Hacking when all the bugs have been found?

  Рет қаралды 5,258

InsiderPhD

InsiderPhD

Күн бұрын

Finding bugs on the main app is something a lot of people are a little afraid of, a lot of people think that if a program has been out a while that there's no point even looking at it. But actually the majority of my bugs have actually been on the main application and rarely do I write off a program as unhackable. As you all know by now recon is definitely one of my weakest skills, so here are some tips for approaching the main app and actually getting bugs.
This series couldn't happen without the support of our sponsor Bugcrowd, Bugcrowd is the best place to start hacking with a wide range of public and private programs from APIs to Desktop Applications and everything in between. Not ready to jump into a public program yet? Fill out your platform CV and sign up for a waitlisted program. Tell Bugcrowd a bit about your skills, previous certifications or experience and they’ll match you up with the right program using their industry-leading CrowdMatch technology. Whatever your level, there’s a place for you in the crowd. You can sign up with my link here: bugcrowd.com/user/sign_up.

Пікірлер: 22
@MFoster392
@MFoster392 8 ай бұрын
Thank you as usual :) Just so you know at 18:52 you have Ffuz instead of FFUF on your points so you'll have to fix that if you use it in any more videos :)
@InsiderPhD
@InsiderPhD 8 ай бұрын
Thanks for that!
@MFoster392
@MFoster392 8 ай бұрын
@@InsiderPhD I'm sorry, i always watch your videos a few times and idk if you checked but i gave you she wrong time stamp it's around 8:44 not 18:52 that's the end of the movie
@Sam-wl7vn
@Sam-wl7vn 8 ай бұрын
The realest advice out there as per!
@kittoh_
@kittoh_ 8 ай бұрын
One of the videos with substantial knowledge gained! Awesome! It would also be cool if you can show a demo . Cheers!
@comosaycomosah
@comosaycomosah 8 ай бұрын
your videos been a huge help!
@Not0ver
@Not0ver 7 ай бұрын
Thanks for these vids I really learn a lot!
@mynameisrezza
@mynameisrezza 8 ай бұрын
What a legit content, katie! I'm still stuck on understanding how to fuzz api/graphql endpoint manually :(
@knowledgeboxbd9625
@knowledgeboxbd9625 8 ай бұрын
Great video, want more
@danishbhat1536
@danishbhat1536 8 ай бұрын
Doing the same approach from past 2 years.
@warnawarni5227
@warnawarni5227 8 ай бұрын
if i don't have AWS and i can't using IP rotator....how to avoid WAF when we FUZZ the app
@user-xw7qi3wx5w
@user-xw7qi3wx5w 8 ай бұрын
Same question
@MFoster392
@MFoster392 8 ай бұрын
Use a VPN
@RR-hl6zi
@RR-hl6zi 8 ай бұрын
​@@MFoster392Self-hosted VPN, right?
@Proxyone444
@Proxyone444 8 ай бұрын
@mehdi35191
@mehdi35191 8 ай бұрын
👏👏👏❤️🙏
@mnageh-bo1mm
@mnageh-bo1mm 8 ай бұрын
why bugcrowd not hackerone?
@InsiderPhD
@InsiderPhD 8 ай бұрын
Already made a h1 video a few years ago look for “choosing your target” on my channel
@memento-mori-amor
@memento-mori-amor 8 ай бұрын
the video’s lessons apply regardless of platform. AFAIK the differences between the platforms tend to be cosmetic
Why does DNS always break the internet?
17:26
InsiderPhD
Рет қаралды 10 М.
"Easiest" Beginner Bugs? Access Control and IDORs
31:46
InsiderPhD
Рет қаралды 19 М.
ЧУТЬ НЕ УТОНУЛ #shorts
00:27
Паша Осадчий
Рет қаралды 10 МЛН
小宇宙竟然尿裤子!#小丑#家庭#搞笑
00:26
家庭搞笑日记
Рет қаралды 14 МЛН
Updated Beginners Guide to API Bug Bounty
30:05
InsiderPhD
Рет қаралды 12 М.
Giving Yourself the Best Opportunity to Find a Bug
36:45
InsiderPhD
Рет қаралды 6 М.
IDOR with EXIF Vulnerability | Bug Bounty POC
2:16
Jiiva hacks
Рет қаралды 4,7 М.
Learn Bug Bounty Hunting with These Resources!
35:22
InsiderPhD
Рет қаралды 13 М.
Approaching Large Scope Targets Without Feeling Overwhelmed
20:13
Revealing Secrets with Information Disclosure Bugs
19:07
InsiderPhD
Рет қаралды 7 М.
My Hacking Setup and How to Use It (Firefox/Burp Community)
28:28
Finding Your First Bug: Getting Started on a Target (Part 2)
33:31
Finding Your First API Bug (NahamCon 2023)
22:10
InsiderPhD
Рет қаралды 10 М.