Watch me hack a bug bounty-like target from scratch.

  Рет қаралды 27,072

thehackerish

thehackerish

3 жыл бұрын

In this video, I will demonstrate a bug bounty hunting methodology on a CTF website that mimics a bug bounty target. I will start from scratch and become admin on multiple web applications. Many techniques will be used: Subdomain enumeration, directory bruteforcing, using tools such as assetfinder, ffuf and Burp Suite Intruder.
- Download your FREE Web hacking LAB: thehackerish.com/owasp-top-10...
- Read more on the blog: thehackerish.com/my-bug-bount...
- Support this work: thehackerish.com/how-to-support
- Facebook Page: / thehackerish
- Follow us on Twitter: / thehackerish
- Listen on Anchor: anchor.fm/thehackerish- Listen on Spotify: open.spotify.com/show/4Ht8jEb...
- Listen on Google Podcasts: podcasts.google.com/?feed=aHR...
Thumbnail photo by Andrea Piacquadio from Pexels

Пікірлер: 55
@itsalgore
@itsalgore 2 ай бұрын
This is the most educative video so far, been going in circles
@CristiVladZ
@CristiVladZ 3 жыл бұрын
Looking forward to reading it!
@goooooo9197
@goooooo9197 3 жыл бұрын
I think you don’t do ctf you do real thing called bug bounty
@TheWhaleon
@TheWhaleon Жыл бұрын
I've taken a few bounty Udemy courses and have watched a ton of video guides on youtube and other places. I wouldn't say I'm new to the content but I'm definitely not a professional when it comes to bug bounties. I'm not even 5 minutes into this video and have already dubbed this one of the best beginner videos I've seen so far. Why? Because the step-by-step example methodology and information is gold.. Not really found in other places as far as I've seen so far. Other typically explain their seemingly complex methodology that they have adopted, and beginner courses tend to focus on very beginner content. This has been middle ground information that is really useful! Looking forward to more!
@thehackerish
@thehackerish Жыл бұрын
I am glad your found the content helpful! Thanks for sharing your feedback!
@bertrandfossung1216
@bertrandfossung1216 3 жыл бұрын
This video met me at the right time. Thank you very much. I'll definitely learn a lot from it.
@thehackerish
@thehackerish 3 жыл бұрын
Glad the timing was perfect for you ! Enjoy
@avijitmazumder1762
@avijitmazumder1762 2 жыл бұрын
Just the video I wanted. Thanks.
@medjassertoubib4467
@medjassertoubib4467 3 жыл бұрын
those are the kind of video we want to see . great video dude wish you all the best
@thehackerish
@thehackerish 3 жыл бұрын
Thanks!
@Xplo8E
@Xplo8E 3 жыл бұрын
Finally what I wanted I got🔥❤️👍
@a.for.arun_
@a.for.arun_ 2 жыл бұрын
Great content 👍🏻
@xrfox1634
@xrfox1634 3 жыл бұрын
Thanks for the video!
@thehackerish
@thehackerish 3 жыл бұрын
Enjoy! my pleasure :)
@jissjose1382
@jissjose1382 3 жыл бұрын
This was the one i searching for
@thehackerish
@thehackerish 3 жыл бұрын
I am glad you liked it :) Enjoy!
@user-tg6vk4ig3i
@user-tg6vk4ig3i 3 жыл бұрын
Awesome. Maybe you can show us more challenges from this website and how you solve them:) It was a great help for me understanding how an Bug Bounty researcher is thinking!
@thehackerish
@thehackerish 3 жыл бұрын
As much as I'd love to, this might spoil the fun for you and skew the leaderboard on the website. I will think about it though.
@user-tg6vk4ig3i
@user-tg6vk4ig3i 3 жыл бұрын
@@thehackerish Thank you so much!
@goodboy8833
@goodboy8833 3 жыл бұрын
Very Good Quality content.
@thehackerish
@thehackerish 3 жыл бұрын
Thank you
@ahmedehab6899
@ahmedehab6899 3 жыл бұрын
great video i'm Looking forward to reading the book
@thehackerish
@thehackerish 3 жыл бұрын
Hope you enjoy it!
@xbparmar
@xbparmar 3 жыл бұрын
Awesome ❤️
@thehackerish
@thehackerish 3 жыл бұрын
Thank you! Cheers!
@Adam-wc5ol
@Adam-wc5ol 3 жыл бұрын
Nice video
@chrismcnabb3134
@chrismcnabb3134 3 жыл бұрын
Great video! Thanks! Is the "A Bug Bounty Hunting Journey" book available yet?
@thehackerish
@thehackerish 3 жыл бұрын
It is available: www.amazon.com/dp/B08T81PP65/
@psychoSherlock
@psychoSherlock 3 жыл бұрын
You deserve more 👏👏👏
@thehackerish
@thehackerish 3 жыл бұрын
Appreciate your comment! Share the channel in your hacking surroundings buddies :)
@psychoSherlock
@psychoSherlock 3 жыл бұрын
@@thehackerish did already..... Ma discord buddies are on the way.... 😄
@thehackerish
@thehackerish 3 жыл бұрын
@@psychoSherlock You are the best!
@psychoSherlock
@psychoSherlock 3 жыл бұрын
@@thehackerish Nop, you are. I felt like you teach something in a way no other KZbinrs does........ That's y I asked them....
@darshanjogi5781
@darshanjogi5781 3 жыл бұрын
nice video
@thehackerish
@thehackerish 3 жыл бұрын
Thanks
@naumanalam1
@naumanalam1 3 жыл бұрын
I just say woowwwww
@jbrown8274
@jbrown8274 3 жыл бұрын
so do the flags coincide with vulnerabilities within the domain, if this was real life would those flags be something that could be abused and therefore reported in a BB report?
@thehackerish
@thehackerish 3 жыл бұрын
Some, not really. Others, definitely! It depends on the situation.
@vihangadeshan2587
@vihangadeshan2587 3 жыл бұрын
Really Helpful. Where can I find the e-book (A bug bounty hunting journey...)
@thehackerish
@thehackerish 3 жыл бұрын
Will be shared once ready :)
@vihangadeshan2587
@vihangadeshan2587 3 жыл бұрын
@@thehackerish looking fwd to reading it :)
@androzilla9825
@androzilla9825 2 жыл бұрын
It’s ready or not 🌝
@zerobyte536
@zerobyte536 Жыл бұрын
Lol clicked video because it said you were going to hack an actual bugbounty target, then i see its a ctf. Was going to say how did het get to release this! Every bugbounty i have ever done has a non-disclosure. Lol any way good video for beginners
@thehackerish
@thehackerish Жыл бұрын
I had permission from one developer to release a video doing bug bounty, well... web hacking, cuz I did it for free. Check it out, kzbin.info/www/bejne/l5qyomCvhN-ajZI
@maheshkarunanithi2970
@maheshkarunanithi2970 3 жыл бұрын
alternative for burp collabrator
@position876
@position876 3 жыл бұрын
When did a CTF become a "bug bounty target"?
@thehackerish
@thehackerish 3 жыл бұрын
When we started watching new websites providing bug bounty-like challenges in the form of a CTF.
@Arfat-Khan
@Arfat-Khan Жыл бұрын
I have exploit no rate limit, but now its been duplicate, what else i can do based on no rate limit. Further what can i exploit?
@thehackerish
@thehackerish Жыл бұрын
bruteforce directories for interesting ones? passwod spraying using a custom wordlist?
@Arfat-Khan
@Arfat-Khan Жыл бұрын
@@thehackerish ok thanks
@asaad0x
@asaad0x 2 жыл бұрын
Wow That was so smooth makes it look very easy to be hacker 😁 keep going bro
@karthik3913
@karthik3913 Жыл бұрын
Idk why iam always finding errors while running the tools I applied as same as u applied
A new #bugbounty hunting book has joined the family!
7:59
thehackerish
Рет қаралды 1,7 М.
Finger Heart - Fancy Refill (Inside Out Animation)
00:30
FASH
Рет қаралды 29 МЛН
Heartwarming Unity at School Event #shorts
00:19
Fabiosa Stories
Рет қаралды 25 МЛН
Задержи дыхание дольше всех!
00:42
Аришнев
Рет қаралды 3,8 МЛН
Iron Chin ✅ Isaih made this look too easy
00:13
Power Slap
Рет қаралды 36 МЛН
How much money I made in my 1st year of bug bounty? Bounty vlog #4
17:02
Bug Bounty Reports Explained
Рет қаралды 144 М.
Finding Your First Bug: Manual IDOR Hunting
33:28
InsiderPhD
Рет қаралды 76 М.
The 3 Tools You Need // How To Bug Bounty
10:02
NahamSec
Рет қаралды 30 М.
Cracking JSON Web Tokens
14:34
The Cyber Mentor
Рет қаралды 56 М.
How to Find Your First Bug
23:33
InsiderPhD
Рет қаралды 37 М.
I legally defaced this website.
25:48
thehackerish
Рет қаралды 511 М.
Which XSS payloads get the biggest bounties? - Case study of 174 reports
28:40
Bug Bounty Reports Explained
Рет қаралды 25 М.
HACK, Backdoor, Defend, in MINUTES!
11:27
thehackerish
Рет қаралды 4,4 М.
API Hacking Demo | Bug Bounty Web App Testing
13:35
Ryan John
Рет қаралды 35 М.
I Hacked & Exposed This Fake Website for Educational Purposes - CTF
11:26
Finger Heart - Fancy Refill (Inside Out Animation)
00:30
FASH
Рет қаралды 29 МЛН