BUG BOUNTY TOOLS: Creating Python Tool to find Sensitive Information | 2023

Поділитися
Вставка
  • Опубліковано 11 вер 2024
  • Note: This video is only for educational purpose.
    Intigriti: go.intigriti.c...
    Hi everyone! In this video, you will learn how to create your own custom python tool to find sensitive javascript information on bunch of endpoints.
    Website: bepractical.tech
    Telegram: telegram.me/be...
    Previous Video: • BUG BOUNTY: EXPLOITING...
    The Art Of Web Reconnaissance:
    www.udemy.com/...
    Coupon: OEI1ODk0QkZBNUJCNUNEMDBDMUY= (Decode it to get max discount!)
    Hacking Windows with Python from Scratch: www.udemy.com/...
    The Ultimate Guide to Hunt Account Takeover:
    www.udemy.com/...

КОМЕНТАРІ • 19

  • @BePracticalTech
    @BePracticalTech  9 місяців тому +1

    Course Coupon: OEI1ODk0QkZBNUJCNUNEMDBDMUY= (Decode and use it to get 90% off on our latest course)
    Course Link: www.udemy.com/course/the-art-of-web-reconnaissance-bug-bounty-ethical-hacking/?referralCode=25FFF9BA65C3368C2C2C
    Intigriti: go.intigriti.com/bepractical

  • @Yash.Lonewolf
    @Yash.Lonewolf 9 місяців тому +2

    sir more video like this

  • @i_am_dumb1070
    @i_am_dumb1070 9 місяців тому

    Great content! 🙏 Your amazing videos have taught me so much. Keep 'em coming, can't wait for more awesome content from you! 👍

  • @mounifishing121
    @mounifishing121 9 місяців тому

    very nice video, faiyaz bhai ❤❤

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked 9 місяців тому

    I'm here from the Telegram post, bro bro.

  • @SOBHITSHARMA
    @SOBHITSHARMA 9 місяців тому +1

    Again a great video. I created my account. I have few question and would love to hear your prospective.
    I recently started recon and found sensitve data on two programs. But it has either only apikey or account_sid or secret key but not both. Does this still count as vulnerability ?
    Also is it worth buying license for burp suite pro?
    Can you create a video e.g js query version is vulnerable and application still using it now burp suite report this but I dont know how to exploit. This would really help. I recently took trial version for pro and I can see Client-side desync issue, js query, http smuggling
    Input returned in response (reflected) vulnerability issue, tls issue but dont know how to exploit and earn the bounty.
    Please shed your light of knowledge for new bee like me.

    • @BePracticalTech
      @BePracticalTech  9 місяців тому +1

      Thanks for the question! I'll be answering them on my telegram channel soon

    • @SOBHITSHARMA
      @SOBHITSHARMA 9 місяців тому +1

      @@BePracticalTech whats your telegram channel? or can you also tweet about it ?

    • @SOBHITSHARMA
      @SOBHITSHARMA 9 місяців тому +1

      @@BePracticalTechBtw as I have reported only apikey and secret key programs says its deliberately saved on the application and cannot be consider as threat. I dont know what to do next as my bug status becomes more info required.

  • @user-eq1er5lh3d
    @user-eq1er5lh3d 9 місяців тому

    Awsome script!!!

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked 9 місяців тому

    Early crew. First.

  • @abhik_makwana
    @abhik_makwana 9 місяців тому

    @BePractical heyy bro, I'm getting some error so how could I ping you prsnly.

    • @BePracticalTech
      @BePracticalTech  9 місяців тому

      Send a mail at faiyazahmad.online@gmail.com

    • @abhik_makwana
      @abhik_makwana 9 місяців тому

      @@BePracticalTech Okay Brothermen ✨💜

  • @SFZACK_GAMING
    @SFZACK_GAMING 9 місяців тому

    Can I get your LinkedIn profile link??

    • @BePracticalTech
      @BePracticalTech  9 місяців тому

      www.linkedin.com/in/faiyaz-ahmad-64457520b

  • @ramanandsoibam5598
    @ramanandsoibam5598 9 місяців тому

    Sir, can I get your personal Email ID