I Found 8 CVEs in 2 Weeks (And You Can Too!)

  Рет қаралды 26,601

Tyler Ramsbey || Hack Smarter

Tyler Ramsbey || Hack Smarter

Күн бұрын

Пікірлер: 61
@the-beagle888
@the-beagle888 10 ай бұрын
I've been searching for videos about how to find CVEs, what is the process used, how researchers really hunt for CVES and I can tell you this video is by far the best. Thanks for sharing your knowledge.
@KyserClark
@KyserClark Жыл бұрын
This video was amazing! As a new pentester myself, I figured getting a CVE assigned to me would come later in my career, but you're encouragement and straightforward guide comforts me in this adventure. Congratualtions! and thank you for the video. Keep up the great work! :)
@camelotenglishtuition6394
@camelotenglishtuition6394 Жыл бұрын
When you say new do you have a job pen testing or via bug bounties ?
@flimflam2
@flimflam2 8 ай бұрын
Followed your guide to a T. Re-calibrated by starting the HTB Bug Bounty path to set the scene. In 5 days of restarting learning I got 3 XSS vulns in a moderately popular project. I'm back here to watch the submission instructions :) Can't thank you enough.
@TylerRamsbey
@TylerRamsbey 8 ай бұрын
Whoa! That is awesome! Congrats!
@johnsmith8981
@johnsmith8981 Ай бұрын
Finally getting far enough in THM and am excited to find my first CVE. Putting a CVE on a resume sounds like a great way to get noticed in the security industry.
@SalahTayeh-Tech
@SalahTayeh-Tech 8 ай бұрын
The only real man to clearly describe what a CVE is, It's been so long finding something for it!
@Kura_mon
@Kura_mon 8 ай бұрын
Hi Tyler, I just want to let you know, today my first CVE got published and without your video, i would have never thought of actually publishing the vulnerability i found. Thank you for this video! :)
@dublinnnn
@dublinnnn 5 ай бұрын
Hii I really wonder how do you find targets ti hunt on??
@Kura_mon
@Kura_mon 5 ай бұрын
@@dublinnnn My CVE was a SIEM-Software we used in my company and I found it during training for that software 😅 it literally jumped into my face. I am sorry that this won't help you. But in the end: software that you want to understand makes it easier, and like tyler said: finding stuff on software that already published CVE's before makes it easier to publish.
@prodKossi
@prodKossi Жыл бұрын
I have the same view you used to have - finding CVE's is for the big brain folks. I used to think the same about pentesting/hacking in general however, and I think this video sorta brought CVE's down a peg in my mind - just like THM did in regards to pentesting/hacking. Thanks for this video :) 💜
@edwintan4784
@edwintan4784 2 ай бұрын
Wow Tyler! U did an amazing job of breaking down the process of finding CVEs to a novice in a simple manner! Thank u so much for sharing your knowledge with us for free 😊 Really hope u continue to make more videos as they are really hallmarks of excellence! All the videos i watched contained really practical & easy to digest information ❤
@x7331x
@x7331x Жыл бұрын
Thanks for the process walkthrough, and I wish you a lot more CVEs in 2024!
@h8handles
@h8handles 8 ай бұрын
As you know I'm working on oscp. I am not nieve enough to believe that's enough. So this is the next task. Love you Tyler! Keep being dope!
@wolfyyybandz
@wolfyyybandz Жыл бұрын
Super cool video I am glad I am here for the ride. Great steps to helping me and everyone who sees this to land that first cybersecurity job!
@Marco_Ris
@Marco_Ris 5 ай бұрын
Exactly what I'm looking for. My ToDo list with a CVE of my own found will have another check. Thx for that m8
@Marco_Ris
@Marco_Ris 2 ай бұрын
Update on the Bucketlist. I registered one CVE and now im curious about the next steps 🙂
@DocGMoney
@DocGMoney 7 ай бұрын
Here after the stream last night. Thank you for pointing me this way will have to look into this as well!
@jsmith85151
@jsmith85151 8 ай бұрын
This is insanely generous of you to share. Thank you, Sir!
@jgold96
@jgold96 Жыл бұрын
Much love man, Merry Christmas!
@Redzombi3
@Redzombi3 Жыл бұрын
Great video with ethically amazing approach, Tyler
@CyberDevilSec
@CyberDevilSec 3 ай бұрын
Whoa Tyler well played! I never thought of that before. I indeed also thought you needed some elite knowledge to discover a CVE or pure luck. I discovered a Zero day in the firewall in my youth prison but it was just so i could play some call of duty XD But this looks amazing i'll take a look at it :D
@dustinhxc
@dustinhxc Жыл бұрын
Congratulations! You really opened my eyes and I have been excited to hear more about your process since hearing about this! It’s been very helpful.
@Giperium
@Giperium 7 ай бұрын
Cool, as Tyler, I thought this was an unattainable level of vulnerability research so far. You need to take several courses on web pentesting, and then do it. I see that Tyler took a chance and didn't regret it. I am also on my way to HTB-Academy, a useful source of practical information. Thanks for the video!
@tpevers1048
@tpevers1048 3 ай бұрын
You deserve it with your work and everything
@Macj707
@Macj707 Жыл бұрын
I like the Academy at HTB also it has served me well I think i got 47 of those badges so far... good stuff
@Hemoglakbin
@Hemoglakbin Жыл бұрын
Congratulations, Tyler! I'm just starting in the field, but to keep me motivated I wanted to set a goal to find one in the next two years. The timing with this vid is perfect.
@Marco_Ris
@Marco_Ris 2 ай бұрын
Coming back and yeah who got his first cve? hm? Thx Tayler for your help to show how to do it.
@TylerRamsbey
@TylerRamsbey 2 ай бұрын
Boom! Congrats!!
@zophikel7632
@zophikel7632 Жыл бұрын
Nice job, I mainly wanna do swe since after doing cs/math uni learned it’s fun to build stuff as well
@dancelhernandez
@dancelhernandez Жыл бұрын
Thanks for sharing this. Its very inspiring for someone who is aspiring to break into the cybersecurity field. More power to your channel bro. Happy holidays
@whoami_root
@whoami_root Жыл бұрын
Congrats dude Good job
@malukabee
@malukabee Жыл бұрын
You are absolutely amazing bro!
@rovingwolf79
@rovingwolf79 Жыл бұрын
this is a great idea, thanks Tyler
@AntThinker
@AntThinker Жыл бұрын
03:58 What kind of HTML syntax is that? Have just tried, slashes are indeed treated as spaces, but what are the rules here? Is it just slashes or can we use other characters instead of spaces? Are there any documentation references for this thing?
@Pentester2Pentester
@Pentester2Pentester Жыл бұрын
thanks for the amazing video and information 😊
@hristodabovski4169
@hristodabovski4169 Жыл бұрын
Great Video ! Good job
@aszetamichalski8187
@aszetamichalski8187 Ай бұрын
Hey, great video. It will definitely help me. But I have one question. What happens if, let’s say, I found the vulnerability, but someone did the exact same steps before me and submitted it first. Vendor should inform me, that someone already told them about it and they are currently working on patching this vulnerability, am I right?
@nitro9505
@nitro9505 3 ай бұрын
Hello. I have two questions. How do you proceed if the team you notified never gets back to you? How soon do you expect them to respond? Thank for great video.
@abhishekkumarbiswas3365
@abhishekkumarbiswas3365 Жыл бұрын
Great resourceful man appreciated , by the way is the wall behind you wallpapered or real brick is shown, just asking
@thepotatogaming2340
@thepotatogaming2340 8 ай бұрын
hey, if the company is not very cooperative is it possible that I could get into legal problems?
@afnanbinabbas4867
@afnanbinabbas4867 2 ай бұрын
Bro could you tell me that is it necessary that we should start our cybersecurity career from pentesting or we can directly start from big bounty? I’ve seen the free 14 hours TCM security Pentesting videos so I got the idea of it and have tried some websites for practice but it was too random! So I thought stepping into big bounty would be a better option to learn practically of what I’ve learned. Is this approach good and what are the ways I can learn bug bounty from scratch for free.. do let know. Thank you!
@diefer8093
@diefer8093 Жыл бұрын
Good job bro
@XyndraNerd
@XyndraNerd Жыл бұрын
How did you find the target, and do you get money for this?
@OmaraAJ
@OmaraAJ 8 ай бұрын
Do I need some web-dev skills inorder to do web-app pentesting??
@diegocondori5673
@diegocondori5673 Жыл бұрын
thank you for giving me the trust :-)
@camelotenglishtuition6394
@camelotenglishtuition6394 Жыл бұрын
Love the video, do you think it'd be applicable to apis too as I've been learning to hack those?
@georgiosroumeliotis4383
@georgiosroumeliotis4383 Жыл бұрын
How much time did you spend before finding your first bug?
@itsm3dud39
@itsm3dud39 11 ай бұрын
will they pay us?
@Eggsec
@Eggsec Жыл бұрын
Interested
@shoumikhasan8654
@shoumikhasan8654 Жыл бұрын
Thanks brother
@cesarconterno4962
@cesarconterno4962 Жыл бұрын
Good job
@ravbhuva
@ravbhuva Жыл бұрын
It must be a good idea if videos are timestamped.
@aukir
@aukir Жыл бұрын
Btw, I'm not sure you ever actually say what a CVE is. :) If someone doesn't know, they still don't. Common Vulnerabilities and Exposures.
@kulled
@kulled Жыл бұрын
i like the video and i'd have subscribed had you not been receiving so many obviously fake interactions. not sure if you deliberately purchased bots / alted for those comments but i'm not giving you any more favor in the algorithm.
@TylerRamsbey
@TylerRamsbey Жыл бұрын
Hey -- I haven't purchase anything like that lol..
@Recon_Racing
@Recon_Racing 11 ай бұрын
I'm just a script kiddie with a Net+, Sec+ and CySA+
@Master0-0mind
@Master0-0mind Жыл бұрын
منم مثل این هودی دارم😮
@bret354
@bret354 Жыл бұрын
never heard of cve's
@warehousing2953
@warehousing2953 Жыл бұрын
What a showoff.. 😆
Someone Tried To Hack Me...
8:55
Tyler Ramsbey || Hack Smarter
Рет қаралды 6 М.
this vulnerability shouldn’t even exist
14:33
Low Level
Рет қаралды 237 М.
How To Find Your FIRST CVE!
11:26
Tadi
Рет қаралды 7 М.
How To Become An Ethical Hacker in 2024 - [Detailed Guide]
5:42
Tyler Ramsbey || Hack Smarter
Рет қаралды 23 М.
The Blueprint to Your First $1,000+ Bounty
12:14
NahamSec
Рет қаралды 36 М.
if you view this image, YOU GET HACKED.
8:40
Low Level
Рет қаралды 393 М.
Vulnlab: First Impressions!
15:22
Tyler Ramsbey || Hack Smarter
Рет қаралды 2,7 М.
Detect Hackers & Malware on your Computer (literally for free)
16:38
Hacking Bank from Hackthebox |  HTB Bank Walkthrough | Ethical Hacking
28:17