rs0n_live
rs0n_live
  • 49
  • 389 165
Ask Yourself These Four Questions When Bug Bounty Hunting for IDORs
When bug bounty hunting for IDORs, these questions will help you identify code patterns that can lead to finding bugs faster and easier! If you've seen my video on Access Controls and IDORs (Part 1), this video expands on some of the core topics. I hope it helps!
Hire Me! - ars0nsecurity.com
Watch Live! - twitch.tv/rs0n_live
Free Tools! - github.com/R-s0n
Connect! - www.linkedin.com/in/harrison-richardson-cissp-oswe-msc-7a55bb158/
Переглядів: 1 261

Відео

Bug Bounty Hunting | Find Bugs in Hidden React Source Code!! ⏰ QUICK TIP ⏰
Переглядів 3,2 тис.2 місяці тому
Find XSS bugs (and more!) in client-side React Code! Developers often forget to obfuscate and properly serialize their React code before shipping it to production. In this video, I show you how I find applications with this misconfiguration, download the raw React files, and use a Static Code Analysis tool to find vulnerabilities! I've been working on my editing and pacing, let me know what you...
I'm Back! What to Expect Moving Forward...
Переглядів 1,3 тис.2 місяці тому
00:00 - Quick Recap 00:18 - HUGE thank you to the community! 01:23 - What happened to the Discord Server? 04:08 - What's going on with the Framework? 08:52 - What about Livestreams and Recorded Videos? 10:25 - FloQast Authenticated Bug Bounty Program 13:25 - Wrap Up
I need a break...
Переглядів 3,6 тис.5 місяців тому
The endless stream of demands and harassment around my Bug Bounty Hunting Framework has finally gotten to me, so I've decided to take a break from developing, as well as streaming and recording, for a few months. Thank you all for the love and support! I just need a few months to get my head right and figure out how I want to drive these projects moving forward.
New Fiverr Pro Gig!! Attack Surface Vulnerability Scanning -- 👀🎯 See How Attackers See You
Переглядів 9425 місяців тому
Learn More: www.fiverr.com/s/xg3WvZ I will conduct a thorough vulnerability assessment using a collection of automated tools to enumerate the client's attack surface, identify valid targets in that attack surface, and test those targets for a wide range of known vulnerabilities. Attackers often chose their targets based on who they believe will be an "Easy Target". This testing will simulate th...
New Fiverr Pro Gig!! Web Application & Cloud Infrastructure Penetration Test
Переглядів 7085 місяців тому
Learn More: www.fiverr.com/s/KG8Nez I will conduct thorough penetration testing on a target web application, as well as the cloud infrastructure hosting that application. This testing includes a significant amount of manual testing and is designed to simulate the experience of being targeted by an Advanced Persistent Threat (APT) group with the goal of gaining a foothold in an organization thro...
[Part III] Bug Bounty Hunting for IDORs & Access Controls
Переглядів 9 тис.6 місяців тому
[Part III] Bug Bounty Hunting for IDORs & Access Controls
Live Bug Bounty Hunting | Authenticated Testing the Client-Side & Server-Side on Figma's Core App
Переглядів 7 тис.6 місяців тому
Live Bug Bounty Hunting | Authenticated Testing the Client-Side & Server-Side on Figma's Core App
Bug Bounty Hunting for Client-Side Injection Vulnerabilities | Part I
Переглядів 20 тис.6 місяців тому
Bug Bounty Hunting for Client-Side Injection Vulnerabilities | Part I
Live Bug Bounty Hunting | Client-Side Injection Testing on Starbucks Japan (Plus Q&A)
Переглядів 15 тис.6 місяців тому
Live Bug Bounty Hunting | Client-Side Injection Testing on Starbucks Japan (Plus Q&A)
My Bug Bounty Hunting Framework | New Collaboration Features Out Now!!! -- Alpha 0.0.2 Release
Переглядів 3,1 тис.6 місяців тому
My Bug Bounty Hunting Framework | New Collaboration Features Out Now!!! Alpha 0.0.2 Release
[Part II] Bug Bounty Hunting for IDORs and Access Control Violations
Переглядів 14 тис.7 місяців тому
[Part II] Bug Bounty Hunting for IDORs and Access Control Violations
[Part I] Bug Bounty Hunting for IDORs and Access Control Violations
Переглядів 30 тис.7 місяців тому
[Part I] Bug Bounty Hunting for IDORs and Access Control Violations
This Update to my Bug Bounty Hunting Framework is a GAMECHANGER!!!
Переглядів 1,7 тис.7 місяців тому
This Update to my Bug Bounty Hunting Framework is a GAMECHANGER!!!
A Complete Guide to My Bug Bounty Hunting Framework
Переглядів 13 тис.7 місяців тому
A Complete Guide to My Bug Bounty Hunting Framework
Everything You Need To Know About Burp Suite For Bug Bounty Hunting!
Переглядів 14 тис.8 місяців тому
Everything You Need To Know About Burp Suite For Bug Bounty Hunting!
I'm Exhausted.....but my Bug Bounty Framework (Alpha Version) is FINALLY READY!!!
Переглядів 2,8 тис.8 місяців тому
I'm Exhausted.....but my Bug Bounty Framework (Alpha Version) is FINALLY READY!!!
LIve Bug Bounty Hunting | Unauthenticated Testing on Front.com
Переглядів 73 тис.8 місяців тому
LIve Bug Bounty Hunting | Unauthenticated Testing on Front.com
Live Bug Bounty Recon & Enumeration (Raw Stream) | HackerOne Public Program Starbucks
Переглядів 8 тис.9 місяців тому
Live Bug Bounty Recon & Enumeration (Raw Stream) | HackerOne Public Program Starbucks
Bug Bounty Tip | Do This Exercise Every Day to Get Better at Finding XSS Bugs!
Переглядів 11 тис.9 місяців тому
Bug Bounty Tip | Do This Exercise Every Day to Get Better at Finding XSS Bugs!
Bug Bounty Tip | How to Set Up Testing Requirements for Public HackerOne Program
Переглядів 2,1 тис.9 місяців тому
Bug Bounty Tip | How to Set Up Testing Requirements for Public HackerOne Program
Live Bug Bounty Recon (Raw Stream) | HackerOne Public Program - Hilton
Переглядів 42 тис.9 місяців тому
Live Bug Bounty Recon (Raw Stream) | HackerOne Public Program - Hilton
Bug Bounty Hunting for Server-Side Request Forgery - Who, What, When, Where, How, and Why?
Переглядів 1,1 тис.9 місяців тому
Bug Bounty Hunting for Server-Side Request Forgery - Who, What, When, Where, How, and Why?
Bug Bounty Hunting for Reflected XSS - Who, What, When, Where, Why, and How???
Переглядів 1,8 тис.10 місяців тому
Bug Bounty Hunting for Reflected XSS - Who, What, When, Where, Why, and How???
Bug Bounty Tip | Test Hidden API's From Desktop Applications!
Переглядів 2 тис.10 місяців тому
Bug Bounty Tip | Test Hidden API's From Desktop Applications!
WHAT have I been DOING for the last SIX MONTHS???
Переглядів 86510 місяців тому
WHAT have I been DOING for the last SIX MONTHS???
Install my NEW Bug Bounty Framework on Kali Linux | The Ars0n Framework -- (No Audio)
Переглядів 7 тис.Рік тому
Install my NEW Bug Bounty Framework on Kali Linux | The Ars0n Framework (No Audio)
Bug Bounty Hunting | Deep Dive -- Part II
Переглядів 6 тис.Рік тому
Bug Bounty Hunting | Deep Dive Part II
Bug Bounty Hunting | Deep Dive -- Part 1
Переглядів 29 тис.Рік тому
Bug Bounty Hunting | Deep Dive Part 1
Bug Bounty Hunting | Shopify is paying $200,000 to ANYONE who can hack them!!!
Переглядів 9 тис.Рік тому
Bug Bounty Hunting | Shopify is paying $200,000 to ANYONE who can hack them!!!

КОМЕНТАРІ

  • @JustAnotherKiid
    @JustAnotherKiid День тому

    35:01 "Is this a cloud...? I've been out in the sun today...." lolol, had me dying. Just discovered your channel man, keep at it! Good luck with the framework!

  • @georgekiwarkis8264
    @georgekiwarkis8264 День тому

    i recently discovered this channel and i would like to say that as a knew person to cybersecurity you motivate me and give me alot of knew information to keep going

  • @ianeduardomezastrahm6432
    @ianeduardomezastrahm6432 День тому

    I love your videos man 🦝

  • @SoWhatToDo
    @SoWhatToDo 2 дні тому

    Thx a lot master! Ur videos was really helpful for many guys))

  • @NoOneNew-b4c
    @NoOneNew-b4c 3 дні тому

    but it needs to look like that 'X-Bug-Bounty:HackerOne-{UName}'. so you still got it wrong

  • @fahadali1372
    @fahadali1372 5 днів тому

    Read about Islam and take a look in the Quran, then decide. This world has darkness and puts a lot of stress on people. When you carry all this in your heart, you need to get it out of your body through prayer, reading the Quran, and talking to Allah. Listen to or read the story of Prophet Muhammad and how he faced the people in Makkah, even his cousins, and managed to deal with it with the help of Allah, the Greatest. Go to the gym, listen to the Quran while you are driving, and see the changes. search about azkar of morning and night and sleeping (وفقك الله)

  • @l00pzwastaken
    @l00pzwastaken 5 днів тому

    Yo thanks for this video's also your parts for idors and broken access help me lot to create notes and work accordingly 🙏. Looking for live streams again :)

  • @tokyorockstarVALORANT
    @tokyorockstarVALORANT 5 днів тому

    Hello rson are you still doing 1on1 coaching

  • @hichemsavastano4430
    @hichemsavastano4430 6 днів тому

    OMG please make video about semgrep I have one week and I'm trying to learn it it's little challenging like didn't find someone explain it good 😊 so plz if u can make video because that will help me in my bug bounty 😅

  • @fakepleb
    @fakepleb 6 днів тому

    Welcome back, Sir

  • @cyberpro151
    @cyberpro151 6 днів тому

    very nice

  • @Unknown-u9s
    @Unknown-u9s 6 днів тому

    Good To See You Back Sir 🎉

  • @samioul9180
    @samioul9180 6 днів тому

    welcome back champ

  • @razmjumehdi9069
    @razmjumehdi9069 7 днів тому

    thanks a lot 🙏

  • @TheCyberWarriorGuy
    @TheCyberWarriorGuy 7 днів тому

    :)

  • @manvaldez_
    @manvaldez_ 7 днів тому

    Great to see you back buddy

  • @thepotatogaming2340
    @thepotatogaming2340 7 днів тому

    Hey glad to see you back

  • @user-ff1bs4rz9m
    @user-ff1bs4rz9m 7 днів тому

    Need more videos for Idor pleasseeee

  • @randriamahandryrado9800
    @randriamahandryrado9800 7 днів тому

    Welcome back, need video like that for broken access control 😊

  • @rtleo5260
    @rtleo5260 7 днів тому

    This channel never disappoints 😁

  • @lukeempty3386
    @lukeempty3386 7 днів тому

    Welcome back man.

    • @rs0n_live
      @rs0n_live 7 днів тому

      Thank you! I've been here, work has just been crazy so I haven't had time to make videos. After DEFCON I should have a *lot*more time, and especially through the winter. I'm very exited to get back to it!

  • @khabeirmbh8755
    @khabeirmbh8755 7 днів тому

    Awesome ❤🎉 We need one stream for taking notes when testing with checklist

  • @huzaifamuhammad8044
    @huzaifamuhammad8044 7 днів тому

    Very informative. Missing your streams

    • @rs0n_live
      @rs0n_live 7 днів тому

      Streams are coming back after DEFCON, I promise! I've been so busy, just trying to find time for everything.

    • @yahiayhDZ
      @yahiayhDZ 7 днів тому

      Welcome back man 🎉, we need your lessons on business logic bugs and more videos how to look for access control ​bugs, i like when your videos are very long like the IDOR one@@rs0n_live

  • @axelvirtus2514
    @axelvirtus2514 7 днів тому

    Welcome back

  • @fedoom1477
    @fedoom1477 7 днів тому

    awesome

  • @markgilt.culaway25
    @markgilt.culaway25 9 днів тому

    thanks a lot!!

  • @cyphercoda4575
    @cyphercoda4575 11 днів тому

    dudeee your content is amezing, just fix your camera.

  • @mduduzithanjekwayo8404
    @mduduzithanjekwayo8404 11 днів тому

    This is gold!

  • @bastianobsztyfitykultykiew4331
    @bastianobsztyfitykultykiew4331 12 днів тому

    youre making great vids man <3

  • @slaozeren8742
    @slaozeren8742 14 днів тому

    Teşekkürler.

  • @slaozeren8742
    @slaozeren8742 18 днів тому

    Teşekkürler.

  • @jamesvelopmenthagood8998
    @jamesvelopmenthagood8998 19 днів тому

    After taking some courses online, learning about IDORs with stuff like /account/6789. I found precisely zero url structures like that in the wild. I watched this video last night and found my first 3 IDORs this morning.

  • @jamesvelopmenthagood8998
    @jamesvelopmenthagood8998 20 днів тому

    This is so much better than course videos with super unrealistic flaws

  • @CaiN805
    @CaiN805 22 дні тому

    thx for this awesome lesson. It's a greate idea to combine webdev process with bug bounty.

  • @tkcrash9009
    @tkcrash9009 23 дні тому

    Amazing video🔥

  • @user-fp7fs9xl2t
    @user-fp7fs9xl2t 25 днів тому

    this video is very motivating thanks man ...

  • @user-gt8po7pt9u
    @user-gt8po7pt9u 28 днів тому

    Keep doing bro, you are doing amazing work for the community ❤.

  • @LoneStarBassPursuit
    @LoneStarBassPursuit 29 днів тому

    New into cyber. Learning on THM and enjoying that. Just came across you not to long ago and really enjoy the content.

  • @navienkumar1524
    @navienkumar1524 Місяць тому

    Hey it only for http but not capture https i changet the network proxy to 127.0.0.1 is there is any ssl then how come to bypass there is not enough information related to proxy desktop app im using ubuntu linux

  • @maxi20zexi20
    @maxi20zexi20 Місяць тому

    thx lord

  • @qianlihu1384
    @qianlihu1384 Місяць тому

    hey bro, what's the service on your localhost:3000, seems to be a recon tool.

  • @hades6-3-63
    @hades6-3-63 Місяць тому

    Love these video's. Only thing i would change is keeping the microphone a little closer to yourself, because now your keyboard is really loud for me. Keep up the good work

  • @hades6-3-63
    @hades6-3-63 Місяць тому

    really hate captcha

  • @joeyzanna8458
    @joeyzanna8458 Місяць тому

    Thank you sir. You are my best youtuber

  • @iamagastya0
    @iamagastya0 Місяць тому

    This is fantastic for beginner's

  • @kalendra.ethicalhacker
    @kalendra.ethicalhacker Місяць тому

    getting mangodb error

  • @john_wick_catcher26
    @john_wick_catcher26 Місяць тому

    rewatched some of the videos, i'm not a guy that comments but i have to say : much respect to you, you are the one that got me back into pentesting when i was on the break of giving up, it was also you that helped so many people as well with the software and videos. keep up the good work and i always look forward seeying the live stream. thanks for giving me this push

  • @ankitmeena826
    @ankitmeena826 Місяць тому

    How to hack Aviator

  • @hippolytnavrose5094
    @hippolytnavrose5094 Місяць тому

    Hi R-s0n. I hope all is well. Just checking on you and eagerly waiting for your next streaming.

  • @bughunter1731
    @bughunter1731 Місяць тому

    Can this be installed on a vps?