Це відео не доступне.
Перепрошуємо.

2023 WebApp Pentesting/Hacking Roadmap // How To Bug Bounty

Поділитися
Вставка
  • Опубліковано 14 сер 2024
  • Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training
    Does Cybersecurity Require Programming?
    • Does Cybersecurity Req...
    Buy Me Coffee:
    www.buymeacoff...
    Live Every Sunday on Twitch:
    / nahamsec
    Free $100 DigitalOcean Credit:
    m.do.co/c/3236...
    Follow me on social media:
    / nahamsec
    / nahamsec
    twitch.com/nah...
    hackerone.com/...
    / nahamsec1
    Github:
    github.com/nah...
    Nahamsec's Discord:
    discordapp.com...
    Timestamps:
    00:00 - Intro
    00:45 - How the website works
    01:56 - Curl / Linux basics
    03:10 - Scripting
    04:34 - Basics of Web application Hacking, Don't depend on Automation
    07:49 - Learn JavaScript
    #webhacking #redteam #bugbounty #offensivesecurity #hackerone #hackers #hacking #infosec #hackingtutorial #owasp #educational

КОМЕНТАРІ • 142

  • @rdx8122
    @rdx8122 Рік тому +40

    00:00 = Intro
    00:45 = How the website works
    01:56 = Curl / Linux basics
    03:10 = Scripting
    04:34 = Basics of Web application Hacking, Don't depend on Automation
    07:49 = Learn JavaScript
    For me personally this was not a roadmap, it was more like tips and tricks to upgrade my existing roadmap 😂😂, anyways, thank you very much Naham sir, following you further to learn a lot of stuff 🙏🙏💖💖 Love from India 🇮🇳 🇮🇳 🇮🇳

    • @oviyanthelearner7656
      @oviyanthelearner7656 Рік тому +2

      Bro can you tell about where to practice web hacking

    • @nishantdalvi9470
      @nishantdalvi9470 Рік тому

      @@oviyanthelearner7656 port swigger academy

    • @NahamSec
      @NahamSec  Рік тому +4

      Added to the video. You the best!

    • @rdx8122
      @rdx8122 Рік тому +1

      @@oviyanthelearner7656 there are a lot them out there, explore them online, like tryhackme, hackthebox, especially portswigger and lot more !

    • @rdx8122
      @rdx8122 Рік тому +1

      @@NahamSec thank you sir 🙏🙏❤️❤️

  • @chaospixxie
    @chaospixxie Рік тому +13

    I've just started learning curl. Still trying to wrap my head around it. Baby steps 😊

    • @NahamSec
      @NahamSec  Рік тому +9

      You got this! curl is going to be very helpful especially when looking at APIs!

    • @firzainsanudzaky3763
      @firzainsanudzaky3763 6 місяців тому

      how's the learning my man?

  • @superkool7
    @superkool7 11 місяців тому +2

    Fuck. I just realized something while watching this. I’ve been into this for 2.5 years. Maybe 3. And I’m still finding myself watching these roadmap - how to become a bug bounty Hunter - videos. Damn. What can I do. Seriously.

    • @akhtarmohana2999
      @akhtarmohana2999 10 місяців тому +1

      Disconnect for a while. Do something else. Then come back with a fresh mind

  • @romeoromeo7002
    @romeoromeo7002 Рік тому +1

    Hi Ben,
    I am your huge fan i love your work immensely and your vlogs about live hacking events are as good as your other UA-cam content .
    My question is that I’m currently in Canada and my studies will be over in next month like in Aug 2023 but I am lost in my path I don’t know what to do I am unable to find an internship or job so I needed your guidance and i also want to mention that I have successfully done your udemy course and i am currently preparing for PNPT by TCM security so If i could connect with you and talk about job search and other things then it would be really awesome.

  • @shaifsec
    @shaifsec Рік тому +4

    You are legend sir , Always Appreciated.

  • @axelieve
    @axelieve Рік тому +3

    How important do you think learning Python to an intermediate level is for a bug hunter?
    Awesome video!

  • @glostar_Rx
    @glostar_Rx Рік тому +5

    How to find bugs from view-source? I want a video of this 😊

    • @rdx8122
      @rdx8122 Рік тому +2

      You mean finding bugs in JavaScript ? that's a great topic a video @NahamSec

  • @rahmat_qurishi
    @rahmat_qurishi Рік тому +3

    Great as always🎉

    • @NahamSec
      @NahamSec  Рік тому +1

      Thank you so much 😀

  • @Eric-ey7rm
    @Eric-ey7rm Рік тому +3

    Just found your channel. You seem like a kool dude. Buying your BB Course for my barely 12 year old who lives on hack the box and is always on port swigger site. Hes actually trying to get me into it, but i think i like more actual network pentesting then web apps. That looks way too difficult for me.

    • @NahamSec
      @NahamSec  Рік тому +6

      Hey Eric. Thanks for the comment and thanks for supporting the course! That’s awesome that your son! If I can help him in anyway please let me know. Happy to even chat with the both of you on a zoom call if it helps motivate you guys to get into hacking. Feel free to email me! My emails on the about page of the channel.
      Go after whatever you’re passionate about. Whether it’s network, web, social engineering regardless of the difficulty. IMO that’ll drive you overcome the hurdles more than anything else.
      Best of luck!

  • @bolivianPsyOp
    @bolivianPsyOp Рік тому

    came here from the live stream. and dropped a sub

  • @arijitdas9115
    @arijitdas9115 Рік тому

    Great video as always mentor !

  • @nextbillionaire2513
    @nextbillionaire2513 Рік тому +6

    Actually I needed it.
    Thank you so much for making this video... ♥✌

  • @Meenimie
    @Meenimie Рік тому +1

    I suggest you use more visualization in your video, such as the terms, definitions.

  • @denizyildirim116
    @denizyildirim116 Рік тому +1

    Hey man, thanks for your content.
    Since you mentioned SSRF being network related, I come from a networking and netsec background with 10+ years experience. What hacking track do you recommend me to go where I can take of use my knowledge in networking?

  • @RivuDonTech
    @RivuDonTech Рік тому +2

    Thanks for video ! Keep making more.

  • @joeshmo546
    @joeshmo546 7 місяців тому

    So how in depth should you know about how websites work? Also do you have any prefered resources for learning these skills?

  • @shaifsec
    @shaifsec Рік тому +1

    need resource to know more about DNS Configuration | DNS Records

  • @mohammadalihanfi8237
    @mohammadalihanfi8237 Рік тому +1

    And ctf to start with after learning these basics

  • @krishshah344
    @krishshah344 Рік тому +1

    Any sources to learn this stuff from? Curl, JS for hacking, basics etc...

  • @bugs-lk3jf
    @bugs-lk3jf Рік тому

    like a Boss; Great Content Nahamsec ...

  • @kenkaneshki432
    @kenkaneshki432 Рік тому

    For the first step Learning how the websites and internet works, what book should I choose to learn that how internet and websites works or do you have any resources plz tell me

  • @rahulacharya8159
    @rahulacharya8159 Рік тому +2

    Again I am first viewer 🥳

  • @mereemail8352
    @mereemail8352 Рік тому +1

    Can u please make a video on hoelw to effectively map the web app and discover hidden functionalities

  • @mohammadalihanfi8237
    @mohammadalihanfi8237 Рік тому +1

    After this what are books you recommend to read

  • @PS_Fantasy
    @PS_Fantasy Рік тому +1

    Knowledgeable Content

  • @g1zmo85
    @g1zmo85 Рік тому +1

    Thank you for this video, very good info

  • @night0x1
    @night0x1 Рік тому

    Thanks! For the ADVICE!

  • @krishg767
    @krishg767 Рік тому +1

    Please 🙏 keep it up more and more videos....

  • @m3nt0rz.haxx0r2
    @m3nt0rz.haxx0r2 Рік тому

    Came here from your live

  • @nadakuditigopikrishna6587
    @nadakuditigopikrishna6587 Рік тому

    Thanks for the guidance!!

  • @amoh96
    @amoh96 Рік тому

    as beginner it's really hard to me the part of recon ( DNS , ASN,DNS Records, Revers Ip,,,,,) This stuff about Network i only do basic recon gather subdomains & some google dorks :( is that ok for beginner im in 6 month in bug bounty ??

  • @lzxser6470
    @lzxser6470 Рік тому

    thanks, greetings from turkey

  • @mikiminac251
    @mikiminac251 Рік тому +1

    i reported the vulnerabilities but they are all invalid

  • @1DRS
    @1DRS Рік тому

    Thanks for video .liked it

  • @terrymac-tay5597
    @terrymac-tay5597 Рік тому +1

    Thanks for the video. I purchase your course on udemy and I'm loving it. I have one request to ask, could you connect me to someone I can pair with and we can learn together? Thanks again

    • @NahamSec
      @NahamSec  Рік тому +1

      Come join the discord!

  • @MFoster392
    @MFoster392 Рік тому +1

    Thanks man ;-)

  • @amoh96
    @amoh96 Рік тому +1

    Thanks keep making more videos for beginners :)

  • @DheerajMadhukar
    @DheerajMadhukar Рік тому

    Its a nice watch .... Which watch it is ? :)

  • @user-vf8nm7xy1e
    @user-vf8nm7xy1e Рік тому

    Hi, I came from your stream

  • @Andrei-ds8qv
    @Andrei-ds8qv Рік тому

    Hey hey, nice video, thanks!

  • @zerocool2765
    @zerocool2765 Рік тому +1

    Why is everyone focusing on web bug bounty? Why not mobile and other platforms?

  • @youssef-kz3yn
    @youssef-kz3yn Рік тому

    Do i need to study the a plus content or something like that to get into bug hunting

  • @mametube6654
    @mametube6654 Рік тому

    Love from Ethiopia❤

  • @uniskhan3815
    @uniskhan3815 Рік тому +1

    Very knowledgeable video ❤

  • @TonyAsh-rp6fp
    @TonyAsh-rp6fp Рік тому +1

    good content.

  • @bugs-lk3jf
    @bugs-lk3jf Рік тому

    thank you so much 😎

  • @denildavis3561
    @denildavis3561 Рік тому

    nahamsec . I am working as security in UAE. but I am from India. I fed up with my job because it is very boring. now I started learning about cybersecurity. can I change my job to bug bounty. I want a job that i can work from home. security job is not very interesting . cybersecurity seems to me very interesting

  • @syedrafi3704
    @syedrafi3704 Рік тому +3

    Hi i am from india. I want a great high paying career. On which skills i need to focus and get remote job while i stay in india. I am from non IT back ground. Thank you.

  • @HalfDeaff
    @HalfDeaff Рік тому

    came from the livestream

  • @markfuentes3666
    @markfuentes3666 Рік тому

    Great Video. I am looking for a good video on curl.

  • @vedant.p.baghel8944
    @vedant.p.baghel8944 Рік тому

    what are the different fields in ethical hacking

  • @MP-eq8fx
    @MP-eq8fx Рік тому +1

    Please give the link to the video you said at the beginning.

    • @NahamSec
      @NahamSec  Рік тому +2

      In the description but here you go Does Cybersecurity Require Programming?
      ua-cam.com/video/WQaiClLdvSI/v-deo.html

    • @MP-eq8fx
      @MP-eq8fx Рік тому

      @@NahamSec Thank you very much 💗

  • @stabilizer7225
    @stabilizer7225 Рік тому +1

    awli bood❤❤

  • @moh5entuky940
    @moh5entuky940 Рік тому

    For scripting we should learn Python or Go?Which better? and how learn Scripting? Thank You for your helps@NahamSec

  • @0XmsAhmed
    @0XmsAhmed Рік тому +12

    I want to know API hacking tips and tricks from you. 🙏🙏🙏🙏🙏

    • @NahamSec
      @NahamSec  Рік тому +11

      Soon!

    • @Adarsh.-.
      @Adarsh.-. Рік тому +1

      @@NahamSec waiting dude

    • @lukeempty3386
      @lukeempty3386 Рік тому

      ​@@Adarsh.-.check out apisec University

    • @tecksec
      @tecksec Рік тому

      Need the API hacking too 🎉

    • @lukeempty3386
      @lukeempty3386 Рік тому +2

      @@tecksec TCM security just released an API course

  • @codesaif8075
    @codesaif8075 Рік тому

    How much demand of Ethical Hackers is ?

  • @GoliTech
    @GoliTech Рік тому

    ur the best dude

  • @vineet1
    @vineet1 Рік тому

    Came here from LIVE

  • @unexplicitist-oy3eh
    @unexplicitist-oy3eh 9 місяців тому

    Came here from the future

  • @nareshrapthadu8262
    @nareshrapthadu8262 Рік тому +1

    Can you please make a video on writing PoC of Bugs

  • @shubham_srt
    @shubham_srt Рік тому +2

    1st 🥵

  • @alagunoff
    @alagunoff Рік тому

    Thanks

  • @Zillah_D
    @Zillah_D 10 місяців тому

    tnx but better if it was tear by tear and more step

  • @mehdi_sf7257
    @mehdi_sf7257 Рік тому

    best content

  • @iramdolal488
    @iramdolal488 Рік тому

    from the stream

  • @moh5entuky940
    @moh5entuky940 Рік тому

    For scripting we should learn Python or Go?Which better? and how learn Scripting?

    • @a.g.4843
      @a.g.4843 7 місяців тому

      With Udemy…

    • @moh5entuky940
      @moh5entuky940 7 місяців тому

      Witch course?
      @@a.g.4843

  • @voyageur1016
    @voyageur1016 Рік тому +1

    احبك في الله 😅

  • @cynerboy
    @cynerboy Рік тому +1

    Will penetration tester jobs be replaced by artificial intelligence?

    • @HelloThere-xs8ss
      @HelloThere-xs8ss Рік тому +1

      Machine learning tools are already being used in security operation centers.

  • @satisfiedvideos1
    @satisfiedvideos1 Рік тому

    Hello sir 👋 can you please make a Facebook cloning script for me ❤

  • @harshsharma7505
    @harshsharma7505 Рік тому +1

    still bug bounty is not a robust career!!! spending time on vuln machines and web apps is more important to know more about bugs. Bug hunting should be a part time and a just for fun game. No offense , but it is a matter of duplicates and reality.

  • @amoh96
    @amoh96 Рік тому

    finelly :D

  • @securibee6016
    @securibee6016 Рік тому

    🐝

  • @mereemail8352
    @mereemail8352 Рік тому

    ❤️

  • @ByteHax_
    @ByteHax_ Рік тому

    Api hacking roadmap guru ji

  • @Sharif365
    @Sharif365 Рік тому +1

    Where are the basics of networking ? 🙂

  • @ralphandre4438
    @ralphandre4438 Рік тому

    Finally 😂😂

  • @vedaty.8259
    @vedaty.8259 Рік тому

    Bir de Müslüman olsan süper olurdu naham dayı

  • @uaebikers
    @uaebikers Рік тому

    Definitely not a roadmap lol but thanks for the tips.

    • @NahamSec
      @NahamSec  Рік тому +2

      Thanks! What should I do different next time so it's an actual roadmap? Should I specify where to learn them and what courses/sites to use?

    • @cguzmanvisuals
      @cguzmanvisuals Рік тому +1

      Lmfao this guy wants latitude and longitude 🗺️🗾📍😂😂😂

    • @uaebikers
      @uaebikers Рік тому

      @@NahamSec I recommend making a roadmap for a period of time like 6 months with detailed plan, goals and milestones.
      Maybe even make a playlist discussion each step of the roadmap.

    • @black53342
      @black53342 Рік тому +1

      Buddy wants spoon feeding.....

    • @uaebikers
      @uaebikers Рік тому

      @@black53342 I want things to be called as they are without click baiting! Go simp somewhere else!

  • @user-oc6ge1lj9n
    @user-oc6ge1lj9n 8 місяців тому

    ایرانی هستی

  • @WasiLi0x1e
    @WasiLi0x1e Рік тому

    thx for video

  • @brs2379
    @brs2379 Рік тому +1

    Regexes

  • @behrozarshiya
    @behrozarshiya 10 місяців тому

    i think review owasp better thing for start learn hunting