Welcome to the comment section. If you don't want to miss my future case studies, join BBRE Newsletter for free at bbre.dev/nl
@moizpasha7852 Жыл бұрын
Great vid! One of the weirdest IDORs I found used a UNIX epoch timestamp format as an identifier. I spent a lot of time bruteforcing it, but since I was only changing the time by a matter of milliseconds (I did not know what a UNIX timestamp was) I did not get to exploit it. Reported it anyway and got informed that it was a P1.
@normalitee0os Жыл бұрын
Your channel is just absolute gold man!
@AbdAlkarimTube Жыл бұрын
Nice topic! We need more on BAC. Thanks!
@eyezikandexploits Жыл бұрын
Veen heavy in idor lately this video was nice and perfect timing
@monKeman495 Жыл бұрын
Much appreciated detailed case study of IDOR bug class can we expect your 20k aws misconfiguration vid next ?
@BugBountyReportsExplained Жыл бұрын
I'm not sure if next but I'll definitely do it😉
@guillermoslomon6738 Жыл бұрын
I really like the way you explain it, thank you
@duskb1t Жыл бұрын
I really enjoy your content. You have a new active sub
@andrezaantonelli5024 Жыл бұрын
Thank you so much for your help and your time.
@johnnyonpc6799 Жыл бұрын
Just found your channel, very good content I'd say. Keep it up! Subbed.
@BugBountyReportsExplained Жыл бұрын
Welcome aboard!
@CristiVladZ Жыл бұрын
I love these case studies!
@leghdaf3 ай бұрын
Great Content ...
@musaumarfaruq8675 Жыл бұрын
Where can I find all the bug reports
@ahmetsaric53649 ай бұрын
Thank you
@grassy-p12 Жыл бұрын
Yeah its so informative😍
@MFoster392 Жыл бұрын
Gret video thanks
@EndlessTech Жыл бұрын
According to you how many people in world are there in Penetration testing and ethical hacking in cybersecurity like range or gesture for example 4-5 million, etc.
@BugBountyReportsExplained Жыл бұрын
I have no idea
@sxhil.d3v Жыл бұрын
can u share all reports coz i just started idk much idors
@BugBountyReportsExplained Жыл бұрын
They are all shared in BBRE Premium archive
@GajendraMahat11 ай бұрын
which website he is using to view all the writeup
@BugBountyReportsExplained11 ай бұрын
It's on my website as a part of BBRE Premium
@GajendraMahat11 ай бұрын
@@BugBountyReportsExplained 🥺🥺👍
@32_jadav_akash22 Жыл бұрын
If the identifier is long or uuid it could be found on the Wayback machine it is still a valid report??
@BugBountyReportsExplained Жыл бұрын
rez0 has a great blogpost about the topic: rez0.blog/hacking/cybersecurity/2022/08/18/unpredictable-idors.html