How I Choose Bug Bounty Targets

Поділитися
Вставка
  • Опубліковано 8 лис 2024

КОМЕНТАРІ • 29

  • @chenfoot3663
    @chenfoot3663 2 роки тому +15

    You're literally that kind of gem that I'd want to hide from everyone so I can be the only one that sees it xD. Keep going man. You really help a lot.

    • @kaoh1778
      @kaoh1778 Рік тому +2

      Great minds think alike. It's worth noting the gem's true beauty and worth shine brighter when it is discovered by many more great minds.
      Let's celebrate the gems within ourselves!

    • @DavidCrow-ks1zz
      @DavidCrow-ks1zz Рік тому

      pls am new in hackerone i need help plssss

  • @minhld8736
    @minhld8736 Рік тому

    I love the way you deliver Yoda's quote, thanks a lot for your sharing, keep up the good work!

  • @nazusec
    @nazusec 2 роки тому +2

    Thank u ar right we must spend a lot of time by choosing a target

  • @saglamairdropstrongairdrop495
    @saglamairdropstrongairdrop495 Рік тому +1

    whats your suggestions for beginner bug bounty hunters about scope? Which easy ones should i focus? Open redirect,self XSS etc. mostly not paying and out of scope.

  • @AnthonyMcqueen1987
    @AnthonyMcqueen1987 2 роки тому +1

    Me personally i go for the larger scopes which means more opportunities to find critical in a ocean with a thousand other dudes. Then in a pool swimming with a thousand other dudes.

  • @محمّد.09
    @محمّد.09 Рік тому

    Last tip was the best

  • @Mr_tadoo
    @Mr_tadoo 2 роки тому

    last tip was interesting🔥

  • @d1hoops975
    @d1hoops975 2 роки тому +2

    As a beginner, what realistically should I be looking for as my first bug ? Idors, xss or something else easier?

    • @ryan_phdsec
      @ryan_phdsec  2 роки тому +6

      If you are good with HTML then xss will be the easiest. If not then I would recommend looking for IDORs. However look for IDORs in hard to get places. Maybe something like this, go to a random subdomain that requires you to login, and look around. People look in easy places so the key is to go where other people are too lazy to look. Tomorrow I am going to release a video about shodan and maybe you can use that to look for sensitive data. It is tedious and time consuming but very beginner friendly.

    • @d1hoops975
      @d1hoops975 2 роки тому

      @@ryan_phdsec Thank you very much, can't wait for the shodan video 🙏

    • @ryan_phdsec
      @ryan_phdsec  2 роки тому +1

      @@d1hoops975 It will be tomorrow. Sorry I had some things come up 🙃

    • @d1hoops975
      @d1hoops975 2 роки тому

      @@ryan_phdsec I'm sure it will be worth the wait 😁

    • @abdonito8254
      @abdonito8254 Рік тому

      After 3 month you find your first bug or no ??

  • @denverzimunya8303
    @denverzimunya8303 2 роки тому +1

    Thank you for the great n educational content, keep up the wonderful work.

  • @kenichishirahama513
    @kenichishirahama513 2 роки тому

    Reminds me of (meet the robbinsons) movie quote

  • @coffinplayz
    @coffinplayz Рік тому

    Why you look like AI no expression in face 😂❤

  • @ajsoumyadip1694
    @ajsoumyadip1694 2 роки тому +1

    sir please make a video as a begineer how to start HTB. account create , how to deploy machine , which machine best for beginning .... please make a one video sir.........

    • @mojxng114
      @mojxng114 Рік тому

      Tryhackme is probably more suited for beginners, was 7 months ago hope your cyber journey has gone well.

  • @ananthakrishnaner9807
    @ananthakrishnaner9807 2 роки тому

    ❤️❤️❤️❤️

  • @PetritK10
    @PetritK10 2 роки тому +1

    which is better hackerone vs intigriti

    • @ryan_phdsec
      @ryan_phdsec  2 роки тому +1

      If you know a language other than english I would use Intigriti because it will have less hackers on it.

  • @Ryclic
    @Ryclic 2 роки тому

    do you recommend hackerone as the platform a beginner should start on, or is there something with less people? i'm not necessarily looking for any paid bounties, just want to start with finding and writing reports before i even think about the monetary side of it