Easy $500 Vulnerabilities! // How To Bug Bounty

  Рет қаралды 76,549

NahamSec

NahamSec

Күн бұрын

Пікірлер: 252
@NahamSec
@NahamSec Ай бұрын
📚 Purchase my course and learn about bug bounty hunting with over 11 hours of content, 100+ labs, and 15+ vulnerability types 👇 hhub.io/HWTl-LpLF0
@SyedShayan-yt3in
@SyedShayan-yt3in 11 ай бұрын
Hey! Would love to see the demo videos on each vulnerablity type.
@NahamSec
@NahamSec 11 ай бұрын
Noted!🫡🫡
@eviI_genius
@eviI_genius 11 ай бұрын
@@NahamSec yes we want demo, specially it would be great if you explain us XSS in deep like using the dev tools, inspecting the element, give us some deets about how backend XSS works, I really loved ur Bling XSS video :) it would be great if you build up on that
@darkalpha2701
@darkalpha2701 11 ай бұрын
@NahamSec I would really love to see demo video of IDOR
@karthik3387
@karthik3387 11 ай бұрын
Plse do vedio
@CruzNateChroniclles
@CruzNateChroniclles 11 ай бұрын
Video vulnerability examples would be great.
@marcelosmoniz
@marcelosmoniz 11 ай бұрын
● [1:41] Prerequisites: HTML, Web Technologies ● [1:57] #1 - XSS ● [4:03] #1(2) - CSRF ● ● [4:11] Burp Suit PRO : "Engagement tools" -> "Generate CSRF PoC" ● [6:22] #3 - IDOR ● [8:46] #4 - Authorization Issues ● [10:34] #5 - Leaked Credentials
@NizarZaidh
@NizarZaidh Ай бұрын
bro doing social service 👍
@minimanimo7636
@minimanimo7636 11 ай бұрын
It would be very helpful and interesting to have videos on: - How to quickly and efficiently write a bug report (templates, automation, AI and so on...) - What are the most common BBPs policies and practices for not breaking them (rate limit, automation limitations) - Burp suite: best extensions and when to use Thanks mate, love your videos and appreciate your work!
@vladiaveryanov610
@vladiaveryanov610 11 ай бұрын
Great one, would be great one to get those!
@MrFrankenstock
@MrFrankenstock 11 ай бұрын
Hands-on demo would definitely be a great way to absorb and ultimately solidify this content in the old brain! Thank you, Ben!
@MarkFoudy
@MarkFoudy 11 ай бұрын
Yes please do a demo of the vulnerabilities. Love your encouragement! Your videos always pump me up!
@NahamSec
@NahamSec 11 ай бұрын
Thanks for watching and thank you for being a channel member! 🙏
@MarkFoudy
@MarkFoudy 11 ай бұрын
of course! I hope to meet you at defcon in the future. Your content has been so impactful for me. @@NahamSec
@mianashhad9802
@mianashhad9802 11 ай бұрын
CSRF and IDOR hands-on tutorials would be interesting. Would love to see some handy tricks for when our attacks aren't working.
@omarmahmood4209
@omarmahmood4209 9 ай бұрын
Yes, would absolutely love a hands on video on each of all the topics! 1. XSS 2. CSRF 3. IDOR 4. Auth Issues 5. Leaked Creds
@OmphemetseMokene
@OmphemetseMokene 11 ай бұрын
Am planning on being a full time bug bounty hunter this coming January, but my piggy bank is still behind ..if i could i would take your bug bounty course to fortify my skills..,gotta say your vids really motivate me..cheers!! from Botswana
@bata3258
@bata3258 11 ай бұрын
dont
@DavitHayrapetyan-tc1uj
@DavitHayrapetyan-tc1uj 11 ай бұрын
this channel is literally a goldmine, don't understand how it's only 105k subscribers
@papafhill9126
@papafhill9126 11 ай бұрын
Honestly, I care less about learning the hands-on-tutorials about specific vulns, I would much rather see a tutorial on how to enumerate a target and suggestions on how to learn the technology the target is using. What questions should I be looking to answer about that tech? How to check for previous CVEs on that specific tech? Then maybe most importantly, how can track data flow of the target with that specific tech in mind. The issue with seeing tutorials on specific attack types seems to be trying to attack the same few input fields for hours but ignoring the all the technology used on that webpage that would likely tell me, "Hey, this page is pretty secure, maybe keep digging into other subs/ends."
@bertrandfossung1216
@bertrandfossung1216 11 ай бұрын
A hands on version of this video where you can make some labs will be highly appreciated. Thanks for the cool heads up !!
@azoosh
@azoosh 11 ай бұрын
Yes! I would very much want to see more hands on videos on these bugs :) Your videos are awesome always!
@alexandriarichard7671
@alexandriarichard7671 11 ай бұрын
Listen $500 is a lot for me and thank you so much for this video! I am going to focus on Blind XSS and start your Udemy course thank you!
@nihilizmfelsefesi
@nihilizmfelsefesi 2 ай бұрын
Did you make some money? How did it go?
@VinceOConnor
@VinceOConnor 11 ай бұрын
Yes, Love the content and would love you to do a demo of the vulnerabilities.
@TrailMix324
@TrailMix324 10 ай бұрын
Yes i would genuinely love to see and would definitely watch hands on demo videos of each vulnerability type
@darealist232003
@darealist232003 10 ай бұрын
Yes, can we get a demo video showing how to look for these vulnerabilities. I just got my Sec+ and have been interested in learning more about bug bounty. Thanks for the video and get up the great work.
@francisstocktilliii2413
@francisstocktilliii2413 6 ай бұрын
I would love to see a hands-on video of this. That's exciting to hear.
@ASecurityPro
@ASecurityPro 11 ай бұрын
Please do a hands on version of each vulnerability . Thank you man ❤
@MW-cs8zd
@MW-cs8zd 11 ай бұрын
I would love more videos like this from you. Very helpful. Thank you
@marijasilentj969
@marijasilentj969 11 ай бұрын
Yes please! You really talanted tutor! It easy to understand and follow you. Thank you a lot xx
@Cyber10791
@Cyber10791 11 ай бұрын
Needs brother these types of beginners friendly bugs and how to test for it it's very helpful. Looking forward too see these types of videos.
@nhlimon201
@nhlimon201 11 ай бұрын
Hey Ben, It will be better to share step by step resources to learn, master and get confidence of hunting for a specific bug. :) It would be a really awesome content. People like me sometimes get confused how they could master a bug and how to learn that at an insane level to get out of average hackers. So I hope you'll make this content in near future.
@hpuser-ui3tp
@hpuser-ui3tp 8 ай бұрын
Hey! I Would love to see the demo videos on each vulnerablity type.
@ralphandre4438
@ralphandre4438 11 ай бұрын
This is amazing! I want to find my find my first live bug, paid or not before the year end. I would love the video demo.
@rizvanhawaldar
@rizvanhawaldar 11 ай бұрын
If I get $500 based on content made available for then I will purchase your course based on that. Good luck to you too!
@litebulbentertainment
@litebulbentertainment 11 ай бұрын
Yes.... The content is really good... Looking for demo video on each vulnerability
@Z0nd4
@Z0nd4 8 ай бұрын
I like this content. Yes NahamSec, please do more videos. Thank you.
@akshaybhorde3787
@akshaybhorde3787 7 ай бұрын
It was very helpful for me. Good approach and techniques. Share your practical knowledge also.
@prasadande5690
@prasadande5690 11 ай бұрын
Yes Ben, Please also provide a demo of all those vulnerabilities :)
@alexaliwarlock
@alexaliwarlock 11 ай бұрын
That’d be awesome to see a demo video. Keep up the great and educational content! 🙌
@shriyanssudhi4545
@shriyanssudhi4545 11 ай бұрын
I'd love to see a video on Authorization issues. Though I've found some, but I feel I am missing something.
@shurikenhacks
@shurikenhacks 11 ай бұрын
Dude, clickbait us all you want. LOVE your videos! ❤‍🔥
@NahamSec
@NahamSec 11 ай бұрын
🙌
@sandeeppn1876
@sandeeppn1876 11 ай бұрын
Yes demo will be very helpful
@Marty_YouTuber
@Marty_YouTuber 11 ай бұрын
i want a hands-on version of this. I love these videos.
@panagiotismitkas5526
@panagiotismitkas5526 11 ай бұрын
Yes we want to see the hands on lab videos. About xss do you recommend kxss to see what is reflected?
@jeremyg737
@jeremyg737 11 ай бұрын
It would be awesome to see a video on encoding. Both from a defensive point of view and as a method of obfuscation.
@BoitumeloKhushiSelelo
@BoitumeloKhushiSelelo 11 ай бұрын
it would be helpfull if you can share demo on how to find this vulnerabilities, thank you
@JoseSanchez-ue9wk
@JoseSanchez-ue9wk 8 ай бұрын
Yes Naham we would love to see a hands on demo!
@IvanIvanov-ix5no
@IvanIvanov-ix5no 11 ай бұрын
I am looking forward to seeing a demo of those vulnerability types :)
@deekshithkalakotla9024
@deekshithkalakotla9024 6 ай бұрын
We want full video hands on each concept ❤
@hxmo656
@hxmo656 11 ай бұрын
For a new starter which bug bounty platform would you recommend; does it really matter whether we pick H1 / Bugcrowd VS a smaller place like Intigrity with less competition surely? 😊
@mynameisrezza
@mynameisrezza 11 ай бұрын
Gold! Cant wait to see the demo of those vulns, thanks ben!
@umegakweekene
@umegakweekene 11 ай бұрын
Yeahh, please do demo vids on them. And practical low hanging fruits
@mrashco
@mrashco 11 ай бұрын
Would love more in-depth videos on each topic mentioned!
@AlexaSiri-u3z
@AlexaSiri-u3z 11 ай бұрын
Thank you for the video. My question is -- How do we find XSS if X-XSS-Protection header is placed on every page of a webpage?
@jkong3553
@jkong3553 10 ай бұрын
Def would love to see the demo. Very informative
@ivanildofreitas7907
@ivanildofreitas7907 11 ай бұрын
Do a demo. We are eager to see that is possible. Nice and educational video by the way! Thanks.
@siddharthtayade3474
@siddharthtayade3474 11 ай бұрын
Yes. Need demo for the vulnerabilities.
@darklord5231
@darklord5231 11 ай бұрын
Yes we would like to see videos on each vulnerability
@lukeempty3386
@lukeempty3386 11 ай бұрын
Do you think burpsuite pro is worth while if im just starting out. Almost done with the CBBH course from htb and then doing portswigger labs. I need burpsuite pro to do the portswigger certification though and not sure if its worthwhile if im just starting out
@Sasquatchbones
@Sasquatchbones 8 ай бұрын
Honestly learned a lot really fast, clickbait was worth it 😂
@damavox
@damavox 11 ай бұрын
I love ya dude and you do a lot of for the community! But as someone who heard the same information from different sources what I would love to see is training, the secret sauce, and technique sharing. I know in bug bounty those things are held close to the chest but for someone stuck in the middle from beginner to practitioner, it would really help all us in that position to advance and level up. I would even be willing to pay. Thank you my friend Let's see that demo!
@mugstep
@mugstep 10 ай бұрын
You just unlocked how bug bounty hunters really make money.
@damavox
@damavox 10 ай бұрын
@@mugstep 🤣🤣 I'm going to assume lots of sarcasm in that comment to which in hindsight. I completely agree.
@damavox
@damavox 10 ай бұрын
@@mugstep I'm sure jason haddix's course is full of information like that. At least enough for one to develop their own secret sauce but also I want to hear from different sources.
@ГришаФомин-о5щ
@ГришаФомин-о5щ 7 ай бұрын
чувак, спасибо тебе за этот ролик! он полезный , круто! продолжай в том же духе 🤘 Хотелось бы подробнее с примерами о : SSRF, CSRF.
@Death_User666
@Death_User666 11 ай бұрын
Yes demos for all of them please please please I need to make extra money to afford my bills and I got 4 months left before I run out of money lol 😂 I want to learn and I want to be good Another video idea could be reading bug bounty scope of work properly sometimes they are confusing to understand fully
@muhammaddanialhazimbinmohd5737
@muhammaddanialhazimbinmohd5737 11 ай бұрын
Hands on video showing how to find these vulnerabilities plsss
@محمّد.09
@محمّد.09 11 ай бұрын
We want demo for each of those five.
@Mbro-dq2do
@Mbro-dq2do 9 ай бұрын
your videos are great Sec. Thanks for the knowledge
@trendyzawwad
@trendyzawwad 11 ай бұрын
it will be very much helpful to us, As a beginner we try to understand to of the vulnerability's and lost our most of the time's, If you do the hand's on video, may be it can push us to do more hand's on practice
@discount_ChadKroeger
@discount_ChadKroeger 11 ай бұрын
I love anything cyber so im in. Especially on current bugs and news....Also duhhh show us the hands on.
@gem0x00
@gem0x00 11 ай бұрын
Can you make videos for mastering a vulnerability or the most vulns needed alot of thinking to make the vuln have more impact
@feedomomics8103
@feedomomics8103 11 ай бұрын
Hey great video, I have a question how to get pentests or rather how to get into pen-testing.
@josephvelasquez2677
@josephvelasquez2677 11 ай бұрын
yes, please make demos on the mentioned vulns
@zukxxxx0
@zukxxxx0 11 ай бұрын
Actually, when played your videos liked them at the very beginning 😅😅😅
@CuriousByteYT
@CuriousByteYT 8 ай бұрын
Yes we do need a hands on explanation :)
@hailelleultesera8643
@hailelleultesera8643 11 ай бұрын
make a video on authorization issues I would definitely watch that
@youssefm5079
@youssefm5079 11 ай бұрын
Yeeees hands on videos and thank you so much ffor this content
@NahamSec
@NahamSec 11 ай бұрын
Glad you like them!
@socalledhacker
@socalledhacker 11 ай бұрын
Now i am waiting for nxt Monday
@NahamSec
@NahamSec 11 ай бұрын
Already?
@GoliTech
@GoliTech 11 ай бұрын
Hi Ben, thanks a lot for the video, please make hands-on as well.
@NahamSec
@NahamSec 11 ай бұрын
Noted!
@fahadfahad2000
@fahadfahad2000 11 ай бұрын
Hello NahamSec, i would like to thank you for this video. Kindly please make video how to bid for the bounty on bugcrowed or intigriti platform from start to send report. Thanks
@SohanRana-v6u
@SohanRana-v6u 11 ай бұрын
can you please make a video on authorization ?
@heatherryan9820
@heatherryan9820 11 ай бұрын
Great video. Appreciate the advice, and yes I'd like to see a hands-on. Any help I can get is always welcome.... Please?
@PhantasmagoriaVisions
@PhantasmagoriaVisions 11 ай бұрын
Hands-on demo would definitely be a great
@jaredlee8883
@jaredlee8883 11 ай бұрын
Do a hands-on video of each please!
@husseindhooma5816
@husseindhooma5816 11 ай бұрын
Hi Ben, awesome video once again, would love for you to post more content on IDORs and Authorization Issues. Just by the way you don't need to click bait me to get to watch your videos, the whole reason I subscribe to you is cos your content is excellent. I would watch it anyways and support you any day. Would some day love to make a $500 Bounty (IA) but it takes a lot of practice and I just need to get my butt away from streaming crap in the evenings and studying. Thank you once again. Keep up the great work. 😉
@j4ck_d4niels
@j4ck_d4niels 11 ай бұрын
maybe web tech video will be awesome, some common places to look for, like in swagger ui have xss with low-medium impact
@INTJames
@INTJames 10 ай бұрын
If these are the most common bug bounty skills then does that mean most bounties are web based? Or is the web just the first point of contact when trying to find a company's real internal servers? I guess companies internal servers aren't usually exposed for bounty hunting as often as their web servers ?
@SHADOW-uk2rq
@SHADOW-uk2rq 11 ай бұрын
Hands on videos yessssss
@TaminHay-hc7bq
@TaminHay-hc7bq 11 ай бұрын
What do you think about tool nuclei?
@prakhar0x01
@prakhar0x01 11 ай бұрын
appreciate Ben, Really amazing content.., well we want more content like this, but missing streams and interviews.
@aquatester
@aquatester 11 ай бұрын
demo on each vulnerability
@MayankKumar-tl5rx
@MayankKumar-tl5rx Ай бұрын
How to find website vulnerability without burp suite?
@elkins540
@elkins540 11 ай бұрын
I will like a hands on video of this type of vulnerabilities.
@aavezsheikh5781
@aavezsheikh5781 11 ай бұрын
Yes demo of all the vulnerabilities plz
@Ucsd4life
@Ucsd4life 10 ай бұрын
Demo video please! This is awesome content!
@marlinshanklin-ww7em
@marlinshanklin-ww7em 10 ай бұрын
500$ works for me let's get started.
@arianahmadi1227
@arianahmadi1227 11 ай бұрын
It would be amazing if we see examples from u
@ismailsaid6389
@ismailsaid6389 11 ай бұрын
Man, for god sake i love your content
@lakshaysiwach3652
@lakshaysiwach3652 11 ай бұрын
yes absolutely a demo would be great
@RichardinSA
@RichardinSA 10 ай бұрын
Course on Udemy hasn't been updated in 2 years? Have things not changed much?
@Drakan1990
@Drakan1990 11 ай бұрын
Want to see those demos! 🤘🏻
@francisstocktilliii2413
@francisstocktilliii2413 6 ай бұрын
Yes I would love to see a demo
@ElliotRodger-cz7rb
@ElliotRodger-cz7rb 11 ай бұрын
Hey Ben great video, we understand you cannot show real-time bug hunting, can you show us finding real time VDP bugs. I think actually see you do it would me really motivating. Thanks a lot and keep it up!
@jannmoon
@jannmoon 11 ай бұрын
He can't, its mostly because if someone sees the vulnerability they can go and hack the company before they fix it not because someone might jack your report And take your cash before you can report it . Cool name by the way 👽👽👽
@NahamSec
@NahamSec 11 ай бұрын
I have done this before :) Check out my Redbull video, REDACTED, and bug bounty stories!
@snekyff1682
@snekyff1682 11 ай бұрын
can you explain more about API keys for compenies i can scan any domain and get a lot of keys letterly any domain
@richowens5254
@richowens5254 11 ай бұрын
i would love to see a hands on version. I've had hands on computers and networks since 1983, compulsively consume bug bounty education, have hunted multiple bounty programs and just can't even seem to even find dups....i can't, won't, and refuse to give up on this. i've always been the computer/network tech/ guy on the blue side and just can't help but to think i just can't seem to think nefariously enough to be the "red-teamer"... wtf (btw, you are my fucking hero yo!)
@jamesdriscoll1658
@jamesdriscoll1658 10 ай бұрын
Yes please do a demo video.
@Progressive_Entrepreneur
@Progressive_Entrepreneur 11 ай бұрын
Drop that video ! I’m a visual learner 😊
@5checktech357
@5checktech357 7 ай бұрын
Yes, please, the video will be awesome.
@IrishOverkilled
@IrishOverkilled 11 ай бұрын
Would like to see a demo video and I like the content
@naurismetlans8623
@naurismetlans8623 11 ай бұрын
Very good video, would like to see demos.
The Beginner's Guide to Blind XSS (Cross-Site Scripting)
21:21
Finding Your First Bug
9:14
NahamSec
Рет қаралды 44 М.
Seja Gentil com os Pequenos Animais 😿
00:20
Los Wagners
Рет қаралды 45 МЛН
Mom had to stand up for the whole family!❤️😍😁
00:39
Kluster Duo #настольныеигры #boardgames #игры #games #настолки #настольные_игры
00:47
Cross-Site Scripting (XSS) Explained! // How to Bug Bounty
14:43
This Bug Got Me A $30,000 Bounty
12:41
NahamSec
Рет қаралды 14 М.
How Can Fuzzing Help You Find Hidden API Endpoints?
9:18
How much money I made in my 1st year of bug bounty? Bounty vlog #4
17:02
Bug Bounty Reports Explained
Рет қаралды 160 М.
I used AI to hack this website...
23:23
Tech Raj
Рет қаралды 104 М.
The Truth About Bug Bounties
11:31
NahamSec
Рет қаралды 39 М.
Access Location, Camera  & Mic of any Device 🌎🎤📍📷
15:48
zSecurity
Рет қаралды 2,5 МЛН
Seja Gentil com os Pequenos Animais 😿
00:20
Los Wagners
Рет қаралды 45 МЛН