Easy IDOR hunting with Autorize? (GIVEAWAY)

Поділитися
Вставка
  • Опубліковано 15 чер 2024
  • I've said it once and I'll say it again APIs are some of the best applications to hunt on, and now I've worked at a platform I have some data to back me up that IDORs are fantastic first bugs and they are EVERYWHERE! But, when we test a real API vs a lab or CTF there are so many endpoints and resources and stuff to test, so what if we could make IDOR hunting easier? What if we could automate it? Well this is what Autorize is designed to do! This free Burp extension allows us to automatically make a second request to test if our attacker account can do something to affect our victim. It's such a useful tool to have installed I 100% recommend it especially if you're a beginner.
    Did you know this episode was sponsored by Intigriti? Sign up with my link go.intigriti.com/katie I'm so pleased with everyone's positive response to the Intigriti sponsorship and I'm so pleased you folks are finding bugs and even finding your first bugs! Thank you for being awesome!
    This month as a thank you for bearing with me as I get back into video making we're doing a giveaway! To win one of the following prizes please enter via a comment on this video with an answer to: What bug or type of hacking do you want to know more about? And the text: #bountypls
    1x Lifetime Membership to www.bugbountyhunter.com/
    5x 1 month memberships PentesterLab Pro
    5x 2 months Try Hack Me Premium
    10x InsiderPhD Swag Pack

КОМЕНТАРІ • 259

  • @dhruvkandpal9909
    @dhruvkandpal9909 2 роки тому +6

    Great video, Katie! Loved it as always.
    My favourite bug bounty tools are burp suite, all tomnomnom's tools, amass and the ones I developed on my own! (LazyFuzzZ, Wordlist Weaver, Fu-JS) #bbhammer

  • @gf32768
    @gf32768 2 роки тому +3

    Awesome video, as always!
    Favourite tool - Burp Suite - even if the only features it had were the proxy history and Repeater, it'd still be amazing.
    ##bbhammer

  • @brucezhang4967
    @brucezhang4967 2 роки тому +3

    Thanks Kate! I want to know more about SSRF and businesss logic.#bountypls And my favourite bug bounty tool is absolutely BurpSuite!!! #bbhammer

  • @prashant.singh08
    @prashant.singh08 2 роки тому +5

    Thanks for doing so much for the community ❤️
    It'll be great to have more videos about DOM based vulnerabilities #bountypls

  • @link-ed
    @link-ed 2 роки тому +2

    Thanks for the video! The tool that I use the most is fuff, cause of it's speed and simplicity. Burp is another indispensable tool as well! #bbhammer

  • @rajanrawal3761
    @rajanrawal3761 2 роки тому

    amazing, this could be probably one of the biggest information that i have ever been given

  • @syedbukhari4761
    @syedbukhari4761 2 роки тому +2

    Great video Katie, my favourite tool is Amass & Wireshark; would love to see more videos on Business logic flaws & XXE flaws.
    #bountypls

  • @iamkaustubh
    @iamkaustubh 2 роки тому

    Wowww Thanks katie 🔥🔥🔥🔥it really encourages people more thanks for video

  • @saite2560
    @saite2560 Рік тому

    nice video i've watched quite a few of em. clear well rehearsed script.. this video actually tries to show us something. well rounded video.
    i wish more of your videos showed us how to actually do this stuff like this video. you do great on the speaking side of teaching tho, need more hands on tho.

  • @arrheniusangipaelongan8693
    @arrheniusangipaelongan8693 2 роки тому +5

    Thanks for all your videos Katie!❤ I got my first bug from your IDOR video. My favorite tool is burp! #bbhammer

  • @sangeethaa5101
    @sangeethaa5101 2 роки тому +2

    I want more videos explaining bugs with dem websites not just presentations. Thank You, Katie. #bountypls #bbhammer

  • @stablewater
    @stablewater 11 місяців тому +1

    Thanks for this great knowledge. I am currently learning IDOR and I've been able to use autorize and I got "enforced" in some areas. What next am I to do next. How do I exploit this for bug bounty?

  • @chitraa87
    @chitraa87 2 роки тому +1

    Thanks for doing amazing video katie. My fav bug bounty tool is burp ofcourse. I'm looking forward more automation videos like this..#bbhammer

  • @svrajput14
    @svrajput14 Рік тому

    Really nice tip on how to use tool effectively !!

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 роки тому +1

    Started learning following your recon videos. My go to tool for now is Burpsuite community edition. #bbhammer

  • @amitabhgupta21
    @amitabhgupta21 2 роки тому +3

    Started following you Katie and I am blown by the content u and
    other fellow u tubers are providing by the way my favourite BB tools are - Burp Pro,Rustscan,amass and nuclei
    #Bbhammer

  • @webapplicationsecurity1853
    @webapplicationsecurity1853 2 роки тому +1

    Thanks for the video, have been using this tool for a while now. This is my favourite tool: Autorize allows to check most of the access Logic tests. #bbhammer

  • @vanquisherstraveltube
    @vanquisherstraveltube 2 роки тому +2

    You are really a great teacher.
    I am following your videos and learning a lot. Thank you so much!
    *Burp* is my favorite tool
    #bbhammer

  • @DieTeewurst
    @DieTeewurst 2 роки тому +1

    Thank you for your great Videos! My favorite Bug bount tool is burp for sure! So much functionality in one tool! #bbhammer

  • @rami1785
    @rami1785 2 роки тому +1

    Thanks for all your videos Katie , My favorite tool is burp #bbhammer .

  • @amandabarbosasobrinho5878
    @amandabarbosasobrinho5878 2 роки тому +1

    Hey Katie, as always, awesome video! My favorite bug bounty tool is Burp, for sure! #bbhammer

  • @wingwing2683
    @wingwing2683 Рік тому +1

    Thanks so much sharing!

  • @vikasrushi3714
    @vikasrushi3714 2 роки тому +1

    Thanks :) my favourite bug bounty tool are Amass and FFUF #bbhammer

  • @p.k5016
    @p.k5016 2 роки тому +1

    Thank you Katie for this amazing video. My favourite bug bounty tool is Burpsuite. #bbhammer

  • @ainter216
    @ainter216 2 роки тому

    Thank you very much for the video! My favourite toos is Burp Suite, it is so powerful and you can do so many things. #bbhammer

  • @jarvis9092
    @jarvis9092 2 роки тому +2

    Please never stop creating content like these😍..It would be helpfull if you would increase your volume as i felt the audio is lower than other youtube videos..My favourite tool is BurpSuite #bbhammer

  • @meletismichael2495
    @meletismichael2495 2 роки тому +1

    You are precious for the community! pls go more in depth on chaining vulnerabilities! #bountypls

  • @ksr608
    @ksr608 2 роки тому +1

    Thank you for all your videos! My favourite tool is amass and burpsuite. #bbhammer. It'll be good to see more videos on subdomain takeover with an example. #bountypls

  • @RahulKumar-vy4lu
    @RahulKumar-vy4lu 2 роки тому +2

    Great video as always. I would love to have more videos about XSS & chaining of bugs. #bountypls

  • @mohammedsaneem4179
    @mohammedsaneem4179 2 роки тому +2

    Great video as always. Would love to see videos based on chaining of bugs #bountypls

  • @SergeantDaynes
    @SergeantDaynes 2 роки тому +3

    Awesome video as usual. As for the types of bugs/hacking I want to learn about…SSRFs, broken access controls, business logic, and APIs! #bountypls

  • @mayank-ir7tm
    @mayank-ir7tm 2 роки тому +1

    My favourite bug bounty tool is ffuf combined with burp. I can bypass the speed limit of Intruder during fuzzing using -replay-proxy in ffuf which gives me the benifit of higher fuzzing speeds of ffuf and all the packets are captured in burp proxy too due to -replay-proxy flag set in ffuf.
    #bbhammer

  • @singularityfinale7680
    @singularityfinale7680 2 роки тому +3

    You videos are both no bs info and free which is great for broke student like me. Well my favorite tool is Burpsuite #bbhammer
    And I think I will give Autorize a try.

  • @sekmekci
    @sekmekci Рік тому

    Thanks for the video. Information part is starting at 3:49

  • @abhishekpraveen6219
    @abhishekpraveen6219 2 роки тому +2

    I would love to see more videos on recon methadology for beginners . #bountypls

  • @Death_User666
    @Death_User666 6 місяців тому

    You are my favorite bug bounty channel

  • @ndmath
    @ndmath 2 роки тому +1

    Thank you Katie. I'd love to know more about Burp. #bountypls

  • @kushagraaa
    @kushagraaa 2 роки тому

    Hey Katie, glad you are back again. Could you please make a detailed video on NOSQL injection attacks. My favourite tool is httpx by projectdiscovery due to it offering so many cool features.
    Have a great day. #bountypls #bbhammer

  • @champagnepete3386
    @champagnepete3386 2 роки тому

    Great video, good resource!!

  • @Silly_lilly926
    @Silly_lilly926 2 роки тому +1

    Thanks Kate ❤️ for this giveaway I'm so inspired by you and Aditi Singh and my favourite tool is FFUF love data exposed ❤️ #bbhammer

  • @asantoshkumarachary2692
    @asantoshkumarachary2692 Рік тому

    Thanks for this video Katie

  • @andymarty80
    @andymarty80 2 роки тому

    I'd like to see videos on Anti-CSRF bypass, 2FA/MFA bypass or prediction.

  • @eraedith696
    @eraedith696 2 роки тому

    Fav tool is Burpsuite because it has some automation and also manual testing which is good and it's also beginner friendly tool and many more to learn.... Thank you❤
    #bbhammer

  • @sadabesher2886
    @sadabesher2886 2 роки тому

    Burp and ffuf is my favorite tool

  • @TechRideGamer
    @TechRideGamer 2 роки тому

    Thanks for this one its more than awesome.
    By favourite tool is Amass, fuff and in extensions autorepeater & Param Miner this are lit. #bbhammer

  • @sudokom
    @sudokom 2 роки тому +1

    My favourite bugbounty tools are FFuF, Dirsearch, and Burpsuite with this extentions such as autorize #bbhammer

    • @sudokom
      @sudokom 2 роки тому

      ... And also obsidian #bbhammer

  • @ambsambs2973
    @ambsambs2973 2 роки тому +2

    It'll be good if we get videos on web cache related vulnerabilities also once again thanks for making good contents for the community! #bountypls

  • @deepeshrane8412
    @deepeshrane8412 2 роки тому

    Awesome video, I love to use Amass and burp suite!! #bbhammer

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 роки тому

    Thank you for the video

  • @0xff1337
    @0xff1337 2 роки тому

    why you're so late katie. i was waiting for this video for so long

  • @don-ce8ig
    @don-ce8ig 2 роки тому

    Thanks for making content! My favourite bug bounty tool is burpsuite #bbhammer

  • @DevilAlpacca
    @DevilAlpacca 2 роки тому

    Awesome, will definitely use the burp addon. Fav tool #bbhammer #bountypls

  • @ronny_xavier
    @ronny_xavier 2 роки тому

    Thanks as always Katie. My fav tool is Burp definitely. #bbhammer

  • @sien1337
    @sien1337 2 роки тому

    my favorite bb tool is Burp, you can just do so much with it! #bbhammer

  • @papajohn2821
    @papajohn2821 2 роки тому +2

    Mobile application security is what I am practicing for a month now. And videos on that topic will be great to learn from. #bountypls

  • @gk_eth
    @gk_eth 2 роки тому

    Mostly there r auth bearer token for APIs which also needs to be add in cookies section?

  • @tharunbaalaji8306
    @tharunbaalaji8306 2 роки тому +1

    I like to see more vedios on business logic bugs , like taking a public program and understanding the business logic of the functionalities.#bbhammer #bountypls

  • @italoamaya8230
    @italoamaya8230 2 роки тому

    thank you so much

  • @kovanbakr
    @kovanbakr 2 роки тому

    thankyou,
    My favourite bug bounty tool is Burpsuite. #bbhammer

  • @jovensqueprosperam
    @jovensqueprosperam 2 роки тому

    Thanks for this channel

  • @darshannn10
    @darshannn10 2 роки тому

    Fav bug bounty tools - Burp, amass, nuclei, ffuf #bbhammer

  • @tommydave2908
    @tommydave2908 2 роки тому

    I'd like to learn more about SSRFs, and maybe web cache poisoning, sounds cool. #bountypls

  • @tomj1883
    @tomj1883 2 роки тому

    Thanks for the videos!!! My favorite tool is burp for sure #bbhammer

  • @subhadipnag6028
    @subhadipnag6028 2 роки тому

    Your video is really awesome :)
    Always love for Burp Suite tool for damn sure !! #bbhammer

  • @gonzalogermano2312
    @gonzalogermano2312 2 роки тому

    Thanks Katie my favorite tools is burpsuite #bbhammer

  • @roxneil1974
    @roxneil1974 Рік тому

    katie, i'm new to bug hunter, i'm still practicing about the web security system, i have joined in ingriti but i don't know what i can and can't do when looking for bugs, can you give a little direction and tips on how to work in intigriti please,,

  • @gauravdeore9477
    @gauravdeore9477 2 роки тому +1

    #bbhammer
    According to me burpsuite repeater is the best tool for hacking. We can perform any attack with it.

  • @tXambe
    @tXambe 2 роки тому

    Thanks very much for your videos and my favourite tool is burpsuite #bbhammer

  • @user-ov2ll4vc7j
    @user-ov2ll4vc7j 2 роки тому

    Katie thanks for the video. I would like to learn more about hacking APIs. #bbhammer

  • @kavishshah1988
    @kavishshah1988 2 роки тому

    Have only used Burp suite till now so I guess that's my favourite tool as of yet #bbhammer

  • @shameeluddin3563
    @shameeluddin3563 2 роки тому

    Just found your channel searching for cybersec stuff.
    My favorite tool so far is burp.
    #bbhammer

  • @morphsec
    @morphsec 2 роки тому +1

    Subdomain takeovers would be nice, saw a lot of good reports but never seemed to fully understand them. #bountypls
    Burp and Amass is the bread and butter for me. #bbhammer

  • @pushpinderkaur6570
    @pushpinderkaur6570 2 роки тому

    Thank you for this video. I would love to know more about cloud security esp AWS. #bountypls

  • @mohammadisbah1458
    @mohammadisbah1458 8 місяців тому

    @Inderderphd
    Have you find idor vulnerability which leads to privilege escalation? Could you please tell me the scenario.

    • @InsiderPhD
      @InsiderPhD  8 місяців тому

      Usually it's permission related - create mutliple accounts with different permission levels, and try and do an admin action as a regular user

  • @pr0xy_
    @pr0xy_ 2 роки тому

    my favorite bug bounty tools are amass and burp suite. #bbhammer

  • @VincentOldMark
    @VincentOldMark 2 роки тому +1

    My favourite tool is of course burp suite #bbhammer You are great Katie!

  • @kbsavage77
    @kbsavage77 2 роки тому

    Welcome back! I'd love to learn more about SSRF #bountypls

  • @IrfanAli-vp5mh
    @IrfanAli-vp5mh 2 роки тому

    Next video idea suggestion: Burp autorepeater

  • @sudarshsaraswathula1401
    @sudarshsaraswathula1401 2 роки тому

    Thanks a lot for the vid. My favourite tool is ffuf #bbhammer

  • @tajsec498
    @tajsec498 2 роки тому

    my favorite tool is burp suite, nmap :)) thanks for great contents
    #bbhammer

  • @sandiyochristan
    @sandiyochristan 2 роки тому

    Thanks Kate ❤ for this giveaway I'm so inspired by you #bountypls #bbhammer

  • @bhonenaingoo6158
    @bhonenaingoo6158 2 роки тому

    Thanks for sharing. Burpsuite of course i am just the beginner #bbhammer

  • @shamim_12
    @shamim_12 2 роки тому

    Well my favorites are FFUF and Dirsearch #bbhammer

  • @Malware01
    @Malware01 2 роки тому

    Hey, my favourite bb tools are burpsuite, sql map #bbhammer

  • @fatihburaktoprak769
    @fatihburaktoprak769 Рік тому

    My favorite is always Burp Suite! #bbhammer

  • @adamkimbro
    @adamkimbro 2 роки тому

    #bbhammer My favorite tool burp. Thanks for your videos!!!

  • @fng2971
    @fng2971 2 роки тому

    Thanks for the video, my favorite tools are burp & amass #bbhammer

  • @mikhailmaksimov8247
    @mikhailmaksimov8247 2 роки тому

    My fav to the moment is chrome dev tools ;) #bbhammer thank you Katie for another awesome video ;) and I desperately need this zseanos bbh membership :)

  • @faique2995
    @faique2995 2 роки тому +3

    Thank you for holding my hands and taking me to this level in cyber security, Be healthy and happy😁
    #bountypls

  • @Diddy81
    @Diddy81 2 роки тому

    My favorite BugBounty tool has to be Burp Suite #bbhammer

  • @danzosow5703
    @danzosow5703 2 роки тому

    Great 👍 topics I like nuclei thank you for your time and efforts
    #bbhammer

  • @maapi
    @maapi 3 дні тому

    I'm having an issue with autorize picking up requests that should be out of scope. Anyone else have this issue? This leads to a lot of extra requests to parse through, which really slows me down

  • @dimuthdeja7859
    @dimuthdeja7859 Рік тому

    Hi
    I am following your videos long time.
    My favourite tool is Burp-Suite. Thank you. #bbhammer

  • @RahulKumar-vy4lu
    @RahulKumar-vy4lu 2 роки тому

    My go-to was always Burpsuite. #bbhammer

  • @AnNafiMedia
    @AnNafiMedia 5 місяців тому

    great video

  • @devangsolanki4622
    @devangsolanki4622 2 роки тому

    Thank you for the giveaway!!
    My favourite tool is burpsuite! because Its so simple and powerfull. #bbhammer

  • @user-qe5ru6mv3l
    @user-qe5ru6mv3l 10 місяців тому

    Burpsuite is my fav

  • @prakashinfo
    @prakashinfo 2 роки тому

    My favorite bug bounty tool is nuclei..
    #bbhammer

  • @ShaneCaldwell11C
    @ShaneCaldwell11C 2 роки тому +1

    My favorite BugBounty tool is definitely Burp Suite! It's a monster. #bountypls

  • @dharneeshb4211
    @dharneeshb4211 2 роки тому

    Vim editor was my favourite bug bounty tool. It automates a lot #bbhammer