Hunting IDOR with Z-winK (Part 2)

Поділитися
Вставка
  • Опубліковано 14 лип 2022
  • Welcome to the fifth piece in Bugcrowd's LevelUpX series! Our speaker in the series is Z-winK. In this presentation, Z-winK will build on his latest series and will take you through a deeper dive into hunting IDOR (Insecure Direct Object Reference) for big dollars.
    Want to get involved?
    We’re always looking for researchers and hackers like you who have tips, tricks, and skills that you want to share with the community! If you have any questions, or would like to participate with LevelUpX, please reach out to researcher.marketing@bugcrowd.com
  • Наука та технологія

КОМЕНТАРІ • 36

  • @kittoh_
    @kittoh_ 7 місяців тому +7

    This is one of the few videos that is legitimately teaching actual knowledge. Hoping his channel would come back.

  • @CodingQuan
    @CodingQuan Рік тому

    One of the cleanest easy to understand videos on the topic!! 💯Bravo

  • @CodeAcademia00
    @CodeAcademia00 Рік тому +1

    Thank you man , thats so amazingly helpful ❤

  • @ciconid
    @ciconid 3 місяці тому

    Great video!!! Loved the phrase "It doesn't require rocket surgery" :)

  • @ZaG-yo3fd
    @ZaG-yo3fd Рік тому

    Great explanation! Thanks Z-winK😁🙌✌💪

  • @modmah7191
    @modmah7191 Рік тому

    thanks for the amazing video!
    please make more content about another vulnerabilities.

  • @wardellcastles
    @wardellcastles Рік тому +12

    Great video!
    In my research into hacking APIs, rarely do I find IDs in the GET request. If I see any ids they are highly encoded in the cookie. What do you do when you see this?

  • @diegopirela9808
    @diegopirela9808 Рік тому +2

    thank for information bro you are great

  • @shuvamadhikari2662
    @shuvamadhikari2662 Рік тому +1

    Awesome video 😄 ❤.

  • @haanrey
    @haanrey Рік тому

    I like when ryan reynolds himself teachers IDOR !! Just Awesome !!

  • @tayyabch2868
    @tayyabch2868 Рік тому

    Nice tutorial. I have been having content issues with my hmdi connected speaker and subwoofer. No soft is coming through, still coming out of

  • @techguru5230
    @techguru5230 Рік тому +5

    where is part1

  • @nikeshrajbanshi647
    @nikeshrajbanshi647 Рік тому +1

    very helpful video

  • @extrabgmi2788
    @extrabgmi2788 Рік тому

    very very gooood, thaaankss maan

  • @robot67799
    @robot67799 Рік тому

    Thank-you ✨

  • @birch8005
    @birch8005 Рік тому +3

    Z-winK, when you are testing for idor, which are not numerical values can you irritate over the list not exposing sensitive information?🤔

  • @robot67799
    @robot67799 Рік тому

    26:51 Damn, that's cool

  • @aliuzun8885
    @aliuzun8885 4 місяці тому

    Ty

  • @StephenOgu
    @StephenOgu Рік тому

    Favorite bugs 🐛

  • @andrewalba369
    @andrewalba369 Рік тому +1

    project a lot because I've been working on other stuff (and being lazy lol). Also, I had been facing a recurring problem of content dropouts in

  • @user-ey5ob2ow7y
    @user-ey5ob2ow7y 7 місяців тому

    Where is part 1 plz

  • @prabuinet
    @prabuinet 11 місяців тому

    where is part 1

  • @sharifulislamshupol8364
    @sharifulislamshupol8364 Рік тому

    What is this site/ others?
    How to works in this site?
    plz help me.

  • @imosolar
    @imosolar 8 місяців тому

    Please what about the cookie swap with accounts

  • @gitanshgulati1732
    @gitanshgulati1732 Рік тому +1

    I procrastinated for 6 years

  • @WaseemAkram-kx7tq
    @WaseemAkram-kx7tq Рік тому +5

    Where is first part ?

  • @UK-TECH-
    @UK-TECH- Рік тому

    The GMS that you use here is completely different softing than the one I use even though I'm using tNice tutorials exact software, why is tNice tutorials?

  • @ArSiddharth
    @ArSiddharth Рік тому +1

    I want to start bug bounty...
    And I just don't wanna start, I also want to find bugs,
    So first I have to learn then I will do this
    so where do i start learning.

    • @wardellcastles
      @wardellcastles Рік тому +1

      Portswigger Web Academy is a good place to start.

    • @haksting
      @haksting Рік тому

      @@wardellcastles +1

  • @thewholeworldblurred
    @thewholeworldblurred Рік тому +2

    All his videos are gone

  • @Aditya-vv3sq
    @Aditya-vv3sq Рік тому

    !

  • @EhsanEnglishCare2000
    @EhsanEnglishCare2000 Рік тому

    lmao XDDD

  • @samindunimsara
    @samindunimsara Рік тому +1

    If you saw api/detaback/?ad_id=1234577