Live Hacking Tutorial: How to Think Like a Bug Bounty Hunter

Поділитися
Вставка
  • Опубліковано 9 лют 2025
  • Learn how to hack like a bug bounty hunter in this live hacking tutorial! In this video, I will show you how to find and exploit vulnerabilities in real time, using the same techniques that bug bounty hunters use to earn thousands of dollars every year.
    This tutorial is perfect for beginners, but even experienced hackers will learn something new. I will cover everything from the basics of web application security to more advanced techniques like SQL injection and XSS.
    By the end of this video, you will be able to think like a bug bounty hunter and start finding vulnerabilities on your own.

КОМЕНТАРІ • 129

  • @RohitRajput-xm8hg
    @RohitRajput-xm8hg Рік тому +12

    "SEAN, professional pizza maker (and eater!), can cut your hair also if required."LMAO🤣

  • @alexandrosmitsouli8763
    @alexandrosmitsouli8763 6 місяців тому +11

    Good content brother, good vibe I almost felt we were together on this , I have been learning on my own for the last 3 months , and I am aiming in starting gaining some spare money from bug bounty ( in my own pace ), you were really helpful , hope to see you live as well

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  6 місяців тому +3

      Hey m8 big thanks for the kind words! I'm planning to add some more structure to the channel :)

  • @im_hunter87
    @im_hunter87 Рік тому +83

    Thats how i exploited my university's website 🤣.
    best method : learn from practical experiments. ❤

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Рік тому +8

      Whaha love it 😂

    • @benatobeqiraj6483
      @benatobeqiraj6483 Рік тому +1

      Ur a god teach me masterr

    • @goblinninja1234
      @goblinninja1234 Рік тому +1

      What did you do to the website

    • @im_hunter87
      @im_hunter87 Рік тому

      @@goblinninja1234 just got access of my classmate's account(with their permission). and then reported to our HOD, about it.

    • @futuretrunks6927
      @futuretrunks6927 Рік тому

      I did that too when i was in my school, i got access to the admin cpanel acc through sql injection

  • @willson1646
    @willson1646 Рік тому +37

    Would love to see a video like this where you implement/script a scraper tool to automate the process. Great content 👍🏻

  • @thenarrowgate3063
    @thenarrowgate3063 11 місяців тому +1

    I love how much fun your having while hacking, I'm the same way I get excited every time I come across an anomaly I can exploit 👏👍

  • @amoh96
    @amoh96 Рік тому +4

    im beginner bug hunter new to this channel want more videos about mindset and manuel aproach for bug bounty & more vidoes related to bug bounty i really hate automation i love manuel work and dig deep thank you brother

  • @afggg8194
    @afggg8194 3 місяці тому +2

    thanks for this. did you do any certifications which utilised ur knowledge to do pen testing or was it all self taught using platforms and yt vids?

  • @Nightmare-23
    @Nightmare-23 Рік тому +8

    Would be great if you create the python program for retriving the values from the form.

  • @coolperzon63
    @coolperzon63 Рік тому +8

    what is your notion template? you mentioned that you use notion and Im curious

  • @YA-xv9ig
    @YA-xv9ig Рік тому +5

    great work ! I hope you continue making clips like this

  • @skysunset877
    @skysunset877 Рік тому +5

    Thank you so much for the good information!👍👍 I'm a bugbounty novice, and it's been a great help. By the way, are there any restrictions on the scan tools you use to run a bugbounty? I'd like you to let me know if you've experienced any examples

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Рік тому

      Hey m8 that depends from
      The company, like some just doesn’t like automated scans and then they are restricted to 1 request a sec😁

  • @gazbowyer8617
    @gazbowyer8617 11 місяців тому

    Thankyou, followed along and learnt a lot, keep up the awesome work , 👍

  • @tonyjo5224
    @tonyjo5224 5 місяців тому +1

    18:00 you set target url here, you missed fastfood part between bugbountytraining and /admin. Maybe you could found more vulns

  • @rodolfojr.valdez7284
    @rodolfojr.valdez7284 2 місяці тому

    Hi I really like your videos and I was able to enhance my hacking skill by watching it. Just a question was there already a video for the scraper tool that you mentioned here? I do appreciate your videos because it was really helpful for me as a novice for this profession.

  • @SazidHossain-y2h
    @SazidHossain-y2h Рік тому +2

    Wonderful Hacking Tutorial Brother. Learned a lot. Tnx

  • @nassvandrunen6020
    @nassvandrunen6020 Рік тому +1

    Will try the export target= It seems Nice

  • @aryamannkhare9505
    @aryamannkhare9505 Рік тому +1

    Amazing Vide! Loved it:)

  • @khalnayakgamer6607
    @khalnayakgamer6607 Рік тому +2

    Very nice video 🎉

  • @febzey445
    @febzey445 Рік тому

    Great introduction to this type of activity

  • @lilham9044
    @lilham9044 10 місяців тому

    GREAT VIDEO!!!..... How did you kno to type that in the GET REQUEST in Burp Suite?

  • @Max-wn1ed
    @Max-wn1ed Рік тому +1

    Can you make a video on how to start, explore and find career path in cybersecurity.?

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Рік тому +1

      Yea sure maybe I call
      Tell my story I got hired because of a project I made en the motivation 😁

  • @kokurate
    @kokurate Рік тому +4

    That's a very good tutorial, really appreciate it. Anyway, could you share your wordlist you usually use when doing bug bounty?

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Рік тому +3

      You can use seclist for a lot of labs and in real the best is to make custom list for a target you can use a Python program or a language model 😁

    • @davidharding3465
      @davidharding3465 Рік тому

      You could use cewl to create a wordlist specific to the target.

  • @0xdiato
    @0xdiato Рік тому +2

    amazing job, i learned a lot. PLS DO MORE VIDEO LIKE THIS!!!!

  • @Aromatiquevibes
    @Aromatiquevibes Місяць тому

    is there any video of automatically information save ? i mean like a code or a tool. please help

  • @RichardinSA
    @RichardinSA Рік тому +1

    I like your style!

  • @parwatsingh677
    @parwatsingh677 Рік тому +1

    Thank you 😊

  • @MustafaGains
    @MustafaGains Рік тому +2

    Great 👍🏿

  • @Tyagi174
    @Tyagi174 Рік тому +2

    One question sir i wanted to come into bug bounty does i need to learn networking or just strt with practicals and tut on UA-cam

  • @Khalid-bm4fw
    @Khalid-bm4fw Рік тому +2

    Cool
    Just do more video like this.
    Thanks a lot

  • @onyxdetailing9163
    @onyxdetailing9163 Рік тому +3

    awesome video. quality content.

  • @shubhambajaj4939
    @shubhambajaj4939 Рік тому +6

    are there other areas in cybersecurity except for bug bounty hunting? I really like infrastructure network bug hunting but not sure if they have a similar type of bounty programs.

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Рік тому

      Yea you can become a network expert and protect networks or try to find some bugs in it. Euh that is mostly done by a company because it has a lot more risk to just let everyone in the network. But there are great courses with labs😁

    • @user-wf9oc4bq3e
      @user-wf9oc4bq3e Рік тому

      ⁠@@CyberSquad-JoinTheSquadagreed. Cause it kind pf related to the LAW. One wrong step then might go inside

    • @watchmo2310
      @watchmo2310 9 місяців тому

      @@shubhambajaj4939dude said teach him one to one lmaooo

  • @diefer8093
    @diefer8093 Рік тому +1

    Good job bro. Thanks for this information.

  • @scriptkiddie-fo3vo
    @scriptkiddie-fo3vo Рік тому +1

    ur videos are really helpfull thanks u will be soon big W guy

  • @behenuemichael6051
    @behenuemichael6051 10 місяців тому +1

    doesn't scanning puts a pressure on the webpage server? don't we send requests continously while scanning ?

    • @epokal1
      @epokal1 6 місяців тому

      afaik, only verbose and continuous scanning does this

  • @raven-vr5yz
    @raven-vr5yz 6 місяців тому +1

    I'm not a pro, but I immediately thought about exploiting ssrf with that redirection url...

  • @cyberman6021
    @cyberman6021 Рік тому +1

    Rare content, thank you i like it :)

  • @denimsahu7718
    @denimsahu7718 10 місяців тому

    What i don't understand is even tho you found that xxs valun but since there is no way to make you js add to the website source code unlike having xxs valun when placing a order or something which results in our malicious js code being saved into data base and getting executed whenever someone opens out order but in this website case there nothing like that so can someone please explain me how it will help us? Yeah it a valn but not that useful since we just can't go and hijack someone user or admin session using this , I'm a beginner so please help if I'm not seeing the bigger picture here

  • @brain.rot.indian-x2w
    @brain.rot.indian-x2w 26 днів тому

    i have betting website can you find admin panel and admin id password

  • @articfox1934
    @articfox1934 2 місяці тому

    Need more videos from u brother.

  • @dalo1100
    @dalo1100 3 місяці тому

    im a noob, but for the part where he exploited the redirect, would anyone visiting the site be hit by the alert box?

  • @MediaClipGames
    @MediaClipGames Рік тому

    i was like why does he not check order number 1-3 it would probally be snowy or the other guy emails

  • @ESPECTRO.1
    @ESPECTRO.1 Рік тому +1

    Produto da ferramenta e paga correto?

  • @SalNeidenbach
    @SalNeidenbach 2 дні тому

    Appreciate it for sharing! I need guidance: My wallet on OKX has some USDT, and I possess the SEED: -clean- -party- -soccer- -advance- -audit- -clean- -evil- -finish -tonight- -involve- -whip- -action-. What’s the best way to handle moving them to my Binance account?

  • @warri0rs16
    @warri0rs16 Рік тому +2

    Nice video can you make more videos on SQL injection,ssrf and xss

  • @galliharmada617
    @galliharmada617 Рік тому +1

    its awesome!

  • @yaboy7120
    @yaboy7120 Рік тому +2

    can you talk more about your origins 😃

  • @shashankk7827
    @shashankk7827 Рік тому

    admin.php is a file, so there is no use of doing dirb on it because its not a folder…am i right?

    • @as3ad.
      @as3ad. Рік тому

      It depends on the dirb-busting tool used. GoBuster does not support file extensions, but there are tools that do e.g. FeroxBuster, which you can specify extensions to search for (e.g. php,html,asp,aspx, txt). Ferox will use the words in the specified wordlist, and append the extensions when fuzzing.

  • @nazuko2721
    @nazuko2721 5 місяців тому

    how did you directly copy url from windows to linux?

    • @thegaminggoblin1197
      @thegaminggoblin1197 3 місяці тому +1

      That's what i was thinking. When I was in school we had a specific VM that allowed this but I can't find it

  • @Maik.iptoux
    @Maik.iptoux Рік тому +4

    20:30 You missed multiple times that you use the wrong url on dir buster, and I notice this on smartphone...

  • @aryzen2781
    @aryzen2781 10 місяців тому

    how many bugs have you found doing bug bounties?

  • @GeraldPajulas
    @GeraldPajulas Рік тому +1

    After downloaded a bootatble kali linux distro. Then watching this is 👌

  • @TheCalax
    @TheCalax Рік тому

    What if the Bug Bounty Program only allows me to scan like, 2 requests per second? This all is gonna take ages

  • @timtzu6034
    @timtzu6034 Місяць тому +1

    what did he do?

  • @Yash.Lonewolf
    @Yash.Lonewolf Рік тому +1

    excellent

  • @sheronizes6993
    @sheronizes6993 11 місяців тому +1

    in reality, burp will intercept one million useless request and just create an account recquire a lot of patience

  • @razdingz
    @razdingz Рік тому +1

    this good - here take joint bro

  • @TheFuture36520
    @TheFuture36520 Рік тому

    Imagine hacking someone via a UA-cam comment 😂

  • @h5e
    @h5e Рік тому

    Pls part 2

  • @jhonwick-s9x
    @jhonwick-s9x Рік тому

    are you a professional hacker??

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Рік тому +4

      Hey I’m a junior application security engineer so yes but still learning every day😁

  • @tranquilla-videos
    @tranquilla-videos 11 місяців тому

    is this is how we perform Bunty Bounty?

  • @mohdbilal5672
    @mohdbilal5672 4 місяці тому

    if it's clickable it's hackable

  • @Relax_sound121
    @Relax_sound121 8 місяців тому

    How to hack aviator game round plz help me

  • @Lucifersatan001
    @Lucifersatan001 8 місяців тому

    How to hack Aviator

  • @neeroseg.pradhan9311
    @neeroseg.pradhan9311 Рік тому +1

    Hello bro

  • @ZERO247-1
    @ZERO247-1 7 місяців тому

    19:30

  • @Teslas_Workshop
    @Teslas_Workshop 11 місяців тому

    you missed many more vulnerabilities

  • @Kulwazoldik
    @Kulwazoldik Рік тому

    Can you help me hack an application lovley pet؟؟

  • @RAN522-p5o
    @RAN522-p5o Рік тому

    ua-cam.com/video/mALRt5SXMeI/v-deo.html

  • @bobbydrillboid
    @bobbydrillboid 9 місяців тому +2

    honestly a horrible video, you talk through it and do stuff as if we fully understand everything you are using and talking about, but that is far from the truth. I don't know much about this stuff at all and I'm trying to learn how to do it, but if you don't explain how to use every single thing piece of everything than I get completely lost and want to close the video because I cant follow along. For example, I don't know how to work burpsuite or set it up, so when you're clicking around and doing things i cant follow along. You should include the entire process of EVERYTHING I don't care how long the video gets, I need you to talk to me like I know nothing about this stuff at all, because that's kind of the case.

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  8 місяців тому +1

      I will try making some more basic vids mate 😁

    • @Schizohandlers
      @Schizohandlers 8 місяців тому +1

      Skill issue

    • @alan-t7b
      @alan-t7b 7 місяців тому +1

      There are other resources to learn how to use the tools you are unfamiliar with. You could look up a video on setting up a Kali Linux VM to start.. learning is a process.

  • @Towersfam43232
    @Towersfam43232 Рік тому +1

    guy thinks hes a hacker using typical programs. Dude cmon your brain smaller then your biceps for sure

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Рік тому +2

      I don’t think aim a hacker, I work in the field of cybersecurity and I don’t ask you to watch my videos. I love to see some videos where you show your skills and maybe I can learn some of that😁

  • @nimaism
    @nimaism Рік тому +1

    nice bro

  • @bigerrncodes
    @bigerrncodes 10 місяців тому

    Order ID 42069 lol

  • @RAN522-p5o
    @RAN522-p5o Рік тому

    ua-cam.com/video/mALRt5SXMeI/v-deo.html