Easy $500 Vulnerabilities! // How To Bug Bounty

Поділитися
Вставка
  • Опубліковано 1 лют 2025

КОМЕНТАРІ • 255

  • @NahamSec
    @NahamSec  4 місяці тому +2

    📚 Purchase my course and learn about bug bounty hunting with over 11 hours of content, 100+ labs, and 15+ vulnerability types 👇
    hhub.io/HWTl-LpLF0

  • @MrFrankenstock
    @MrFrankenstock Рік тому +24

    Hands-on demo would definitely be a great way to absorb and ultimately solidify this content in the old brain! Thank you, Ben!

  • @marcelosmoniz
    @marcelosmoniz Рік тому +34

    ● [1:41] Prerequisites: HTML, Web Technologies
    ● [1:57] #1 - XSS
    ● [4:03] #1(2) - CSRF
    ● ● [4:11] Burp Suit PRO : "Engagement tools" -> "Generate CSRF PoC"
    ● [6:22] #3 - IDOR
    ● [8:46] #4 - Authorization Issues
    ● [10:34] #5 - Leaked Credentials

    • @NizarZaidh
      @NizarZaidh 5 місяців тому

      bro doing social service 👍

  • @minimanimo7636
    @minimanimo7636 Рік тому +58

    It would be very helpful and interesting to have videos on:
    - How to quickly and efficiently write a bug report (templates, automation, AI and so on...)
    - What are the most common BBPs policies and practices for not breaking them (rate limit, automation limitations)
    - Burp suite: best extensions and when to use
    Thanks mate, love your videos and appreciate your work!

  • @SyedShayan-yt3in
    @SyedShayan-yt3in Рік тому +169

    Hey! Would love to see the demo videos on each vulnerablity type.

    • @NahamSec
      @NahamSec  Рік тому +50

      Noted!🫡🫡

    • @eviI_genius
      @eviI_genius Рік тому +7

      @@NahamSec yes we want demo, specially it would be great if you explain us XSS in deep like using the dev tools, inspecting the element, give us some deets about how backend XSS works, I really loved ur Bling XSS video :) it would be great if you build up on that

    • @darkalpha2701
      @darkalpha2701 Рік тому +1

      @NahamSec I would really love to see demo video of IDOR

    • @karthik3387
      @karthik3387 Рік тому

      Plse do vedio

    • @CruzNateChroniclles
      @CruzNateChroniclles Рік тому

      Video vulnerability examples would be great.

  • @MarkFoudy
    @MarkFoudy Рік тому +26

    Yes please do a demo of the vulnerabilities. Love your encouragement! Your videos always pump me up!

    • @NahamSec
      @NahamSec  Рік тому +10

      Thanks for watching and thank you for being a channel member! 🙏

    • @MarkFoudy
      @MarkFoudy Рік тому

      of course! I hope to meet you at defcon in the future. Your content has been so impactful for me. @@NahamSec

  • @mianashhad9802
    @mianashhad9802 Рік тому +23

    CSRF and IDOR hands-on tutorials would be interesting. Would love to see some handy tricks for when our attacks aren't working.

  • @DavitHayrapetyan-tc1uj
    @DavitHayrapetyan-tc1uj Рік тому +2

    this channel is literally a goldmine, don't understand how it's only 105k subscribers

  • @OmphemetseMokene
    @OmphemetseMokene Рік тому +2

    Am planning on being a full time bug bounty hunter this coming January, but my piggy bank is still behind ..if i could i would take your bug bounty course to fortify my skills..,gotta say your vids really motivate me..cheers!! from Botswana

  • @azoosh
    @azoosh Рік тому +2

    Yes! I would very much want to see more hands on videos on these bugs :) Your videos are awesome always!

  • @omarmahmood4209
    @omarmahmood4209 Рік тому

    Yes, would absolutely love a hands on video on each of all the topics!
    1. XSS
    2. CSRF
    3. IDOR
    4. Auth Issues
    5. Leaked Creds

  • @alexandriarichard7671
    @alexandriarichard7671 Рік тому +1

    Listen $500 is a lot for me and thank you so much for this video! I am going to focus on Blind XSS and start your Udemy course thank you!

  • @bertrandfossung1216
    @bertrandfossung1216 Рік тому +1

    A hands on version of this video where you can make some labs will be highly appreciated. Thanks for the cool heads up !!

  • @TrailMix324
    @TrailMix324 Рік тому

    Yes i would genuinely love to see and would definitely watch hands on demo videos of each vulnerability type

  • @papafhill9126
    @papafhill9126 Рік тому +9

    Honestly, I care less about learning the hands-on-tutorials about specific vulns, I would much rather see a tutorial on how to enumerate a target and suggestions on how to learn the technology the target is using. What questions should I be looking to answer about that tech? How to check for previous CVEs on that specific tech? Then maybe most importantly, how can track data flow of the target with that specific tech in mind. The issue with seeing tutorials on specific attack types seems to be trying to attack the same few input fields for hours but ignoring the all the technology used on that webpage that would likely tell me, "Hey, this page is pretty secure, maybe keep digging into other subs/ends."

  • @VinceOConnor
    @VinceOConnor Рік тому +1

    Yes, Love the content and would love you to do a demo of the vulnerabilities.

  • @marijasilentj969
    @marijasilentj969 Рік тому

    Yes please! You really talanted tutor! It easy to understand and follow you. Thank you a lot xx

  • @AnonymousTrust21
    @AnonymousTrust21 Рік тому

    If I get $500 based on content made available for then I will purchase your course based on that. Good luck to you too!

  • @damavox
    @damavox Рік тому +1

    I love ya dude and you do a lot of for the community!
    But as someone who heard the same information from different sources what I would love to see is training, the secret sauce, and technique sharing. I know in bug bounty those things are held close to the chest but for someone stuck in the middle from beginner to practitioner, it would really help all us in that position to advance and level up.
    I would even be willing to pay.
    Thank you my friend
    Let's see that demo!

    • @mugstep
      @mugstep Рік тому

      You just unlocked how bug bounty hunters really make money.

    • @damavox
      @damavox Рік тому

      @@mugstep 🤣🤣
      I'm going to assume lots of sarcasm in that comment to which in hindsight.
      I completely agree.

    • @damavox
      @damavox Рік тому

      @@mugstep I'm sure jason haddix's course is full of information like that.
      At least enough for one to develop their own secret sauce but also I want to hear from different sources.

  • @MW-cs8zd
    @MW-cs8zd Рік тому +2

    I would love more videos like this from you. Very helpful. Thank you

  • @ASecurityPro
    @ASecurityPro Рік тому +1

    Please do a hands on version of each vulnerability . Thank you man ❤

  • @alexaliwarlock
    @alexaliwarlock Рік тому

    That’d be awesome to see a demo video. Keep up the great and educational content! 🙌

  • @darealist232003
    @darealist232003 Рік тому

    Yes, can we get a demo video showing how to look for these vulnerabilities. I just got my Sec+ and have been interested in learning more about bug bounty. Thanks for the video and get up the great work.

  • @mynameisrezza
    @mynameisrezza Рік тому

    Gold! Cant wait to see the demo of those vulns, thanks ben!

  • @nhlimon201
    @nhlimon201 Рік тому +3

    Hey Ben, It will be better to share step by step resources to learn, master and get confidence of hunting for a specific bug. :) It would be a really awesome content. People like me sometimes get confused how they could master a bug and how to learn that at an insane level to get out of average hackers. So I hope you'll make this content in near future.

  • @AbdulRaufFawwazKhan
    @AbdulRaufFawwazKhan Місяць тому

    This was a very informative video. I think that you should make a video with each of the vulnerabilities you spoke about.

  • @Cyber10791
    @Cyber10791 Рік тому

    Needs brother these types of beginners friendly bugs and how to test for it it's very helpful.
    Looking forward too see these types of videos.

  • @prasadande5690
    @prasadande5690 Рік тому +1

    Yes Ben, Please also provide a demo of all those vulnerabilities :)

  • @JoseSanchez-ue9wk
    @JoseSanchez-ue9wk 11 місяців тому

    Yes Naham we would love to see a hands on demo!

  • @francisstocktilliii2413
    @francisstocktilliii2413 10 місяців тому

    I would love to see a hands-on video of this. That's exciting to hear.

  • @mrashco
    @mrashco Рік тому +1

    Would love more in-depth videos on each topic mentioned!

  • @Z0nd4
    @Z0nd4 Рік тому

    I like this content. Yes NahamSec, please do more videos. Thank you.

  • @Bitcoin1y
    @Bitcoin1y Рік тому

    i want a hands-on version of this. I love these videos.

  • @litebulbentertainment
    @litebulbentertainment Рік тому

    Yes.... The content is really good... Looking for demo video on each vulnerability

  • @ralphandre4438
    @ralphandre4438 Рік тому

    This is amazing! I want to find my find my first live bug, paid or not before the year end. I would love the video demo.

  • @IvanIvanov-ix5no
    @IvanIvanov-ix5no Рік тому +1

    I am looking forward to seeing a demo of those vulnerability types :)

  • @youssefm5079
    @youssefm5079 Рік тому +1

    Yeeees hands on videos and thank you so much ffor this content

  • @Sasquatchbones
    @Sasquatchbones Рік тому

    Honestly learned a lot really fast, clickbait was worth it 😂

  • @jeremyg737
    @jeremyg737 Рік тому

    It would be awesome to see a video on encoding. Both from a defensive point of view and as a method of obfuscation.

  • @ismailsaid6389
    @ismailsaid6389 Рік тому

    Man, for god sake i love your content

  • @jkong3553
    @jkong3553 Рік тому

    Def would love to see the demo. Very informative

  • @hpuser-ui3tp
    @hpuser-ui3tp Рік тому

    Hey! I Would love to see the demo videos on each vulnerablity type.

  • @akshaybhorde3787
    @akshaybhorde3787 10 місяців тому

    It was very helpful for me. Good approach and techniques. Share your practical knowledge also.

  • @Mbro-dq2do
    @Mbro-dq2do Рік тому

    your videos are great Sec. Thanks for the knowledge

  • @ivanildofreitas7907
    @ivanildofreitas7907 Рік тому

    Do a demo. We are eager to see that is possible. Nice and educational video by the way! Thanks.

  • @shriyanssudhi4545
    @shriyanssudhi4545 Рік тому +1

    I'd love to see a video on Authorization issues.
    Though I've found some, but I feel I am missing something.

  • @Ghalahad999
    @Ghalahad999 Рік тому

    Yeahh, please do demo vids on them. And practical low hanging fruits

  • @darklord5231
    @darklord5231 Рік тому

    Yes we would like to see videos on each vulnerability

  • @Aravindb26
    @Aravindb26 Рік тому

    Yeah practical explanation video needed naham ❤

  • @Death_User666
    @Death_User666 Рік тому

    Yes demos for all of them please please please
    I need to make extra money to afford my bills and I got 4 months left before I run out of money lol 😂
    I want to learn and I want to be good
    Another video idea could be reading bug bounty scope of work properly sometimes they are confusing to understand fully

  • @ГришаФомин-о5щ
    @ГришаФомин-о5щ 10 місяців тому

    чувак, спасибо тебе за этот ролик! он полезный , круто! продолжай в том же духе 🤘
    Хотелось бы подробнее с примерами о : SSRF, CSRF.

  • @Drakan1990
    @Drakan1990 Рік тому

    Want to see those demos! 🤘🏻

  • @deekshithkalakotla9024
    @deekshithkalakotla9024 9 місяців тому

    We want full video hands on each concept ❤

  • @AlexaSiri-u3z
    @AlexaSiri-u3z Рік тому

    Thank you for the video. My question is --
    How do we find XSS if X-XSS-Protection header is placed on every page of a webpage?

  • @SHADOW-uk2rq
    @SHADOW-uk2rq Рік тому +1

    Hands on videos yessssss

  • @panagiotismitkas5526
    @panagiotismitkas5526 Рік тому

    Yes we want to see the hands on lab videos. About xss do you recommend kxss to see what is reflected?

  • @prakhar0x01
    @prakhar0x01 Рік тому

    appreciate Ben, Really amazing content.., well we want more content like this, but missing streams and interviews.

  • @rahmat_qurishi
    @rahmat_qurishi Рік тому

    Love these videos❤

  • @feedomomics8103
    @feedomomics8103 Рік тому

    Hey great video, I have a question how to get pentests or rather how to get into pen-testing.

  • @BoitumeloKhushiSelelo
    @BoitumeloKhushiSelelo Рік тому

    it would be helpfull if you can share demo on how to find this vulnerabilities, thank you

  • @socalledhacker
    @socalledhacker Рік тому +1

    Now i am waiting for nxt Monday

  • @gem0x00
    @gem0x00 Рік тому

    You're the best bro my role model ❤

  • @oscarromero1007
    @oscarromero1007 Рік тому

    Thanks for the video!!

  • @hailelleultesera8643
    @hailelleultesera8643 Рік тому

    make a video on authorization issues I would definitely watch that

  • @ElliotRodger-cz7rb
    @ElliotRodger-cz7rb Рік тому

    Hey Ben great video, we understand you cannot show real-time bug hunting, can you show us finding real time VDP bugs. I think actually see you do it would me really motivating. Thanks a lot and keep it up!

    • @jannmoon
      @jannmoon Рік тому

      He can't, its mostly because if someone sees the vulnerability they can go and hack the company before they fix it not because someone might jack your report And take your cash before you can report it . Cool name by the way 👽👽👽

    • @NahamSec
      @NahamSec  Рік тому

      I have done this before :) Check out my Redbull video, REDACTED, and bug bounty stories!

  • @j4ck_d4niels
    @j4ck_d4niels Рік тому

    maybe web tech video will be awesome, some common places to look for, like in swagger ui have xss with low-medium impact

  • @trendyzawwad
    @trendyzawwad Рік тому

    it will be very much helpful to us, As a beginner we try to understand to of the vulnerability's and lost our most of the time's, If you do the hand's on video, may be it can push us to do more hand's on practice

  • @siddharthtayade3474
    @siddharthtayade3474 Рік тому

    Yes. Need demo for the vulnerabilities.

  • @discount_ChadKroeger
    @discount_ChadKroeger Рік тому

    I love anything cyber so im in. Especially on current bugs and news....Also duhhh show us the hands on.

  • @jaredlee8883
    @jaredlee8883 Рік тому

    Do a hands-on video of each please!

  • @shurikenhacks
    @shurikenhacks Рік тому +1

    Dude, clickbait us all you want. LOVE your videos! ❤‍🔥

  • @gem0x00
    @gem0x00 Рік тому

    Can you make videos for mastering a vulnerability or the most vulns needed alot of thinking to make the vuln have more impact

  • @Ucsd4life
    @Ucsd4life Рік тому

    Demo video please! This is awesome content!

  • @sandeeppn1876
    @sandeeppn1876 Рік тому +1

    Yes demo will be very helpful

  • @hxmo656
    @hxmo656 Рік тому +1

    For a new starter which bug bounty platform would you recommend; does it really matter whether we pick H1 / Bugcrowd VS a smaller place like Intigrity with less competition surely? 😊

  • @5checktech357
    @5checktech357 11 місяців тому

    Yes, please, the video will be awesome.

  • @tedwallace5640
    @tedwallace5640 Рік тому

    Love the vid. Yes, please do demos...

  • @josephvelasquez2677
    @josephvelasquez2677 Рік тому

    yes, please make demos on the mentioned vulns

  • @francisstocktilliii2413
    @francisstocktilliii2413 10 місяців тому

    Yes I would love to see a demo

  • @muhammaddanialhazimbinmohd5737

    Hands on video showing how to find these vulnerabilities plsss

  • @محمّد.09
    @محمّد.09 Рік тому +1

    We want demo for each of those five.

  • @PhantasmagoriaVisions
    @PhantasmagoriaVisions Рік тому

    Hands-on demo would definitely be a great

  • @lukeempty3386
    @lukeempty3386 Рік тому +1

    Do you think burpsuite pro is worth while if im just starting out. Almost done with the CBBH course from htb and then doing portswigger labs. I need burpsuite pro to do the portswigger certification though and not sure if its worthwhile if im just starting out

  • @husseindhooma5816
    @husseindhooma5816 Рік тому

    Hi Ben, awesome video once again, would love for you to post more content on IDORs and Authorization Issues. Just by the way you don't need to click bait me to get to watch your videos, the whole reason I subscribe to you is cos your content is excellent. I would watch it anyways and support you any day. Would some day love to make a $500 Bounty (IA) but it takes a lot of practice and I just need to get my butt away from streaming crap in the evenings and studying. Thank you once again. Keep up the great work. 😉

  • @zukxxxx0
    @zukxxxx0 Рік тому

    Actually, when played your videos liked them at the very beginning 😅😅😅

  • @HariHacks22
    @HariHacks22 Рік тому +1

    Theory + Demo 💯

  • @jamesdriscoll1658
    @jamesdriscoll1658 Рік тому

    Yes please do a demo video.

  • @naurismetlans8623
    @naurismetlans8623 Рік тому

    Very good video, would like to see demos.

  • @lakshaysiwach3652
    @lakshaysiwach3652 Рік тому

    yes absolutely a demo would be great

  • @adyp487
    @adyp487 Рік тому

    You're a good person Ben.
    Yes, please create a video on those 5 vulns, but maybe less focus on csrf? Random thought.

    • @NahamSec
      @NahamSec  Рік тому +1

      We'll see. I think there are a few good CSRF tricks I can show you guys though!

    • @a_al_Jahin
      @a_al_Jahin Рік тому

      Yeah please sir!! Wanna know csrf in deep @@NahamSec

    • @fabiothebest89lu
      @fabiothebest89lu Рік тому

      @@NahamSecI’d be interested in that

  • @heatherryan9820
    @heatherryan9820 Рік тому

    Great video. Appreciate the advice, and yes I'd like to see a hands-on. Any help I can get is always welcome.... Please?

  • @richowens5254
    @richowens5254 Рік тому

    i would love to see a hands on version. I've had hands on computers and networks since 1983, compulsively consume bug bounty education, have hunted multiple bounty programs and just can't even seem to even find dups....i can't, won't, and refuse to give up on this. i've always been the computer/network tech/ guy on the blue side and just can't help but to think i just can't seem to think nefariously enough to be the "red-teamer"... wtf (btw, you are my fucking hero yo!)

  • @CuriousByteYT
    @CuriousByteYT Рік тому

    Yes we do need a hands on explanation :)

  • @IrishOverkilled
    @IrishOverkilled Рік тому

    Would like to see a demo video and I like the content

  • @SohanRana-v6u
    @SohanRana-v6u Рік тому

    can you please make a video on authorization ?

  • @gads2143
    @gads2143 4 місяці тому

    awesom video bro

  • @aavezsheikh5781
    @aavezsheikh5781 Рік тому

    Yes demo of all the vulnerabilities plz

  • @TaminHay-hc7bq
    @TaminHay-hc7bq Рік тому

    What do you think about tool nuclei?

  • @syedamer130
    @syedamer130 Рік тому

    can't wait to see demo

  • @fahadfahad2000
    @fahadfahad2000 Рік тому

    Hello NahamSec, i would like to thank you for this video. Kindly please make video how to bid for the bounty on bugcrowed or intigriti platform from start to send report. Thanks