How To Get Started In Bug Bounties

  Рет қаралды 110,923

DC CyberSec

DC CyberSec

Күн бұрын

Пікірлер: 154
@domaincontroller
@domaincontroller 4 жыл бұрын
02:13 HTTP, TCP/IP, Linux, Bash scripting 02:30 Web apps, Networking, HTML, PHP 02:50 Burp Suite, Google 05:08 owasp
@mr.shanegao
@mr.shanegao 3 жыл бұрын
thx
@xd_preet
@xd_preet 3 жыл бұрын
Father of cj
@atmane001
@atmane001 4 жыл бұрын
Super useful resourxrs; 1.Twitter, gold mine for bug bounty. Hust follow the main players. 2.Start reading bug bounty reports, as many as you can and test. 3.Readn read ... many free resources out there. Big G is your friend in this case. 4.YT of course, follow channels that talk about bug bounty, cybersec and even dev. 5.Do some coding projects (c, c++, javasxript, python). It will be useful. Check github for ideas. 6.Have fun 😁😁
@no1sploit529
@no1sploit529 4 жыл бұрын
Your video motivated me, I consider all of your words. This is heart touching. Thanks for such a great information.
@dccybersec
@dccybersec 4 жыл бұрын
Thanks for the nice words and for watching :)
@no1sploit529
@no1sploit529 4 жыл бұрын
@@dccybersec welcome sir. Keep helping us 💓
@tirtheshpawar9614
@tirtheshpawar9614 4 жыл бұрын
JUST THE PRACTICAL GUIDANCE NEEDED IN AN ERA OF FLOODING INFORMATION... KEEP DOING THE GOOD WORK DC CYBERSEC!!!!
@dccybersec
@dccybersec 4 жыл бұрын
thanks man!
@shadowbandit5689
@shadowbandit5689 4 жыл бұрын
Thanks for the information mate. Very helpful me and mates currently studying Cyber Security and are looking into diving into some bug bountys.
@devcreed8175
@devcreed8175 4 жыл бұрын
For all those who are here to get information about how to get started, here are few videos which might help you out: kzbin.info/www/bejne/baquhmOZiK2oa6M kzbin.info/www/bejne/p57IZaV3eZegoq8 kzbin.info/www/bejne/eYacepScmJJ8ndU kzbin.info/www/bejne/rIG6o6WNoculjrM kzbin.info/www/bejne/oZ-Tm3aijLiXepo An unhelpful suggestion from me: The methodology I follow is, master a technology and then exploit it. Without mastering (or at least understanding) a technology, you can't start finding bugs in it. There are a tons of things going on behind the website you open or this video you are watching like a server hardware residing in a data center somewhere in this world with a hypervisor installed on it and a VM instance with a web hosting application, hosting this website behind a loadbalancer which is behind a dedicated physical firewall which might be behind some proxy server which might be behind another firewall. This was only the hardware part, many such things are deployed on the software-side too! So, start it with focus of learning it and then master it and then -_- Sit back home and read this comment again! Goodluck for your journey!
@DamienBiffinc0ldm3th0d
@DamienBiffinc0ldm3th0d 4 жыл бұрын
THANK YOU, i cannot say this enough THANK YOU, i needed a definite go here learn this start there.
@dccybersec
@dccybersec 4 жыл бұрын
😊😊
@hakunamatras
@hakunamatras 4 жыл бұрын
Great video! I'm a student in Internet of Things with interests in cybersecurity and pen testing also, due to my study i don't have a lot of time to search the perfect resource on where to start, i usually get home, make my homework and at around 1am i can start learning. thanks for helping me out on that haha Could you make this a serie maybe? How to get started. How I did my first bounty Where are the keypoints the check How to write a good report Things not to do while bug hunting Roadmap to pen testing Again, Great channel, keep it up ^^ Greetz from Belgium!
@dccybersec
@dccybersec 4 жыл бұрын
You literally named almost every episode of the bug bounty series that i've got in the works hahaha. Thanks for watching man, really appreciate it!
@hakunamatras
@hakunamatras 4 жыл бұрын
@@dccybersec Don't thank me, you're doing the work! i'd love to help you with finding sources or just philosophize about bug hunting, any way i can reach out to you?
@dccybersec
@dccybersec 4 жыл бұрын
@@hakunamatras Discord or Twitter (links in description). Probably discord is best, i'm pretty active in my server :)
@wtfdoiputhere
@wtfdoiputhere 3 жыл бұрын
Im gonna start with this bcz it seems easier to me than some magic assembly voodoo shit and i have great knowledge in linux, js and networking so im ready
@psychoticgamer6853
@psychoticgamer6853 4 жыл бұрын
Bali mask is background 😱 This boi can Rob a bank🔥
@jonathanyturralde
@jonathanyturralde 4 жыл бұрын
This was a great video. Thanks for the content. Awesome stuff and very helpful for a newbie like myself.
@dccybersec
@dccybersec 4 жыл бұрын
Glad it helped out :)
@RN-kl4kp
@RN-kl4kp 4 жыл бұрын
Yes..! Thank you very much... for this... just a request when you find get a bug bounty 💵💵💵 which we hope soon ? Can you please share with us?? The process??
@dccybersec
@dccybersec 4 жыл бұрын
Yep will do mate. I’ll be documenting my whole process from beginning to bounty!
@harihacke9454
@harihacke9454 4 жыл бұрын
@@dccybersec where mate
@fourofour9569
@fourofour9569 3 жыл бұрын
Good stuff! It really got my interest in bug bounties.
@mahir_saif
@mahir_saif 2 жыл бұрын
This video was so damn intense. Thanks a lot.
@Plutosantorini
@Plutosantorini 4 жыл бұрын
Bro dont forget about cyber mentor man that guy is a hero
@dccybersec
@dccybersec 4 жыл бұрын
For sure! He’s awesome 😎
@Mauricio_Ferrari
@Mauricio_Ferrari 4 жыл бұрын
Stok has been great to watch, already watched some of his videos. Great video by the way and thanks for recommendations.
@dccybersec
@dccybersec 4 жыл бұрын
he's an absolute legend. thanks for watching!
@prafullss
@prafullss 4 жыл бұрын
Your all videos are really awesome. I like every video. Post video more . thank you bro. 😊
@dccybersec
@dccybersec 4 жыл бұрын
Thanks mate! That’s very kind of you
@prafullss
@prafullss 4 жыл бұрын
Your kindness. 🤗😊
@vishnudileesh1243
@vishnudileesh1243 4 жыл бұрын
Looking forward to the future video in which u tell your first bug finding story
@dccybersec
@dccybersec 4 жыл бұрын
I can’t wait!
@youarenotspecial17
@youarenotspecial17 4 жыл бұрын
nice video. btw I subscribe your channel cause you look like a really nice and honest guy!
@dccybersec
@dccybersec 4 жыл бұрын
lol thanks :D
@ThushyCyber
@ThushyCyber 2 жыл бұрын
Thanks 😊
@dccybersec
@dccybersec 2 жыл бұрын
No problem 😊
@JK-pb3vj
@JK-pb3vj 4 жыл бұрын
Loving the content mate - great advice! Cheers from BNE, Aus 🍻
@dccybersec
@dccybersec 4 жыл бұрын
Thanks mate! I should do a local Brisbane meetup sometime
@JK-pb3vj
@JK-pb3vj 4 жыл бұрын
Keen as, let’s put something together.. Where you at @codingo_ !
@Jawdey
@Jawdey 4 жыл бұрын
Hey how good is brisbane!
@alexramsey1006
@alexramsey1006 4 жыл бұрын
Very nice presentation... Thank you.
@dccybersec
@dccybersec 4 жыл бұрын
Glad you liked it!
@hugoalexandregoncalvespica124
@hugoalexandregoncalvespica124 4 жыл бұрын
7:26 💪
@aritra1414
@aritra1414 4 жыл бұрын
Definitely helpful. Thanks man!
@kaotechtalk2395
@kaotechtalk2395 4 жыл бұрын
This video was great! Thankyou so much for all of the info! Got a sub from me
@dccybersec
@dccybersec 4 жыл бұрын
Thanks for the sub!
@realcarttons2177
@realcarttons2177 4 жыл бұрын
please do clear my confusion ,do we need to stay ananmous during bug bounyt
@darkhack3r417
@darkhack3r417 4 жыл бұрын
New subscriber here also this is the first video i watch in your channel xD
@dccybersec
@dccybersec 4 жыл бұрын
woohoo! welcome! thanks for watching :)
@kylewattssurfing3266
@kylewattssurfing3266 4 жыл бұрын
Thank you thank you thank you!
@dccybersec
@dccybersec 4 жыл бұрын
You’re welcome :)
@maxitaxi7340
@maxitaxi7340 4 жыл бұрын
I dont understand something. Some hackers are reading the code and they see instantly where a voulnabilty could be. But if i try to read webside code i dont understand anything. So i always go through the webside,and im testing every parameter. But how can i learn to find bugs by reading code?
@skiddy5294
@skiddy5294 4 жыл бұрын
I think that comes down to experience.. I could be absolutely wrong because I'm just beginning as well. I think over time, you learn what will/wont work in that language.
@kylewattssurfing3266
@kylewattssurfing3266 4 жыл бұрын
Awesome thank you
@dccybersec
@dccybersec 4 жыл бұрын
thanks for watching mate!
@frostyboi6989
@frostyboi6989 3 жыл бұрын
Is doing a bug bounty like doing a pen test you break into the company and tell them the bug ?
@dccybersec
@dccybersec 3 жыл бұрын
More or less, yes
@abiworldseccentric9878
@abiworldseccentric9878 4 жыл бұрын
Some times in The Hacker one site bug bounty section whom want to find the bugs they ask me to do find the bugs but they have one demand that shouldn't use Burpsuite and such a readymade tools so how can I performe..? Please can you suggest me
@manojbajgain7660
@manojbajgain7660 4 жыл бұрын
Really loved your videos #Can you discuss about Class 0 sms
@dccybersec
@dccybersec 4 жыл бұрын
It’s in the list man, you don’t need to keep asking lol
@manojbajgain7660
@manojbajgain7660 4 жыл бұрын
@@dccybersec you didn't response so I keep on making query😝😝
@francis2k488
@francis2k488 4 жыл бұрын
Thanks for this video. I am still learning and believe it will all sync soon. I got the OWASP Testing Guide V4
@hackedemy9324
@hackedemy9324 4 жыл бұрын
Are you Nigerian? Goodluck on your journey brother!
@francis2k488
@francis2k488 4 жыл бұрын
@@hackedemy9324 yeah but live in Australia. Are you? Where do you live?
@hackedemy9324
@hackedemy9324 4 жыл бұрын
@@francis2k488 You're really lucky! I'm in Nigeria at the moment but hopefully, I'll move out soon.
@francis2k488
@francis2k488 4 жыл бұрын
@@hackedemy9324 are you a hacker? Why did you say I am lucky. With skills we can be lucky anywhere bro. You can try migration pathway.
@hackedemy9324
@hackedemy9324 4 жыл бұрын
@@francis2k488 Yes I am. I'm self-studying cybersec online and studying Computer Engineering in the uni. Planning to leave Nigeria and study Computer Science or Cybersec elsewhere bc this isn't helping me. I'll try the migration pathway, saving towards it currently.
@rooney.46
@rooney.46 4 жыл бұрын
Love ya, keep going ❤️
@dccybersec
@dccybersec 4 жыл бұрын
Thanks mate. Will do!
@rastinghasemi634
@rastinghasemi634 4 жыл бұрын
Tanx
@yashwanthd1998
@yashwanthd1998 4 жыл бұрын
What i dont understand is people always talk about xss injection.. if the website itself doesn't take any user input or input is sanitised which is everywhere these days..xss injection seems very weak and impossible.could u explain
@MyNameIsTX
@MyNameIsTX 4 жыл бұрын
Soo essentially when you are going to attempt a bug bounty ( I am a completely clueless btw I have tried it and I don't know anything) do you just have to try every single exploit or like try all the possible problems? I do not exactly understand how it works. Also, I have no programming knowledge I have tried to self teach myself it and I am currently in college (community college) and hoping to transfer out to study IT but I want to branch out into cybersecurity. Basically, I do not know how to say what I want to say but, I think it is the owasp top 10 or something like that, do we try to find all those vulnerabilities in the program or website or is it something more specific.
@36cowboysintotalatramranch
@36cowboysintotalatramranch 4 жыл бұрын
Yeah, basically you can try everything possible. Each app is a new challenge, with different bugs and defenses to evade, and then you report on what worked and on what didn’t. The job of a pentester is to evaluate the client’s systems, so it’s also good to tell them where you weren’t able to get anywhere because they did things right!
@ocelotrevolver4125
@ocelotrevolver4125 3 жыл бұрын
Can I make a living from doing bug bounties, or perhaps doing security evaluations for businesses demonstrating network security flaws to business owners and how to secure their systems and how to harden them. I have a good understanding of cybersecurity with years of experience using Linux I'm just not sure how I can transfer these skills I've learned over the years and turn this into a freelance income, any advice?
@faruky9197
@faruky9197 4 жыл бұрын
First of all English is not my native language. I really want to do bug bounty but not too many resources in my language in bug bounty. Because of this, I cannot learn by reading documents or watching videos. That's why I need to learn software languages so that I can understand its logic. What should I do?
@LotsOVideosMan
@LotsOVideosMan 4 жыл бұрын
What is song called at 0:32?
@malikimranawan3762
@malikimranawan3762 4 жыл бұрын
if a Subdomain give us error 404 .. can that Takeover ?
@yousefkammouneh6559
@yousefkammouneh6559 4 жыл бұрын
Just found my first bug
@dccybersec
@dccybersec 4 жыл бұрын
Woohoo!
@wackyskullgaming6711
@wackyskullgaming6711 4 жыл бұрын
This is very informative
@dccybersec
@dccybersec 4 жыл бұрын
Thanks mate
@koushikram4036
@koushikram4036 3 жыл бұрын
please answer this do I need burb suite pro for my first bug ???
@dccybersec
@dccybersec 3 жыл бұрын
Nope. You can use the free one
@koushikram4036
@koushikram4036 3 жыл бұрын
@@dccybersec thanks for your replay
@abhichauhan350
@abhichauhan350 3 жыл бұрын
I want to learn bug bounty So tell me what topic should I learn
@harreve3629
@harreve3629 3 жыл бұрын
Love bro..
@dccybersec
@dccybersec 3 жыл бұрын
love you too mate!
@usama_sadiq
@usama_sadiq 3 жыл бұрын
Mera ye sawaal hai ke agar hum kise company ke ek se ziada bug dhoond lein tu hum us company ko saare bugs ke liye sirf ek report likhen ya har bug ke liye alag alag report likhen
@dccybersec
@dccybersec 3 жыл бұрын
I tried translating this from Hindi and still couldn't really understand, sorry :( Can you reply in english please so I can help out?
@inspirationeveryday1175
@inspirationeveryday1175 4 жыл бұрын
Hello Sir Do you recomended KALI LINUX for BugBounty or Windows and MacOs is Good ? THANK you ⭐🔥
@dccybersec
@dccybersec 4 жыл бұрын
Honestly, whatever works for you. Kali might be easier as it has all the tools built in already but honestly, you can use any machine
@alonsocorrea1256
@alonsocorrea1256 4 жыл бұрын
Having the OSCP helps to get into bug bounty??
@dccybersec
@dccybersec 4 жыл бұрын
for sure, but not necessarily needed
@dougthebugwrx
@dougthebugwrx 4 жыл бұрын
@@dccybersec having done 35 oscp lab boxes so far , i say no . oscp web app labs are very average . you will learn more from portswigger web academy. also use owasp zap , its free
@jhadeeksollesta497
@jhadeeksollesta497 4 жыл бұрын
Broo thank you so so much im only 12 and im only 12 and i dont know really if I can do this but thxxx
@taylors4733
@taylors4733 4 жыл бұрын
The earlier the better!🙃 Go for it.
@davidg9469
@davidg9469 4 жыл бұрын
Did you find many bugs ?
@misterbrompton2400
@misterbrompton2400 4 жыл бұрын
You didn't link OWASP
@kylewattssurfing3266
@kylewattssurfing3266 4 жыл бұрын
Awesome cool...
@dccybersec
@dccybersec 4 жыл бұрын
Thanks ✌️
@jinxscript
@jinxscript 2 жыл бұрын
it's interesting 🤔
@dccybersec
@dccybersec 2 жыл бұрын
Thanks man!
@QuranicMoments
@QuranicMoments 3 жыл бұрын
Lot of thanks sir. 🔥🔥 سبحان اللّه 🔥🔥
@dccybersec
@dccybersec 3 жыл бұрын
My pleasure. Thanks for watching!
@sunilrai5506
@sunilrai5506 3 жыл бұрын
I am going to start bug bounty in hacker1 or bug crowd should I take permission or how to get permission from a web application, please help me anyone who all did bug bounty someone told me we have to take permission to bug hunting otherwise without permission it's will be a cybercrime plz someone explain😢😢😢😢
@dccybersec
@dccybersec 3 жыл бұрын
As long as you stay within the scope of what is defined by hacker1 or bugcrowd, then you're relatively safe. Just make sure you understand what the scope is and how to stay inline with that
@sunilrai5506
@sunilrai5506 3 жыл бұрын
@@dccybersec by the way thanks for your diamond advice sir (this advice is like a diamond for me can I follow you on tweeter sir)
@sunilrai5506
@sunilrai5506 3 жыл бұрын
one more last like go to the hacker1 sing up and according their rule pick a program start bug hunting if they told us not to in any subdomain then not to do in any subdomain am I right?
@gurjeetdasari1997
@gurjeetdasari1997 4 жыл бұрын
Please reply with the name of guides u prefer us to follow as I could not get what u said in the video
@dccybersec
@dccybersec 4 жыл бұрын
They are linked in the description
@SecurityTalent
@SecurityTalent 2 жыл бұрын
great
@dccybersec
@dccybersec 2 жыл бұрын
thanks!
@nikkucreations7842
@nikkucreations7842 4 жыл бұрын
Hii dc iam from india your video is more motivational
@sammygun84
@sammygun84 4 жыл бұрын
Where all links from video?where link on guide?
@dccybersec
@dccybersec 4 жыл бұрын
KZbin removed all my video descriptions a while back and replaced it with the default
@epic5855
@epic5855 3 жыл бұрын
EPIC
@jasoe_playz1926
@jasoe_playz1926 4 жыл бұрын
Programming Language is important.
@danielsuarezmartinez1967
@danielsuarezmartinez1967 4 жыл бұрын
how much time pass from 0 knowledge to your first bug??
@dccybersec
@dccybersec 4 жыл бұрын
I'll let you know when I get my first bug haha
@imuser007
@imuser007 4 жыл бұрын
U missed nullbyte channel
@tirilmariepedersen6956
@tirilmariepedersen6956 4 жыл бұрын
Who are you looking at? :p
@lagimmediafiles6478
@lagimmediafiles6478 4 жыл бұрын
Whats up Man?
@dccybersec
@dccybersec 4 жыл бұрын
nm mate, how's it going?
@lagimmediafiles6478
@lagimmediafiles6478 4 жыл бұрын
@@dccybersec im good i will start on My IT Job your channel is a big help
@saddamhussain189
@saddamhussain189 4 жыл бұрын
Hi
@ShashiSingh-ck7mu
@ShashiSingh-ck7mu 4 жыл бұрын
How many money can we make by bug bounty hacking.
@dccybersec
@dccybersec 4 жыл бұрын
It depends which bugs you find for which company
@ShashiSingh-ck7mu
@ShashiSingh-ck7mu 4 жыл бұрын
@@dccybersec like I'm 17 years old and going to graduate from school and I know c++ and python will that help? And as you mentioned in your video about tutorials on KZbin will that help me or courses on udemy or courses on hacker one will help I'm little confused which course to take can you please help me out because I also want to become a hacker like Santiago Lopez and Thomas Thank you.
@b3ast407
@b3ast407 4 жыл бұрын
@@ShashiSingh-ck7mu Yes read hackerone hacktivity,medium blogs, do labs like owaspbwa it definitely helps, @nahamsec's KZbin channel is also very nice
@rithvikgujjula1400
@rithvikgujjula1400 4 жыл бұрын
LEt's go first one here and first comment again
@dccybersec
@dccybersec 4 жыл бұрын
Killin it mate
@kunal9999100
@kunal9999100 3 жыл бұрын
Can I get one of your soft toys?
@dccybersec
@dccybersec 3 жыл бұрын
Sure. Which one do you want
@TheFunnyPOPS
@TheFunnyPOPS 4 жыл бұрын
I won’t recommend it bug bounties has too much competition now all the pros find bugs before you.
@dccybersec
@dccybersec 4 жыл бұрын
They just take the quick and easy payouts first. As far as building experience though it’s pretty good!
@richardjohnson9765
@richardjohnson9765 4 жыл бұрын
Watch hackersploit
@dccybersec
@dccybersec 4 жыл бұрын
Definitely! he's awesome
@mr.shanegao
@mr.shanegao 3 жыл бұрын
02:13 HTTP, TCP/IP, Linux, Bash scripting 02:30 Web apps, Networking, HTML, PHP 02:50 Burp Suite, Google 05:08 owasp
10 Tips For Crushing Bug Bounties in the First 12 Months
16:24
The Truth About Bug Bounties
14:12
The Cyber Mentor
Рет қаралды 118 М.
A Day In The Life Of A Bug Bounty Hunter (ft. STÖK)
24:55
DC CyberSec
Рет қаралды 12 М.
How Good Do You Have To Be To Get Into Cyber Security?
13:12
DC CyberSec
Рет қаралды 39 М.
Hacking on Bug Bounties for a Living
12:59
codingo
Рет қаралды 19 М.
How To Pick Your Targets // How To Bug Bounty
10:19
NahamSec
Рет қаралды 18 М.
How I made 1k in a day with IDORs! (10 Tips!)
23:09
InsiderPhD
Рет қаралды 54 М.
Is It Worth Getting Into Bug Bounties In 2020?
5:04
DC CyberSec
Рет қаралды 25 М.
Get Started With Ethical Hacking: Beginner To Master
15:47
Luke Dexter
Рет қаралды 7 М.
How to Stop Learning and Start Hacking!
17:13
InsiderPhD
Рет қаралды 31 М.
Finding Your First Bug: Choosing Your Target
32:32
InsiderPhD
Рет қаралды 162 М.