Updated Beginners Guide to API Bug Bounty

  Рет қаралды 14,696

InsiderPhD

InsiderPhD

Күн бұрын

Пікірлер: 44
@swapCode
@swapCode 10 ай бұрын
Thank you for sure all of this information Where video links that you mention?
@skysunset877
@skysunset877 9 ай бұрын
I really love this video! Thank you very much!!!
@cybernerddante
@cybernerddante 9 ай бұрын
Thank you for educating the community. You are my favorite bug bounty educator. I have a question about ffuf...how slow should I run ffuf for enumeration? You can set a rate/second with "-rate" or a delay beteeen requests with "-p"... I'm paranoid and sometimes only run 1-2 requests per second...grandpa-style 👴🐢
@InsiderPhD
@InsiderPhD 8 ай бұрын
Depends on the client, should be in their scope or on the program page
@Alexander007A
@Alexander007A 10 ай бұрын
Thank you for the new information MAAM, I'm learning JS will it help me in my API? is learning JSON is worth for API?
@InsiderPhD
@InsiderPhD 10 ай бұрын
JSON yes JavaScript it depends, id focus on react
@Alexander007A
@Alexander007A 10 ай бұрын
@@InsiderPhD alright thank you react is also good.. by the way can you tell me why I got unsubscribe from your KZbin channel?? When I subscribe after few days I got unsubscribe.?
@camelotenglishtuition6394
@camelotenglishtuition6394 9 ай бұрын
silly-ish question but why react and not javascript? Just wondering as I'm choosing one of them atm@@InsiderPhD
@EZ-HACK
@EZ-HACK 9 ай бұрын
thanks im changing sides
@Micah-m1o
@Micah-m1o 10 ай бұрын
very good and helpful thanks
@MFoster392
@MFoster392 10 ай бұрын
Thank you for the information :)
@0xanupam
@0xanupam 10 ай бұрын
I stuck when i see authorization bearer token
@ISaIGoI
@ISaIGoI 10 ай бұрын
I have found an IDOR vulnerability but can't access other users' "id", should I report it?
@InsiderPhD
@InsiderPhD 10 ай бұрын
As in you can’t find how you would discover the other ID?
@ISaIGoI
@ISaIGoI 10 ай бұрын
@@InsiderPhD Yeah, ID looks like this " id=69690bb85f0ea26a7e5a962746cf008b8"
@shubham_srt
@shubham_srt 10 ай бұрын
thanks
@mateuszwojtowicz6270
@mateuszwojtowicz6270 10 ай бұрын
where can I find images from OWASP API Top 10 slide (16:55)?
@InsiderPhD
@InsiderPhD 9 ай бұрын
That’s from an upcoming video :) coming out this week
@mateuszwojtowicz6270
@mateuszwojtowicz6270 9 ай бұрын
@@InsiderPhD bless you all of for those!!!
@orbitxyz7867
@orbitxyz7867 10 ай бұрын
Where is the zoom link mam
@InsiderPhD
@InsiderPhD 10 ай бұрын
Will be announcing it soon, taking a bit longer to sort out the registration form than I expected
@Bit_Fury
@Bit_Fury 10 ай бұрын
Tank you ❤
@0xanupam
@0xanupam 10 ай бұрын
what if program using authorization Bearer token
@InsiderPhD
@InsiderPhD 10 ай бұрын
Barer tokens work exactly the same as cookies
@dexincheng9135
@dexincheng9135 10 ай бұрын
Hello insiderPhD, can you share your PPT?
@InsiderPhD
@InsiderPhD 10 ай бұрын
Sorry I don’t because people are dicks and steal it, you can find some older stuff on leak websites though
@f.n.k.b8678
@f.n.k.b8678 10 ай бұрын
Need help here
@orbitxyz7867
@orbitxyz7867 10 ай бұрын
hoping more videos on web apis 😊
@InsiderPhD
@InsiderPhD 10 ай бұрын
I’m actually running some free live classes in January over Zoom!
@orbitxyz7867
@orbitxyz7867 10 ай бұрын
@@InsiderPhD can we join free classes
@hackergod00001
@hackergod00001 10 ай бұрын
@@InsiderPhD would love to join
@abubakarmohammed2436
@abubakarmohammed2436 10 ай бұрын
How can we join?
@InsiderPhD
@InsiderPhD 10 ай бұрын
Yup! Going to share details on Monday but you just need to register it’s 100% free
@tbjehad106
@tbjehad106 9 ай бұрын
KITERUNNER is not working any more
@abosi2733
@abosi2733 10 ай бұрын
I live in Iran and I can't work with bugcrowd or hakerone 😢💔
@InsiderPhD
@InsiderPhD 10 ай бұрын
Yeah Iran is still under international sanctions, it’s going to be the case for most bug bounty platforms or companies they just aren’t allowed :(
@Exploit5lover
@Exploit5lover 10 ай бұрын
Greetings 🤗
@jasonl9266
@jasonl9266 6 ай бұрын
A brother that code is Brogrammer
@volodyakost4354
@volodyakost4354 4 ай бұрын
@0xanupam
@0xanupam 10 ай бұрын
easy to play with cookies
@finchking
@finchking 6 ай бұрын
Most of your video is just wasting time. Nothing Practical! nothing new! Nothing Helpful for real world scenario?
@AnthonyMcqueen1987
@AnthonyMcqueen1987 6 ай бұрын
Enough talking and show some examples step by step would be more helpful and just this nonsense get to the point.
New OWASP API Top 10 for Hackers
29:43
InsiderPhD
Рет қаралды 10 М.
"Easiest" Beginner Bugs? Access Control and IDORs
31:46
InsiderPhD
Рет қаралды 21 М.
Life hack 😂 Watermelon magic box! #shorts by Leisi Crazy
00:17
Leisi Crazy
Рет қаралды 80 МЛН
Ozoda - Lada ( Official Music Video 2024 )
06:07
Ozoda
Рет қаралды 31 МЛН
龟兔赛跑:好可爱的小乌龟#short #angel #clown
01:00
Super Beauty team
Рет қаралды 30 МЛН
Smart Sigma Kid #funny #sigma
00:14
CRAZY GREAPA
Рет қаралды 12 МЛН
3 Real API Bugs I got a bounty for
17:43
InsiderPhD
Рет қаралды 10 М.
Step-by-Step Guide To Get IDOR in Live Bug Bounty Programs | 2024 Tips
12:11
This Bug Got Me A $30,000 Bounty
12:41
NahamSec
Рет қаралды 13 М.
My Favorite API Hacking Vulnerabilities & Tips
10:08
NahamSec
Рет қаралды 13 М.
Finding Your First API Bug (NahamCon 2023)
22:10
InsiderPhD
Рет қаралды 10 М.
$200 Bug Bounty PoC Worth | Full API Key Recon
14:28
SecShiv
Рет қаралды 13 М.
New methods of recon with OrwaGodfather
42:00
Bugcrowd
Рет қаралды 9 М.
Life hack 😂 Watermelon magic box! #shorts by Leisi Crazy
00:17
Leisi Crazy
Рет қаралды 80 МЛН