Finding Your First Bug: Choosing Your Target

Поділитися
Вставка
  • Опубліковано 16 січ 2025

КОМЕНТАРІ • 108

  • @William-B
    @William-B 3 роки тому +30

    I received my first bounty by targeting a small, relatively unknown, sub domain connected to a large public program.
    It used to belong to a small company that was recently bought out by the big one so I figured it might be an “untapped resource” if you will.

    • @KohzmikYT
      @KohzmikYT 3 роки тому

      Not to be intrusive or anything but what bug did you find??? I'm also starting to get into bug bounties and trying to find a good methodology 😁😁😁

  • @medicineman7894
    @medicineman7894 Рік тому +1

    Please never stop doing these

  • @yunemse48
    @yunemse48 5 років тому +13

    That' what I've been expecting for weeks.. Thanks!

    • @InsiderPhD
      @InsiderPhD  5 років тому +7

      :D Glad you like it, I intend to do a bug bounty methdology/approach video as a follow up to this one soon

  • @suryanshu15
    @suryanshu15 4 роки тому +9

    Thanks, that was really informative for me as a beginner

  • @jaiganesh851
    @jaiganesh851 5 років тому +9

    Really doing a great job...Loved IT ..Waiting for more to come..

    • @InsiderPhD
      @InsiderPhD  5 років тому +2

      Thank you so much, next video will be out tomorrow :)

  • @S0L4RW4V3
    @S0L4RW4V3 4 роки тому +12

    Thankyou Queen for being dope, Sharing your material to my newer team members has been a beauty.

  • @filipesimoes5398
    @filipesimoes5398 4 роки тому +2

    It was pretty much useful. Thank you very much for your help.

  • @zeecat7109
    @zeecat7109 5 років тому +5

    Great job. Thank you. And by the way, are you going to hack in to the pyramid(31:58) as well?. :)

    • @InsiderPhD
      @InsiderPhD  5 років тому +3

      Ahaha my dissertation was on deciphering ancient languages, my wallpaper is a graphic I made for my dissertations, not Egyptian but greek! The writing system is called Linear B

  • @l2m773
    @l2m773 5 років тому +6

    Thank you! Now i don't roam around on h1 for 30 minutes then start a program and give up after 5 minutes lol

    • @InsiderPhD
      @InsiderPhD  5 років тому +15

      It might help to force yourself to pick a program and just say "this week I am going to work on X, and I'm going to look for bug type Y and Z" like go deep

    • @l2m773
      @l2m773 5 років тому

      @@InsiderPhD indeed!

  • @muhammedsillah111
    @muhammedsillah111 4 роки тому +3

    you are absolutely amazing. Really appreciate the information you putting forward.Thanks!!!

  • @taylors4733
    @taylors4733 4 роки тому +1

    Thanks! Was informative. Keep uploading videos

  • @cyber-man
    @cyber-man 3 роки тому

    I really liked this presentation, will try to take into consideration every point

  • @abdullahtanveer316
    @abdullahtanveer316 2 роки тому

    an amazing video that's exactly what i was so confused about

  • @jonathanyturralde
    @jonathanyturralde 4 роки тому +1

    Killer video, very useful, Thanks for taking the time to do this. :)

  • @htsec4923
    @htsec4923 2 роки тому

    Thank you, that’s helped me a lot

  • @wingwing2683
    @wingwing2683 2 роки тому

    Thanks so much!

  • @ali7a-ts492
    @ali7a-ts492 4 роки тому +2

    Great video! All the scrolling up and down in the last 5minutes made me a bit dizzy, but other than that great content. Thanks a lot 😂✌️

  • @dees.9636
    @dees.9636 5 років тому +1

    Massive thanks 💛

  • @Timm2003
    @Timm2003 3 роки тому

    Thank u that was really useful

  • @eduardj-e8x
    @eduardj-e8x 4 роки тому +2

    Nicee, thank you for posting this video. It was very helpful

    • @SankizTime
      @SankizTime 3 роки тому +1

      You are everywhere bruh😂

    • @eduardj-e8x
      @eduardj-e8x 3 роки тому

      @@SankizTime lol XD

    • @SankizTime
      @SankizTime 3 роки тому +1

      @@eduardj-e8x bro, sorry! I don't have discord on this phone, so i am not able to talk to uu these days :(

    • @eduardj-e8x
      @eduardj-e8x 3 роки тому

      @@SankizTime Oh, it's okay buddy, text me when u can.

  • @ashrafulalim1272
    @ashrafulalim1272 4 роки тому

    Subscribed just now! your videos are awesome ❤️ please keep sharing

  • @ggmaxx66
    @ggmaxx66 3 роки тому

    thank you for your work!

  • @danielhemmati
    @danielhemmati 5 років тому +3

    I am speechless, thanks. it really helps.
    I will watch everything content you make
    you made my day. 😍😍😍😍🙏🙏🙏🙏🙏

  • @khneo
    @khneo 5 років тому

    Thanks for the video, very useful !

  • @CameronNoakes
    @CameronNoakes 2 роки тому

    brilliant video mate.

  • @CryptoRootz
    @CryptoRootz 4 роки тому +1

    great video, im motivated.

  • @GameSmilexD
    @GameSmilexD Рік тому +1

    Starting here and leaving this comment to check on in 12wks and hopefully already have found a a buf by then

  • @iitnakanpur..
    @iitnakanpur.. 3 роки тому +1

    Sounds like aussie accent 😅😅
    love your content.

  • @pentestical
    @pentestical 4 роки тому +1

    Just subbed. Amazing content!

  • @bangraph1379
    @bangraph1379 4 роки тому +1

    Great video ✌🏻✌🏻

  • @peopleyoumustknow1325
    @peopleyoumustknow1325 3 роки тому

    Thank u from Vietnam

  • @RahulYadav-qg9ms
    @RahulYadav-qg9ms 5 років тому +1

    Will you also be making practical video's on bug hunting?

    • @InsiderPhD
      @InsiderPhD  5 років тому +3

      R Y I intend to make a full bug bounty methodology/how to approach targets as a follow up to this one :)

  • @fictioncentipede9846
    @fictioncentipede9846 3 роки тому

    perfect thanks

  • @digvijaysadashivpatil650
    @digvijaysadashivpatil650 4 роки тому

    It's a very helpful and interesting video. thanks

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      Glad it was helpful! That's very kind of you :)

  • @coffeehousephilosopher7936
    @coffeehousephilosopher7936 3 роки тому

    Brilliant content

  • @manishneupane6070
    @manishneupane6070 3 роки тому

    Thank you so much for sharing it,🙏💞🇳🇵

  • @Raj_darker
    @Raj_darker 5 років тому +1

    Awesome !! Video :D K33p Posting .Thanks

  • @pawanlakhera8605
    @pawanlakhera8605 4 роки тому

    can u make a video on spf missing with what type of information should written in it nd proof also. plzz

  • @tamjid0x01
    @tamjid0x01 5 років тому

    Wow great one ..... very help-full

  • @eed5278
    @eed5278 4 роки тому

    Amazing! What do you think about XSS as first Bug bounty for a Beginner ?

    • @InsiderPhD
      @InsiderPhD  4 роки тому +2

      I have mixed opinions, I think a few years ago XSS was great! But now there's a lot involved to finding an XSS bug and most are being found by pros with significantly more expertise in bypassing WAFs. However, other people tell me that this gives beginners a good chance to learn how javascript/hacking can work. So if you ask me XSS is dead or dying for beginners. If you ask others XSS is a good first bug still.

  • @vimukthikumarasiri3993
    @vimukthikumarasiri3993 3 роки тому

    It says 'enforces a Signal Requirement'. How I can find bug bounty programs without these requirements or how to fix them?

  • @TXejas19
    @TXejas19 3 роки тому

    This was so good

  • @cybersecurity3306
    @cybersecurity3306 4 роки тому

    Why does it matter
    3:06 4:30
    Things to consider
    4:30 5:58

  • @jessyjill7865
    @jessyjill7865 4 роки тому

    i want practical demonstration of finding bugs of any vulnerabilities step by step ? and how to find the qwebsites having the bugs or not?

    • @InsiderPhD
      @InsiderPhD  4 роки тому

      You can find this in my Finding Your First Bug series or my video on Live API Hacking, both have step by step guides. To find websites to hack you register on a bug bounty platform like HackerOne, Bugcrowd, Intigriti etc, and choose a target like I'm showing on this video

  • @Alexander007A
    @Alexander007A Рік тому

    hello.. if i targeted my hacker one then how i will go their website? i will just login to their website through their link they are provided there?

  • @mohamedkaddouri9622
    @mohamedkaddouri9622 4 роки тому

    Can you make a course please ?

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      Spoilers :) by this is something I’m actively looking into less technical more how to find your first bug and get consistent :)

  • @inspirationeveryday1175
    @inspirationeveryday1175 4 роки тому

    Excellent Video ...⭐⭐⭐ ⭐⭐
    Can we use Kali Linux At live Mode ?
    or we can just use Windows or MacOs ?

    • @InsiderPhD
      @InsiderPhD  4 роки тому

      Use Windows or OSX if you’re more comfortable you DONT need Kali to do bug bounties!

    • @inspirationeveryday1175
      @inspirationeveryday1175 4 роки тому

      @@InsiderPhD thank you madame Katie you are one of my heros

    • @inspirationeveryday1175
      @inspirationeveryday1175 4 роки тому

      @@InsiderPhD please Make video when you speak about how you enter on Bug Bounty and why we can do to do what you do 🙂

  • @nelson32
    @nelson32 4 роки тому

    When showing a webpage.. could you slow down a bit? The constant scrolling doesn't allow the viewer to see what you are seeing.

    • @InsiderPhD
      @InsiderPhD  4 роки тому

      Thanks for the feedback, I will definitely slow down!

  • @fabiosanchez9595
    @fabiosanchez9595 5 років тому

    thanks!

  • @reinventingthewheel5603
    @reinventingthewheel5603 2 роки тому

    What is “scope”

    • @InsiderPhD
      @InsiderPhD  2 роки тому

      That’s the stuff you’re allowed to hack or not allowed, it means if you find a bug in X software they will pay a bounty :)

    • @reinventingthewheel5603
      @reinventingthewheel5603 2 роки тому

      @@InsiderPhD thanks so much

    • @reinventingthewheel5603
      @reinventingthewheel5603 2 роки тому

      Thought it was a tool or something

  • @zeuscybersec659
    @zeuscybersec659 4 роки тому

    Katie pls help.What are the prior knowledge needed for bug bounties? Shoud I do vulnerable web applications?any good books

    • @InsiderPhD
      @InsiderPhD  4 роки тому +3

      zeus cybersec
      0: How the web works (Web application hackers handbook - free at HackerOne is great for this)
      1: How to use burp (my videos + practice)
      2: What bugs are out there and the signs of them (my videos)
      3: How to exploit these bugs (practice on CTFs /real targets)

    • @zeuscybersec659
      @zeuscybersec659 4 роки тому

      @@InsiderPhD thing is I am in this field for 1 year.Preparing for oscp and done many oscp like ctfs.I am more of a network guy but I love web security too.I have done dvwa and Over the wire Natas challenge.I have a good idea on advancd used of Burpsuite.What ctfs/books do you recommend for Getting good in web?Also I don't feel confident as I have given most of my time to ctfs be it network or web.Please help me Katie🙁How can I boost my confidence and what web related books/ctfs should I finish before dipping my feet into bug bounty?

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      I think given your experience you need to START HACKING. It’s always going to be tough but that’s eventually where you want to be so pick a bug, pick a target and just START HACKING. Will it be hard, of course! But nothing worth doing is easy!

    • @zeuscybersec659
      @zeuscybersec659 4 роки тому

      @@InsiderPhD True.Thanks Katie☺️By the way can I add u on insta?I like connecting to people in the community

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      I don't have instagram I'm afraid! But you can follow me on twitter and @ me any time if you have questions and I will DM you :)

  • @hbbss8684
    @hbbss8684 4 роки тому

    best "complete beginner bug"?

    • @InsiderPhD
      @InsiderPhD  4 роки тому

      hbbss hbbss IDORs for sure, not that technically complex, and you can just methodically test endpoints one by one. Relies more on determination than technical skills

    • @hbbss8684
      @hbbss8684 4 роки тому

      Sick! Thanks again for your help, love the content!!

  • @axefallerdelarosa
    @axefallerdelarosa 2 роки тому

    Killer video, very useful, mic sucks

  • @imcool2791
    @imcool2791 4 роки тому

    lol i got no skills or knowledge about coding how can i do it

    • @InsiderPhD
      @InsiderPhD  4 роки тому

      Check out the whole series, especially Business Logic and IDORs which I think are great first bugs when you haven't got a lot of technical skills yet. You can also practice with CTFs

  • @prithviraj6529
    @prithviraj6529 4 роки тому +1

    very low audio volume. had a hard time tbh

    • @InsiderPhD
      @InsiderPhD  4 роки тому +1

      I’m unfortunately not a great UA-camr lmao and it took me a few attempts to get the audio right, for the moment just increase the volume but in the future I have fixed this issue!

    • @prithviraj6529
      @prithviraj6529 4 роки тому

      @@InsiderPhD i ran it on big speakers used earphones did eq on chrome to boost high end still was quite low. hoping to see a fix soon. thanks for resonding. #ayylmao for life.

  • @j.a.7724
    @j.a.7724 4 роки тому

    Yankee with no BRIM!!

  • @everything6504
    @everything6504 2 роки тому

    Hi what is your age plz

  • @ThushyCyber
    @ThushyCyber 3 роки тому

    Good

  • @kallikantzaros
    @kallikantzaros 4 роки тому

    How old are you?

  • @lightyagami5776
    @lightyagami5776 5 років тому +1

    Cute voice

  • @aashikyadav4439
    @aashikyadav4439 5 років тому

    Love your voice. so sweet. :)

  • @aloneking5388
    @aloneking5388 2 роки тому

    Your voice is wery low please chenga your mic