#NahamCon2024

  Рет қаралды 6,679

NahamSec

NahamSec

Күн бұрын

LIKE and SUBSCRIBE with NOTIFICATIONS ON if you enjoyed the video! 👍
For many hackers, changing the redirect_uri to an attacker-controlled host is the only attack they know. But in 2024 it won't work. We have to work harder - exploit and chain multiple smaller bugs together to get the account takeover. Those chains will be the topic of this talk.
📚 If you want to learn bug bounty hunting from me: bugbounty.nahamsec.training
💻 If you want to practice soem of my free labs and challenges: app.hacking.hub.io
🔗 LINKS:
📖 MY FAVORITE BOOKS:
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities -amzn.to/3Re8Pa2
Hacking APIs: Breaking Web Application Programming Interfaces - amzn.to/45g4bOr
Black Hat GraphQL: Attacking Next Generation APIs - amzn.to/455F9l3
🍿 WATCH NEXT:
If I Started Bug Bounty Hunting in 2024, I'd Do this - • If I Started Bug Bount...
2023 How to Bug Bounty - • How to Bug Bounty in 2023
Bug Bounty Hunting Full Time - youtu.be/watch...
Hacking An Online Casino - youtu.be/watch...
WebApp Pentesting/Hacking Roadmap - youtu.be/watch...
MY OTHER SOCIALS:
🌍 My website - www.nahamsec.com/
👨‍💻 My free labs - app.hackinghub...
🐦 Twitter - / nahamsec
📸 Instagram - / nahamsec
👨‍💻 Linkedin - / nahamsec
WHO AM I?
If we haven't met before, hey 👋! I'm Ben, most people online know me online as NahamSec. I'm a hacker turned content creator. Through my videos on this channel, I share my experience as a top hacker and bug bounty hunter to help you become a better and more efficient hacker.
FYI: Some of the links I have in the description are affiliate links that I get a a percentage from.

Пікірлер: 15
@ZarakKhanNiazi
@ZarakKhanNiazi 8 ай бұрын
BBRE guy is the only person who cares about eyesight of content consumers, he used large fonts which we can read easily
@BugBountyReportsExplained
@BugBountyReportsExplained 3 ай бұрын
You're welcome ;)
@Zizo8182
@Zizo8182 29 күн бұрын
thanks both of you for sharing - great video
@KarahannAe
@KarahannAe 7 ай бұрын
18:24 if anyone else was also confused when he says POST-AUTH REDIRECT he is talking about after the Oauth dance is over, he doesnt mean POST based oauth flow.
@BugBountyReportsExplained
@BugBountyReportsExplained 3 ай бұрын
I see how this can be confusing. Since then, I have changed how I say this part to after-auth redirect to be clearer.
@so3litude_
@so3litude_ 8 ай бұрын
Even though the state parameter is present in the request you should always check for CSRF I've found many targets vulnerable to this . Most of the people leave as soon as they see State parameter in the request. This happens because of misconfig in OUath flow where it doesen't validate the state parameter server side . It only checks if it is present or not.
@BugBountyReportsExplained
@BugBountyReportsExplained 8 ай бұрын
very true! The presence doesn't mean it's checked
@heller64
@heller64 8 ай бұрын
most site now uses strict url validation on redirect_uri not even extra dot can be added btw thx greg
@MarkFoudy
@MarkFoudy 8 ай бұрын
Thanks Ben!
@MianHizb
@MianHizb 7 ай бұрын
this was nice
@bughunter9766
@bughunter9766 8 ай бұрын
Thanks Ben and Enjoooooooy 😊
@ZarakKhanNiazi
@ZarakKhanNiazi 8 ай бұрын
I love and enjoy hearing him say enjoy
@bughunter9766
@bughunter9766 8 ай бұрын
@@ZarakKhanNiazi All of us like it 😁✌️✌️✌️
@InfoSecIntel
@InfoSecIntel 8 ай бұрын
Hey brother can you add these to the playlist
@hamzabohra5083
@hamzabohra5083 8 ай бұрын
Second
#NahamCon2024: GraphQL is the New PHP | @0xlupin
26:17
NahamSec
Рет қаралды 9 М.
Cat mode and a glass of water #family #humor #fun
00:22
Kotiki_Z
Рет қаралды 42 МЛН
It’s all not real
00:15
V.A. show / Магика
Рет қаралды 20 МЛН
Une nouvelle voiture pour Noël 🥹
00:28
Nicocapone
Рет қаралды 9 МЛН
I'm GPU Mining QUAI... How to GPU Mine QUAI on Hiveos!
15:53
Modern Mining
Рет қаралды 3,2 М.
#NahamCon2024: .js Files Are Your Friends | @zseano
24:04
NahamSec
Рет қаралды 11 М.
This 'Realistic' Web CTF Was Impossible!
23:36
NahamSec
Рет қаралды 7 М.
OAuth 2.0 explained with examples
10:03
ByteMonk
Рет қаралды 186 М.
#NahamCon2024: Practical AI for Bounty Hunters | @jhaddix
37:26
Watch me hack a Wordpress website..
28:52
Tech Raj
Рет қаралды 312 М.
Access Location, Camera  & Mic of any Device 🌎🎤📍📷
15:48
zSecurity
Рет қаралды 2,9 МЛН
What is OSINT? (With Examples)
18:56
NahamSec
Рет қаралды 12 М.
Cat mode and a glass of water #family #humor #fun
00:22
Kotiki_Z
Рет қаралды 42 МЛН