жыл бұрын
Thank you
@hakluke4 жыл бұрын
No worries
@PIYUSHBEDI-t1s5 ай бұрын
Some great hackers to follow 12:25
@msrobot_3 жыл бұрын
When you say "zero", you mean "zero zero" or just "zero"?
@seanmcelroy58254 жыл бұрын
This is awesome!
@hakluke4 жыл бұрын
Thanks Sean!
@constatineb70653 жыл бұрын
great talk! Thanks!
@ulfp80252 жыл бұрын
Hello, i have Done some both udemy and labs Trying to start bug hunting but as soon as I get on a real target I get overwhelmed and don’t know how to proceed
@camelotenglishtuition639411 ай бұрын
But what about the fact most programs dont allow automation?
@hackerexploit89574 жыл бұрын
I might not do bug bounties, but this definitely helps with pentesting, if im not interested in bug bounties. But maybe, later on, sounds pretty interesting.
@newbiadk2 жыл бұрын
so much information
@razorednight4 жыл бұрын
He said "Turn off KZbin," so I turned it off... a
@thereal69544 жыл бұрын
i do the same !🙂
@lukAndreas4 жыл бұрын
Hi, there is a bug in the description. It shows Katie's KZbin instead of Luke's. ;)
@793matt4 жыл бұрын
Skip the pep talk 8:19.
@danielrdrigues2 жыл бұрын
Is a good thing focus in just one category? Example, web servers?
@SrRunsis3 жыл бұрын
What video-call software are they using in the talk??? its so smooth
@SecretLetters4 жыл бұрын
Hey there's audio in this one! 😆
@hakluke4 жыл бұрын
I find that audio does help to understand what's going on ;)
@obscenity4 жыл бұрын
yeah the sync is way off tho
@saddam52594 жыл бұрын
keep it and thanks for sharing i am flowing u...
@thebrotherhood16754 жыл бұрын
push up explanation may need some sport science expertise, everything else was mint nice one
@tess95124 жыл бұрын
Love you Bugcrowd ♥️
@Alex-oh6lj4 жыл бұрын
Can someone explain how Python Wrappers work? I want to automate this stuff but I have no clue how to do that. Thanks.
@hakluke4 жыл бұрын
basically you use python to run a bash command to execute another tool, and parse the output as text
@sarunkim60963 жыл бұрын
Hello sir , Can I use IMac to find bug bounty ?
@caseyellis56634 жыл бұрын
was "how many background combo's are there in hakluke's talk" one of the ctf questions?
@lvzodiac31614 жыл бұрын
Hai brother... I have studied owasp but i don't know how to implement.. And want to start bug hunting...
@hakluke4 жыл бұрын
this was 3 months ago - where are you at now?
@elmi1082 жыл бұрын
What steps to take to create my own automation ?
@haksting4 жыл бұрын
My FOS is that I will do something wrong like DOSing target or mess something.
@hakluke4 жыл бұрын
If this is scaring you, maybe just stick to programs with full safe harbour and don't do DoS attacks.
@BabarKhan-nv9es4 жыл бұрын
There are lot of people out there that are so full of energy that they say that we mess something but at least we learn something 😀😀😀( by messing mean harming the traget unintentionally)
@Knightfallprotocol4444 жыл бұрын
Question for you Mr.HakLuke , when it comes to automation is this something you achieve with python? what do you recommend?
@hakluke4 жыл бұрын
Python is great for this :)
@gickygackers3 жыл бұрын
Python is amazing. Use it now!
@elmi1082 жыл бұрын
@@hakluke what steps do I need to create my own Automation tool if am good with python but new in Bug Bounty industry
@bobhrobor46543 жыл бұрын
1:16:45 starting: education ( *Jason headaches stuff, pentesters lab, web apps handbook, Twitter community* ) 1:22:00 +/- idea 1:24:30 _new points of view_
@akbare-z8153 жыл бұрын
Thanks
@SecurityTalent2 жыл бұрын
Great bro
@lazarep14 жыл бұрын
Does anyone know where i can find the application hacking version of bug bounty hunter methodology
@hakluke4 жыл бұрын
I actually don't think it ever got released! Jason had to pull out of doing that talk.
@shehanperera14374 жыл бұрын
Do I need a kind of computer deggre to work as a bughunter or my skills are enough?
@hakluke4 жыл бұрын
You don't need a computer degree to learn about hacking, many great hackers are self-taught.
@Bharath-wb8uy3 жыл бұрын
Thank you buddy.
@CyBertronSecK9 ай бұрын
hey can you guide me on automation?
@GeniusFranklyn4 ай бұрын
@hakluke do mean starting from zero zero, like a total dummy beginner in Bug Bounty because i don't know how to start and what to do.
@anurag.303023 ай бұрын
watch nahamsec's recon videos do portswiggers lab and some ctf you will get your way
@astrix88124 жыл бұрын
Awesome thanks for sharing! Btw, What's the into music name?
@hakluke4 жыл бұрын
I totally chose that music! It was some stock one that I bought, I can't remember the name.
@astrix88124 жыл бұрын
@@hakluke No problem. Great music choice as well! Keep rocking and inspiring :D
@taiquangong99124 жыл бұрын
So before I began bug bounties should I master the techniques first or do that as I bug bounty??m
@Najumulsaqib4 жыл бұрын
Music is epic
@hakluke4 жыл бұрын
:)
@Najumulsaqib3 жыл бұрын
@@hakluke Can I ask which music is it?
@mindovermatter11164 жыл бұрын
Hi does anyone know where the Jason Haddix v4 Application hacking is uploaded?? I already saw the v4 recon....
@davidpandolfo4 жыл бұрын
kzbin.info/www/bejne/pmWtmHyrZtKWm6s
@yusufdomun3033 жыл бұрын
This guy is amazing !
@Alfonso0134 жыл бұрын
im bachelor in Netcetcentric Computing.. but i do not see any of use for bug bounty and i dont how where to start it.. can u help me?
@ZarakKhanNiazi2 жыл бұрын
automation means i keep burp pro scan running??
@szmigiellus2 жыл бұрын
I got solidly called out in the very first 5 minutes 💀
@alharosh4 жыл бұрын
Hello to you, am absolutely zero knowledge do you think i can do it, even if i have no back ground of Software. thanks
@vasanthk36334 жыл бұрын
Yes you can
@kthiriomar74643 жыл бұрын
hey i just scan the qr code of the intro and i enter your website and i can't find the flag 😟, any hint ?????
@Man0fSteell3 жыл бұрын
why do u keep changing ur background elements?
@jaydevsolanki10474 жыл бұрын
You forgot to mention the most important tip that "be prepared for the truth that not everyone can learn bug bounty". Thanks 😊