IDOR - how to predict an identifier? Bug bounty case study

  Рет қаралды 16,267

Bug Bounty Reports Explained

Bug Bounty Reports Explained

Күн бұрын

Пікірлер: 30
@BugBountyReportsExplained
@BugBountyReportsExplained Жыл бұрын
Welcome to the comment section. If you don't want to miss my future case studies, join BBRE Newsletter for free at bbre.dev/nl
@moizpasha7852
@moizpasha7852 Жыл бұрын
Great vid! One of the weirdest IDORs I found used a UNIX epoch timestamp format as an identifier. I spent a lot of time bruteforcing it, but since I was only changing the time by a matter of milliseconds (I did not know what a UNIX timestamp was) I did not get to exploit it. Reported it anyway and got informed that it was a P1.
@normalitee0os
@normalitee0os Жыл бұрын
Your channel is just absolute gold man!
@AbdAlkarimTube
@AbdAlkarimTube Жыл бұрын
Nice topic! We need more on BAC. Thanks!
@eyezikandexploits
@eyezikandexploits Жыл бұрын
Veen heavy in idor lately this video was nice and perfect timing
@monKeman495
@monKeman495 Жыл бұрын
Much appreciated detailed case study of IDOR bug class can we expect your 20k aws misconfiguration vid next ?
@BugBountyReportsExplained
@BugBountyReportsExplained Жыл бұрын
I'm not sure if next but I'll definitely do it😉
@guillermoslomon6738
@guillermoslomon6738 Жыл бұрын
I really like the way you explain it, thank you
@duskb1t
@duskb1t Жыл бұрын
I really enjoy your content. You have a new active sub
@andrezaantonelli5024
@andrezaantonelli5024 Жыл бұрын
Thank you so much for your help and your time.
@johnnyonpc6799
@johnnyonpc6799 Жыл бұрын
Just found your channel, very good content I'd say. Keep it up! Subbed.
@BugBountyReportsExplained
@BugBountyReportsExplained Жыл бұрын
Welcome aboard!
@CristiVladZ
@CristiVladZ Жыл бұрын
I love these case studies!
@leghdaf
@leghdaf 3 ай бұрын
Great Content ...
@musaumarfaruq8675
@musaumarfaruq8675 Жыл бұрын
Where can I find all the bug reports
@ahmetsaric5364
@ahmetsaric5364 9 ай бұрын
Thank you
@grassy-p12
@grassy-p12 Жыл бұрын
Yeah its so informative😍
@MFoster392
@MFoster392 Жыл бұрын
Gret video thanks
@EndlessTech
@EndlessTech Жыл бұрын
According to you how many people in world are there in Penetration testing and ethical hacking in cybersecurity like range or gesture for example 4-5 million, etc.
@BugBountyReportsExplained
@BugBountyReportsExplained Жыл бұрын
I have no idea
@sxhil.d3v
@sxhil.d3v Жыл бұрын
can u share all reports coz i just started idk much idors
@BugBountyReportsExplained
@BugBountyReportsExplained Жыл бұрын
They are all shared in BBRE Premium archive
@GajendraMahat
@GajendraMahat 11 ай бұрын
which website he is using to view all the writeup
@BugBountyReportsExplained
@BugBountyReportsExplained 11 ай бұрын
It's on my website as a part of BBRE Premium
@GajendraMahat
@GajendraMahat 11 ай бұрын
@@BugBountyReportsExplained 🥺🥺👍
@32_jadav_akash22
@32_jadav_akash22 Жыл бұрын
If the identifier is long or uuid it could be found on the Wayback machine it is still a valid report??
@BugBountyReportsExplained
@BugBountyReportsExplained Жыл бұрын
rez0 has a great blogpost about the topic: rez0.blog/hacking/cybersecurity/2022/08/18/unpredictable-idors.html
@M7moudx22
@M7moudx22 Жыл бұрын
it's possbile to upload write-ups file ?
@BugBountyReportsExplained
@BugBountyReportsExplained Жыл бұрын
It's uploaded in the BBRE Premium archive
@bibekdhakal3887
@bibekdhakal3887 Жыл бұрын
😁😁
Top privilege escalation techniques - bug bounty case study
22:41
Bug Bounty Reports Explained
Рет қаралды 3,1 М.
0 to $100,000 in Bug Bounty : The architecture !! #bugbounty
18:19
Mayur Chavan
Рет қаралды 3,9 М.
Long Nails 💅🏻 #shorts
00:50
Mr DegrEE
Рет қаралды 16 МЛН
Real Man relocate to Remote Controlled Car 👨🏻➡️🚙🕹️ #builderc
00:24
Twin Telepathy Challenge!
00:23
Stokes Twins
Рет қаралды 110 МЛН
How to do account takeover? Case study of 146 bug bounty reports
30:23
Bug Bounty Reports Explained
Рет қаралды 11 М.
Get Started With Ethical Hacking: Beginner To Master
15:47
Luke Dexter
Рет қаралды 7 М.
Turning unexploitable XSS into an account takeover with Matan Berson
23:46
Bug Bounty Reports Explained
Рет қаралды 14 М.
All About IDOR
1:06:23
Ahmed Najeh
Рет қаралды 1,7 М.
Why Your IDORs Get NA’d, Cookies Explained
20:09
InsiderPhD
Рет қаралды 17 М.
$780,000 in 3 months Bug Bounty!
23:55
Tadi
Рет қаралды 13 М.
Which XSS payloads get the biggest bounties? - Case study of 174 reports
28:40
Bug Bounty Reports Explained
Рет қаралды 27 М.
Long Nails 💅🏻 #shorts
00:50
Mr DegrEE
Рет қаралды 16 МЛН