Live Recon and Automation on Shopify's Bug Bounty Program with

  Рет қаралды 158,116

NahamSec

NahamSec

3 жыл бұрын

Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training
Live Every Friday, Saturday Sunday and Monday on Twitch:
/ nahamsec
Free $100 DigitalOcean Credit:
m.do.co/c/3236319b9d0b
Follow me on social media:
/ nahamsec
/ nahamsec
twitch.com/nahamsec
hackerone.com/nahamsec
/ nahamsec1
Github:
github.com/nahamsec
Nahamsec's Discord:
discordapp.com/invite/ucCz7uh

Пікірлер: 119
@kharbandaumang
@kharbandaumang 3 жыл бұрын
this is some GOD-LEVEL recon !!! We want more sessions from Tom. Thanks nahamsec for bringing this to the community and thanks Tom for sparing your time for this!!!
@alexander_adnan
@alexander_adnan Жыл бұрын
Lol .. 😂…GOD level would leave you speechless
@godspeed2124
@godspeed2124 Жыл бұрын
@@alexander_adnan what god level according to you?
@65hammad
@65hammad 11 ай бұрын
@@alexander_adnanyou don't have a clue then. For mass recon, this is GOD-tier automation. These guys can even automate the entire process if they wanted.
@alexander_adnan
@alexander_adnan 5 ай бұрын
@@godspeed2124 looks like you will find out before others. Not a good idea to do reverse psychology, with strangers. I would be rational though, there’s no recipe for recon, it depends on your target while Technics matters less than the potential.
@cr4zy_0o
@cr4zy_0o 2 жыл бұрын
The calmness that Tom have is really unique, great and fancy. + The way he do his things is really epic Really a great guy
@hayben7046
@hayben7046 2 жыл бұрын
Thank you both for this great content. We want more videos with @TomNomNom.
@netoeli
@netoeli 3 жыл бұрын
fantastic video , Tom really knows his stuff
@franco2179
@franco2179 3 жыл бұрын
It's funny because I can tell from Nahamsec's faces that he just loves Tomnomnom. At the same time it makes him laugh that he is so calm when explaining things.
@NahamSec
@NahamSec 3 жыл бұрын
Haha! Tom is one of the most genuine and nicest people I have had on the show.
@chasejensen88
@chasejensen88 2 жыл бұрын
I think he's also realizing the greatness he's capturing at the moment, he isn't fully comprehending it yet but he knows it.
@piusgabula
@piusgabula 2 жыл бұрын
This is byfar the most incredible live recon i have watched on youtube
@IBDLFSEragon
@IBDLFSEragon Ай бұрын
Mind blowing. Thank you so much for giving back to community.
@HenryLawrenceHMBL
@HenryLawrenceHMBL 2 жыл бұрын
I would love to be a Shopify developer watching this unfold
@rajanrawal6396
@rajanrawal6396 2 жыл бұрын
amazing, this could be probably one of the biggest information that i have ever been given. we need such playlist more and more in upcoming days. i hope i made you understand the things that i wanted to make you understand.. again, we need such playlist more and more in upcoming days.
@xrfox1634
@xrfox1634 3 жыл бұрын
I love this man!
@ashleypursell9702
@ashleypursell9702 3 жыл бұрын
i was literaly looking for something just like anew to use in my automation since i run scans everday i want to add stuff to already existing txt files. i have seen people use it and idk why i only found out about it rn, great video thanks so much
@vonniehudson
@vonniehudson 3 жыл бұрын
“ass, is that a new tool to compete with meg? I don’t know” had me rolling lololz
@baolamminh1146
@baolamminh1146 3 жыл бұрын
I improve my bash skill much when watching this video. thanks Tomnomnom & Nahamsec
@bertrandfossung1216
@bertrandfossung1216 3 жыл бұрын
This is epic!! I've have to watch this video over 10 times just to understand Tomnomnom's recon process. The guy is really really good at what he does. Thanks @nahamsec & @Tomnomnom🙏🏽🙏🏽🙏🏽
@ca7986
@ca7986 3 жыл бұрын
Tom is really really good! He knows what he is doing! Amazing! Thanks Nahamsec for this video.
@shuvamadhikari2662
@shuvamadhikari2662 2 жыл бұрын
Every week i rewatch your videos; I am learning new things 💙.
@SankizTime
@SankizTime Жыл бұрын
hora
@shuvamadhikari2662
@shuvamadhikari2662 Жыл бұрын
@@SankizTime :D
@jeffreynoose
@jeffreynoose 2 жыл бұрын
I can watch these 50 times daily I love nomnom
@gifbfbvhvhdhfhfjffjfnfhfb515
@gifbfbvhvhdhfhfjffjfnfhfb515 Жыл бұрын
best video ive seen in a long time
@Stas1983ful
@Stas1983ful 3 жыл бұрын
Very nice and interesting video bro!
@soloapplications9466
@soloapplications9466 3 жыл бұрын
Awesome video, I loved you Tom
@danieltamang2289
@danieltamang2289 2 жыл бұрын
finally, the two underrated hunters!!
@abdul-rahman7608
@abdul-rahman7608 Жыл бұрын
Tom is a genius I must confess 🖤💯
@Rashedulcss
@Rashedulcss 3 жыл бұрын
Thanks Tom!
@joefawcett2191
@joefawcett2191 11 ай бұрын
these vim and bash skills are really something to behold
@crusader_
@crusader_ 3 жыл бұрын
Could you please upload all the other recons
@SrTCOT
@SrTCOT 3 жыл бұрын
In this video I learned a lot of things thank you so much Nahamsec
@samfisher8426
@samfisher8426 Жыл бұрын
maan seeing how tom is working makes me feel down, this dude is so good
@ar-uh1dj
@ar-uh1dj 3 жыл бұрын
He is truly a Genius!!!!!!!
@mateuszwasielewski7193
@mateuszwasielewski7193 8 ай бұрын
I started watching this with hope of learning something. Ended with depression and one conclusion - I should stop learning this stuff if I'm gonna need to compete with maaany, maaany people as Tom. And as he said - it was his first attempt since like two years ago. I would need like a week to check all the things that he checked. Now I get it why entry-level positions needs few years of experience but in the same time I don't see a way to get this experience
@purplethunder778
@purplethunder778 5 ай бұрын
If you think that the competitors out there are all as skillful as tom . You are very wrong
@remonsec1641
@remonsec1641 Жыл бұрын
insane 🔥
@ahmedahmedx9600
@ahmedahmedx9600 3 жыл бұрын
please which terminal theme tomnomnom used ?
@0xsunil
@0xsunil 3 жыл бұрын
Tom is best!
@theys6837
@theys6837 3 жыл бұрын
*TomNomNom* is a FKIN G 💯👏
@BnayaProgramming
@BnayaProgramming 3 жыл бұрын
Start at 5:59
@chiragagrawal7856
@chiragagrawal7856 3 жыл бұрын
Was it Recon Only ? Completely Mind Blowing stuff I saw today 🙌🙌🙌🙌🙌
@otukencoffee7273
@otukencoffee7273 2 жыл бұрын
Tom is such a wizard
@affulsamuel728
@affulsamuel728 7 ай бұрын
That is why Hacking is time and patience game. i love the way he spend days to come on this i love this channel
@The1994mattj
@The1994mattj 3 ай бұрын
Would be interesting to see how different the process/tools look 3 years on.
@localmega5824
@localmega5824 2 жыл бұрын
Two masters at work
@lufom
@lufom 2 жыл бұрын
Is he previewing the `find` results? Does anyone know how to do that?
@bughunt2568
@bughunt2568 2 жыл бұрын
could you please share your recon methodology you applied on redbull as target.
@faris9859
@faris9859 2 жыл бұрын
anew installation as mentioned in github not working for me. Anyone facing issues?
@sadraasadi
@sadraasadi 2 жыл бұрын
Nice :)
@jayesh6290
@jayesh6290 Жыл бұрын
Here Kali Linux is used right ?
@MrRaja
@MrRaja 2 жыл бұрын
Anyone got the list of all tomnomnom tools used in the video?
@ggmaxx66
@ggmaxx66 3 жыл бұрын
"...previous versions can be a goldmine" wow!
@thatguycrash2255
@thatguycrash2255 3 жыл бұрын
tomnomnom the goat
@charonxxi5985
@charonxxi5985 3 жыл бұрын
💯
@rushikeshchaudhari476
@rushikeshchaudhari476 Жыл бұрын
How I can start with lve website bug bounty hunting
@thenarrowgate3063
@thenarrowgate3063 4 ай бұрын
I wish I had vim mastered in this way, I use nano which has some of the same features but vim has way more flexibility it's a language all it's own and it's why hackers prefer it, I mean true command based hackers..windows has spoiled this generation..nothing wrong with a GUI but hacking is about control and putting that level of control in a GUI is a major resource hog..TOM you are a dying breed, my hats off to you..grey that is
@mrrexder7910
@mrrexder7910 Жыл бұрын
#TOMNOMNOM FOR EVER!
@naveensaradhi6923
@naveensaradhi6923 3 жыл бұрын
We want more live with tom #request
@user-jr3qf7cq5q
@user-jr3qf7cq5q 17 күн бұрын
hey!!))) where i can find list configfiles ?))
@shrumplestiltskin7922
@shrumplestiltskin7922 Жыл бұрын
Where do we get the ass tool?
@imuser007
@imuser007 3 жыл бұрын
I like tom
@razmjumehdi9069
@razmjumehdi9069 10 ай бұрын
Hello Ben 😊. please make a video about "Finding origin IP behind AWS CDN", because i searched a lot, but i found only video about Cloudflair bypass 🙏
@beelostlove
@beelostlove Жыл бұрын
So what's this worth this bug
@user-xd4sb5rq4o
@user-xd4sb5rq4o 3 жыл бұрын
🕵‍♀
@shuvamadhikari2662
@shuvamadhikari2662 2 жыл бұрын
Still in a dilemma how to filter hosts on basis of response body from fff; since, every host is responding with 200 OK 😢.
@rajanrawal6396
@rajanrawal6396 Жыл бұрын
they are not filtering hosts they are just checking those hosts which thet have got liittle bit doubt
@farhonahmed5081
@farhonahmed5081 Жыл бұрын
farhan ahmed was here at 10-31-22
@orxanovn5057
@orxanovn5057 2 жыл бұрын
naham bro this is gf and fff methodology or bug bounty methodology?))))
@saivenkatmaheshwaram9868
@saivenkatmaheshwaram9868 3 жыл бұрын
i didn't understand how he learn all this things and how he remember this all this commands and their particular options of a tools..
@parkour.11parkour58
@parkour.11parkour58 2 жыл бұрын
Probably because it's an hobby for him. When you're not forced to do something that you love, you usually become an expert at it.
@CyberSecForce
@CyberSecForce 3 жыл бұрын
Hi 👋
@n0w0nd3r5
@n0w0nd3r5 3 жыл бұрын
It would be cool if you could list every command tomnomnom uses in this video in the description with a timestamp so people can go directly to that section to see what it does.. Or just watch the video.
@n0w0nd3r5
@n0w0nd3r5 3 жыл бұрын
@hackR That's Cool.
@learnwithpikes
@learnwithpikes 3 жыл бұрын
what's up behrouz ?? how are you ??
@Kas_Styles
@Kas_Styles 2 жыл бұрын
Just to point out that Auv5 is the Shopify security team member. Does anyone know if they have a twitter account?
@lilyrosestracke4591
@lilyrosestracke4591 2 жыл бұрын
...And this, ladies and gentlemen, is how you know you have failed recon101! 😅😜😉
@Kas_Styles
@Kas_Styles 2 жыл бұрын
@@lilyrosestracke4591 don't know why my comments keep getting deleted but I'll try posting it again
@Kas_Styles
@Kas_Styles 2 жыл бұрын
@@lilyrosestracke4591 I'm actually really good at recon. I have a public playlist (all osint videos) with at the time of writing this comment it's has 407 videos in it so from that you can tell that I know a lot about the topic.
@Kas_Styles
@Kas_Styles 2 жыл бұрын
@@lilyrosestracke4591 also, I have checked Google with Google dorks and Twitter and I didn't find anything related to the username.
@Kas_Styles
@Kas_Styles 2 жыл бұрын
@@lilyrosestracke4591 and another thing, you shouldn't be rude to others in general. I asked because I already did some research and I couldn't find it so I was asking. It's OK to ask questions, if anything its good and its how humans learn. Also, it's a social engineering skill which is used a lot in infosec so please don't share the idea that asking questions (after doing research and not finding anything useful/related) is bad because it's 100% not bad.
@yaseenzubair8792
@yaseenzubair8792 2 жыл бұрын
Is tom operating himself on 1.5x?
@MrRaja
@MrRaja 2 жыл бұрын
I am not even sure what i am looking at. I know what he is looking at but i have no clue what to do with what he is looking at.
@baravind719
@baravind719 3 жыл бұрын
Huh man ...
@beelostlove
@beelostlove Жыл бұрын
Hi did you miss me
@Kas_Styles
@Kas_Styles 2 жыл бұрын
Whoxy the website can get historical whois.
@beelostlove
@beelostlove Жыл бұрын
Just gave up her cover
@haxwizard2035
@haxwizard2035 3 жыл бұрын
😁😀😁😁😁😁😁
@Virdoex
@Virdoex 3 жыл бұрын
Hey @Nahamsec what you deal with 403 subdomains
@bobmarley8644
@bobmarley8644 3 жыл бұрын
Just keep bruteforcing for directories, maybe /login will return 200 or /api will return 400
@robinhood3841
@robinhood3841 3 жыл бұрын
i had a scenario where i have found a directory which returns 403 forbidden, so i kept brute forcing on that directory and eventually i got PhpMyAdmin mysql page and it was accessible for anyone and i was able to successfully login with a weak credentials :), thats why u shouldn't stop on a 403 they made it forbidden for a reason and simple miss configuration may give you a high result.
@Sakuraigi
@Sakuraigi Ай бұрын
​@@bobmarley8644and for 401?
@LetsGoTech
@LetsGoTech 2 жыл бұрын
Problem number one I'm on Windows
@chiyoalice327
@chiyoalice327 Жыл бұрын
Tom is not someone to follow . No My brain cells 😪 😭😭😭😭😭
@sandeepsingh87
@sandeepsingh87 Жыл бұрын
Na bhai tune subtitles diye, na tune tools explain kre, aur apni accent mei tum log bol kya rhe ho ghanta samajh nhi aa rha ... Khud hi seekh le bhai, jab ye samajh aa jae ki "padhate kaise hai" tab video upload kr dena
@hellb0y794
@hellb0y794 Жыл бұрын
Ist: it's not his problem if you don't understand english first clear your basics then come here. they both are doing great work
@sandeepsingh87
@sandeepsingh87 Жыл бұрын
@@hellb0y794 Fucking Dimwit, atleast read what I've written before commenting. I wrote "accent". Simplifying it for you, What it means is that, I do know English however I am having difficulty understanding their accent (Google the meaning of accent for more information) Also if you've even seen the starting of the video, you'll notice they are not teaching the basics here, they are talking about approaching a target i.e., their methodology. So, your statement about basics don't even make sense. I mean I don't mind you standing up for the hackers you admire but at least make some logical statement. Even I know these hackers know a lot more than me, but they have little to no idea "how to teach". This could've been structured into a nice course.
@aminumuhammed3114
@aminumuhammed3114 3 жыл бұрын
I think this is the most useful technical video that is related to recon / bug bounty thank you @nahamsec thank you @tomnomnom
@ajaykumark107
@ajaykumark107 Жыл бұрын
In the webpaste part the value he uses @1:06:26 are Code: [...document.querySelectorAll('div.g a:first-child')].map(n=>n.href) On Success: document.location=document.querySelectorAll('a#pnnext')[0].href;
@sushantr24
@sushantr24 2 жыл бұрын
Cat from-findomain | why i m unable to run the command
@snehadeepgolui3757
@snehadeepgolui3757 5 ай бұрын
github dork not working please help [...document.querySelectorAll('.codesearch-results a.v-align-middle')].map(n=>n.href) it is not working
Mama vs Son vs Daddy 😭🤣
00:13
DADDYSON SHOW
Рет қаралды 50 МЛН
What Should You Do After Recon?!
14:47
NahamSec
Рет қаралды 27 М.
The Truth About Bug Bounties
11:31
NahamSec
Рет қаралды 31 М.
The key to succeed in bug bounty - @NahamSec
1:10:22
Bug Bounty Reports Explained
Рет қаралды 12 М.
Easy $500 Vulnerabilities! // How To Bug Bounty
13:19
NahamSec
Рет қаралды 67 М.
Fundamentals of Bug Bounty Recon
12:39
codingo
Рет қаралды 26 М.
Live Recon: Hacking a Bank (Ethically)
1:48:23
NahamSec
Рет қаралды 29 М.
Samsung laughing on iPhone #techbyakram
0:12
Tech by Akram
Рет қаралды 7 МЛН
Хакер взломал компьютер с USB кабеля. Кевин Митник.
0:58
Последний Оплот Безопасности
Рет қаралды 2,3 МЛН
Частая ошибка геймеров? 😐 Dareu A710X
1:00
Вэйми
Рет қаралды 5 МЛН
Как удвоить напряжение? #электроника #умножитель
1:00
Hi Dev! – Электроника
Рет қаралды 1,1 МЛН
ноутбуки от 7.900 в тг laptopshoptop
0:14
Ноутбуковая лавка
Рет қаралды 3,5 МЛН