Live Recon and Automation on Shopify's Bug Bounty Program with

  Рет қаралды 167,149

NahamSec

NahamSec

Күн бұрын

Пікірлер
@NahamSec
@NahamSec 2 ай бұрын
📚 Purchase my course and learn about bug bounty hunting with over 11 hours of content, 100+ labs: bugbounty.nahamsec.training
@kharbandaumang
@kharbandaumang 3 жыл бұрын
this is some GOD-LEVEL recon !!! We want more sessions from Tom. Thanks nahamsec for bringing this to the community and thanks Tom for sparing your time for this!!!
@alexander_adnan
@alexander_adnan 2 жыл бұрын
Lol .. 😂…GOD level would leave you speechless
@godspeed2124
@godspeed2124 Жыл бұрын
@@alexander_adnan what god level according to you?
@65hammad
@65hammad Жыл бұрын
@@alexander_adnanyou don't have a clue then. For mass recon, this is GOD-tier automation. These guys can even automate the entire process if they wanted.
@alexander_adnan
@alexander_adnan 9 ай бұрын
@@godspeed2124 looks like you will find out before others. Not a good idea to do reverse psychology, with strangers. I would be rational though, there’s no recipe for recon, it depends on your target while Technics matters less than the potential.
@cr4zy_0o
@cr4zy_0o 3 жыл бұрын
The calmness that Tom have is really unique, great and fancy. + The way he do his things is really epic Really a great guy
@netoeli
@netoeli 3 жыл бұрын
fantastic video , Tom really knows his stuff
@IBDLFSEragon
@IBDLFSEragon 5 ай бұрын
Mind blowing. Thank you so much for giving back to community.
@franco2179
@franco2179 3 жыл бұрын
It's funny because I can tell from Nahamsec's faces that he just loves Tomnomnom. At the same time it makes him laugh that he is so calm when explaining things.
@NahamSec
@NahamSec 3 жыл бұрын
Haha! Tom is one of the most genuine and nicest people I have had on the show.
@chasejensen88
@chasejensen88 3 жыл бұрын
I think he's also realizing the greatness he's capturing at the moment, he isn't fully comprehending it yet but he knows it.
@HenryLawrenceHMBL
@HenryLawrenceHMBL 2 жыл бұрын
I would love to be a Shopify developer watching this unfold
@mateuszwasielewski7193
@mateuszwasielewski7193 Жыл бұрын
I started watching this with hope of learning something. Ended with depression and one conclusion - I should stop learning this stuff if I'm gonna need to compete with maaany, maaany people as Tom. And as he said - it was his first attempt since like two years ago. I would need like a week to check all the things that he checked. Now I get it why entry-level positions needs few years of experience but in the same time I don't see a way to get this experience
@purplethunder778
@purplethunder778 9 ай бұрын
If you think that the competitors out there are all as skillful as tom . You are very wrong
@rajanrawal6396
@rajanrawal6396 2 жыл бұрын
amazing, this could be probably one of the biggest information that i have ever been given. we need such playlist more and more in upcoming days. i hope i made you understand the things that i wanted to make you understand.. again, we need such playlist more and more in upcoming days.
@CWLabs7209
@CWLabs7209 2 жыл бұрын
Every week i rewatch your videos; I am learning new things 💙.
@SankizTime
@SankizTime Жыл бұрын
hora
@CWLabs7209
@CWLabs7209 Жыл бұрын
@@SankizTime :D
@hayben7046
@hayben7046 2 жыл бұрын
Thank you both for this great content. We want more videos with @TomNomNom.
@ca7986
@ca7986 3 жыл бұрын
Tom is really really good! He knows what he is doing! Amazing! Thanks Nahamsec for this video.
@BnayaProgramming
@BnayaProgramming 3 жыл бұрын
Start at 5:59
@affulsamuel728
@affulsamuel728 10 ай бұрын
That is why Hacking is time and patience game. i love the way he spend days to come on this i love this channel
@bertrandfossung1216
@bertrandfossung1216 3 жыл бұрын
This is epic!! I've have to watch this video over 10 times just to understand Tomnomnom's recon process. The guy is really really good at what he does. Thanks @nahamsec & @Tomnomnom🙏🏽🙏🏽🙏🏽
@abdul-rahman7608
@abdul-rahman7608 Жыл бұрын
Tom is a genius I must confess 🖤💯
@piusgabula
@piusgabula 2 жыл бұрын
This is byfar the most incredible live recon i have watched on youtube
@jeffreynoose
@jeffreynoose 2 жыл бұрын
I can watch these 50 times daily I love nomnom
@baolamminh1146
@baolamminh1146 3 жыл бұрын
I improve my bash skill much when watching this video. thanks Tomnomnom & Nahamsec
@samfisher8426
@samfisher8426 2 жыл бұрын
maan seeing how tom is working makes me feel down, this dude is so good
@vonniehudson
@vonniehudson 3 жыл бұрын
“ass, is that a new tool to compete with meg? I don’t know” had me rolling lololz
@crusader_
@crusader_ 3 жыл бұрын
Could you please upload all the other recons
@ashleypursell9702
@ashleypursell9702 3 жыл бұрын
i was literaly looking for something just like anew to use in my automation since i run scans everday i want to add stuff to already existing txt files. i have seen people use it and idk why i only found out about it rn, great video thanks so much
@joefawcett2191
@joefawcett2191 Жыл бұрын
these vim and bash skills are really something to behold
@The1994mattj
@The1994mattj 7 ай бұрын
Would be interesting to see how different the process/tools look 3 years on.
@thenarrowgate3063
@thenarrowgate3063 8 ай бұрын
I wish I had vim mastered in this way, I use nano which has some of the same features but vim has way more flexibility it's a language all it's own and it's why hackers prefer it, I mean true command based hackers..windows has spoiled this generation..nothing wrong with a GUI but hacking is about control and putting that level of control in a GUI is a major resource hog..TOM you are a dying breed, my hats off to you..grey that is
@xrfox1634
@xrfox1634 3 жыл бұрын
I love this man!
@amir-or6uf
@amir-or6uf Ай бұрын
it was awesome, thanks man.
@theys6837
@theys6837 3 жыл бұрын
*TomNomNom* is a FKIN G 💯👏
@gifbfbvhvhdhfhfjffjfnfhfb515
@gifbfbvhvhdhfhfjffjfnfhfb515 2 жыл бұрын
best video ive seen in a long time
@danieltamang2289
@danieltamang2289 3 жыл бұрын
finally, the two underrated hunters!!
@ar-uh1dj
@ar-uh1dj 3 жыл бұрын
He is truly a Genius!!!!!!!
@ggmaxx66
@ggmaxx66 3 жыл бұрын
"...previous versions can be a goldmine" wow!
@soloapplications9466
@soloapplications9466 3 жыл бұрын
Awesome video, I loved you Tom
@ahmedahmedx9600
@ahmedahmedx9600 3 жыл бұрын
please which terminal theme tomnomnom used ?
@0xsunil
@0xsunil 3 жыл бұрын
Tom is best!
@mrrexder7910
@mrrexder7910 Жыл бұрын
#TOMNOMNOM FOR EVER!
@bughunt2568
@bughunt2568 2 жыл бұрын
could you please share your recon methodology you applied on redbull as target.
@Stas1983ful
@Stas1983ful 3 жыл бұрын
Very nice and interesting video bro!
@chiragagrawal7856
@chiragagrawal7856 3 жыл бұрын
Was it Recon Only ? Completely Mind Blowing stuff I saw today 🙌🙌🙌🙌🙌
@razmjumehdi9069
@razmjumehdi9069 Жыл бұрын
Hello Ben 😊. please make a video about "Finding origin IP behind AWS CDN", because i searched a lot, but i found only video about Cloudflair bypass 🙏
@ВисторАндреевич
@ВисторАндреевич 4 ай бұрын
hey!!))) where i can find list configfiles ?))
@jayesh6290
@jayesh6290 2 жыл бұрын
Here Kali Linux is used right ?
@Rashedulcss
@Rashedulcss 3 жыл бұрын
Thanks Tom!
@otukencoffee7273
@otukencoffee7273 3 жыл бұрын
Tom is such a wizard
@lufom
@lufom 2 жыл бұрын
Is he previewing the `find` results? Does anyone know how to do that?
@faris9859
@faris9859 3 жыл бұрын
anew installation as mentioned in github not working for me. Anyone facing issues?
@yaseenzubair8792
@yaseenzubair8792 3 жыл бұрын
Is tom operating himself on 1.5x?
@localmega5824
@localmega5824 2 жыл бұрын
Two masters at work
@rushikeshchaudhari476
@rushikeshchaudhari476 Жыл бұрын
How I can start with lve website bug bounty hunting
@n0w0nd3r5
@n0w0nd3r5 3 жыл бұрын
It would be cool if you could list every command tomnomnom uses in this video in the description with a timestamp so people can go directly to that section to see what it does.. Or just watch the video.
@n0w0nd3r5
@n0w0nd3r5 3 жыл бұрын
@hackR That's Cool.
@MrRaja
@MrRaja 2 жыл бұрын
Anyone got the list of all tomnomnom tools used in the video?
@orxanovn5057
@orxanovn5057 2 жыл бұрын
naham bro this is gf and fff methodology or bug bounty methodology?))))
@aminumuhammed3114
@aminumuhammed3114 3 жыл бұрын
I think this is the most useful technical video that is related to recon / bug bounty thank you @nahamsec thank you @tomnomnom
@remonsec1641
@remonsec1641 Жыл бұрын
insane 🔥
@saivenkatmaheshwaram9868
@saivenkatmaheshwaram9868 3 жыл бұрын
i didn't understand how he learn all this things and how he remember this all this commands and their particular options of a tools..
@parkour.11parkour58
@parkour.11parkour58 2 жыл бұрын
Probably because it's an hobby for him. When you're not forced to do something that you love, you usually become an expert at it.
@shrumplestiltskin7922
@shrumplestiltskin7922 Жыл бұрын
Where do we get the ass tool?
@CWLabs7209
@CWLabs7209 2 жыл бұрын
Still in a dilemma how to filter hosts on basis of response body from fff; since, every host is responding with 200 OK 😢.
@rajanrawal6396
@rajanrawal6396 2 жыл бұрын
they are not filtering hosts they are just checking those hosts which thet have got liittle bit doubt
@thatguycrash2255
@thatguycrash2255 3 жыл бұрын
tomnomnom the goat
@beelostlove
@beelostlove Жыл бұрын
So what's this worth this bug
@MrRaja
@MrRaja 2 жыл бұрын
I am not even sure what i am looking at. I know what he is looking at but i have no clue what to do with what he is looking at.
@Kas_Styles
@Kas_Styles 2 жыл бұрын
Just to point out that Auv5 is the Shopify security team member. Does anyone know if they have a twitter account?
@lilyrosestracke4591
@lilyrosestracke4591 2 жыл бұрын
...And this, ladies and gentlemen, is how you know you have failed recon101! 😅😜😉
@Kas_Styles
@Kas_Styles 2 жыл бұрын
@@lilyrosestracke4591 don't know why my comments keep getting deleted but I'll try posting it again
@Kas_Styles
@Kas_Styles 2 жыл бұрын
@@lilyrosestracke4591 I'm actually really good at recon. I have a public playlist (all osint videos) with at the time of writing this comment it's has 407 videos in it so from that you can tell that I know a lot about the topic.
@Kas_Styles
@Kas_Styles 2 жыл бұрын
@@lilyrosestracke4591 also, I have checked Google with Google dorks and Twitter and I didn't find anything related to the username.
@Kas_Styles
@Kas_Styles 2 жыл бұрын
@@lilyrosestracke4591 and another thing, you shouldn't be rude to others in general. I asked because I already did some research and I couldn't find it so I was asking. It's OK to ask questions, if anything its good and its how humans learn. Also, it's a social engineering skill which is used a lot in infosec so please don't share the idea that asking questions (after doing research and not finding anything useful/related) is bad because it's 100% not bad.
@farhonahmed5081
@farhonahmed5081 2 жыл бұрын
farhan ahmed was here at 10-31-22
@thenamehasbeenstolen4470
@thenamehasbeenstolen4470 Ай бұрын
he literally have 10 years + experience
@SrTCOT
@SrTCOT 3 жыл бұрын
In this video I learned a lot of things thank you so much Nahamsec
@learnwithpikes
@learnwithpikes 3 жыл бұрын
what's up behrouz ?? how are you ??
@beelostlove
@beelostlove Жыл бұрын
Hi did you miss me
@naveensaradhi6923
@naveensaradhi6923 3 жыл бұрын
We want more live with tom #request
@Kas_Styles
@Kas_Styles 2 жыл бұрын
Whoxy the website can get historical whois.
@beelostlove
@beelostlove Жыл бұрын
Just gave up her cover
@sadraasadi
@sadraasadi 3 жыл бұрын
Nice :)
@charonxxi5985
@charonxxi5985 3 жыл бұрын
💯
@imuser007
@imuser007 3 жыл бұрын
I like tom
@Aravindb26
@Aravindb26 3 жыл бұрын
Huh man ...
@Virdoex
@Virdoex 3 жыл бұрын
Hey @Nahamsec what you deal with 403 subdomains
@bobmarley8644
@bobmarley8644 3 жыл бұрын
Just keep bruteforcing for directories, maybe /login will return 200 or /api will return 400
@robinhood3841
@robinhood3841 3 жыл бұрын
i had a scenario where i have found a directory which returns 403 forbidden, so i kept brute forcing on that directory and eventually i got PhpMyAdmin mysql page and it was accessible for anyone and i was able to successfully login with a weak credentials :), thats why u shouldn't stop on a 403 they made it forbidden for a reason and simple miss configuration may give you a high result.
@Sakuraigi
@Sakuraigi 4 ай бұрын
​@@bobmarley8644and for 401?
@x00-p3z
@x00-p3z 3 жыл бұрын
🕵‍♀
@ThushyCyber
@ThushyCyber 3 жыл бұрын
Hi 👋
@LetsGoTech
@LetsGoTech 3 жыл бұрын
Problem number one I'm on Windows
@chiyoalice327
@chiyoalice327 2 жыл бұрын
Tom is not someone to follow . No My brain cells 😪 😭😭😭😭😭
@haxwizard2035
@haxwizard2035 3 жыл бұрын
😁😀😁😁😁😁😁
@sandeepsingh87
@sandeepsingh87 2 жыл бұрын
Na bhai tune subtitles diye, na tune tools explain kre, aur apni accent mei tum log bol kya rhe ho ghanta samajh nhi aa rha ... Khud hi seekh le bhai, jab ye samajh aa jae ki "padhate kaise hai" tab video upload kr dena
@hellb0y794
@hellb0y794 2 жыл бұрын
Ist: it's not his problem if you don't understand english first clear your basics then come here. they both are doing great work
@sandeepsingh87
@sandeepsingh87 2 жыл бұрын
@@hellb0y794 Fucking Dimwit, atleast read what I've written before commenting. I wrote "accent". Simplifying it for you, What it means is that, I do know English however I am having difficulty understanding their accent (Google the meaning of accent for more information) Also if you've even seen the starting of the video, you'll notice they are not teaching the basics here, they are talking about approaching a target i.e., their methodology. So, your statement about basics don't even make sense. I mean I don't mind you standing up for the hackers you admire but at least make some logical statement. Even I know these hackers know a lot more than me, but they have little to no idea "how to teach". This could've been structured into a nice course.
@ajaykumark107
@ajaykumark107 2 жыл бұрын
In the webpaste part the value he uses @1:06:26 are Code: [...document.querySelectorAll('div.g a:first-child')].map(n=>n.href) On Success: document.location=document.querySelectorAll('a#pnnext')[0].href;
@sushantr24
@sushantr24 2 жыл бұрын
Cat from-findomain | why i m unable to run the command
@snehadeepgolui3757
@snehadeepgolui3757 9 ай бұрын
github dork not working please help [...document.querySelectorAll('.codesearch-results a.v-align-middle')].map(n=>n.href) it is not working
The Blueprint to Your First $1,000+ Bounty
12:14
NahamSec
Рет қаралды 7 М.
Hacker101 - JavaScript for Hackers (Created by @STOKfredrik)
24:17
СКОЛЬКО ПАЛЬЦЕВ ТУТ?
00:16
Masomka
Рет қаралды 3,5 МЛН
ТВОИ РОДИТЕЛИ И ЧЕЛОВЕК ПАУК 😂#shorts
00:59
BATEK_OFFICIAL
Рет қаралды 6 МЛН
1, 2, 3, 4, 5, 6, 7, 8, 9 🙈⚽️
00:46
Celine Dept
Рет қаралды 115 МЛН
Ice Cream or Surprise Trip Around the World?
00:31
Hungry FAM
Рет қаралды 22 МЛН
The Truth About Bug Bounties
11:31
NahamSec
Рет қаралды 41 М.
Easy $500 Vulnerabilities! // How To Bug Bounty
13:19
NahamSec
Рет қаралды 80 М.
How much money I made in my 1st year of bug bounty? Bounty vlog #4
17:02
Bug Bounty Reports Explained
Рет қаралды 164 М.
What Should You Do After Recon?!
14:47
NahamSec
Рет қаралды 30 М.
$200 Bug Bounty PoC Worth | Full API Key Recon
14:28
SecShiv
Рет қаралды 14 М.
СКОЛЬКО ПАЛЬЦЕВ ТУТ?
00:16
Masomka
Рет қаралды 3,5 МЛН