Subdomain Takeover Recon live Website || bug bounty || POC || Tools || 2022

Поділитися
Вставка
  • Опубліковано 9 лис 2024

КОМЕНТАРІ • 39

  • @OtakuQuizLab07
    @OtakuQuizLab07 9 місяців тому +1

    hello brother i brifly have knowledge about all this and want to learn from you personally can you teach me like with zoom or google meet or something like paid online course........

    • @THEBBH
      @THEBBH  9 місяців тому +2

      All the things are free buddy

  • @muhammadidrisalfadany6512
    @muhammadidrisalfadany6512 8 місяців тому +2

    what is your hackerone username, sir

  • @unknown_3293
    @unknown_3293 2 роки тому +4

    Are you selling practical course? bug bounty tricks and method?
    IDOR
    JWT
    CSRF
    etc
    Video like no intro or wasting time just explain smoothly easy to follow and understand?

    • @THEBBH
      @THEBBH  2 роки тому +7

      Nope I am not selling any course i will provided all the resources free of cost not charging the single amount of money. To any one else.

    • @unknown_3293
      @unknown_3293 2 роки тому

      thanks

  • @asunayuuki3748
    @asunayuuki3748 2 роки тому +1

    how do you know that website use shopify cname or another ?

    • @THEBBH
      @THEBBH  2 роки тому

      When I open a the domain. I confirmed that the cname is point out the shopify

  • @uniskhan3815
    @uniskhan3815 Рік тому +1

    Bro. how to take domain if i was find subdomain takeover vulnerabilty. means me kese ek domain le skta hu kisi bhi subdomain to redirect krne ke liy

    • @THEBBH
      @THEBBH  Рік тому +1

      Abhi shopify ke domain ko try krna.

    • @uniskhan3815
      @uniskhan3815 Рік тому

      @@THEBBH thanks bro

  • @ri0tsun
    @ri0tsun 2 роки тому +3

    For shopify, do we submit the report directly to shopify or to the web owner?

    • @THEBBH
      @THEBBH  2 роки тому +2

      Web owner boss because owner are using the services of the shopify.

  • @krrishogx
    @krrishogx 2 роки тому +1

    what if during bug poc the company ask who gave you permission to do bug hunting here
    so what should i answer them as am not having any certificate.
    please answer bhai

    • @THEBBH
      @THEBBH  2 роки тому

      Bhai tumhe yeh kisne bola ki mere pass persimmon nahi hai. Mai jab se video bana raha hun tab ye bola raaha hun ki using google dork for finding the companies. I didn't go the hackerone platform, i didn't use the bugcrowd for directly when I start aur rahi baat certification ki mai har chizz show nahi krta skta bhai. Lekin haan mere pass certification MCSA se lekr CCIE tak RHCE, Ec-Council tak sab hai Offensive ki taiyaari kar raha hun. Isliye tumko bhi yahi boluga ki jo kr rhe ho focus uspr kro until unless yeh jaane me focus dalo ki kiske pass kya hai. Kon kya kr rha hai.

    • @krrishogx
      @krrishogx 2 роки тому

      Wohi bro actually kl maine UA-cam pr ek video dekha tha jisme bola tha ki agr aapke pass koi certificate nhi h jaise merpr koi certificate nhi hai bug hunting ka so agr by chance aap google dork ke through hunting krrhe ho tb company aapse puchti h ki aapko permission kisne di .. so uss time mai kya bolu? Fir wo bola agr aapke pass koi certificate nhi hua tb aap pr case hoskta h . Is it real?

    • @THEBBH
      @THEBBH  2 роки тому +1

      Aisa kuch nahi hota hai. Bro jab tak aap bina misuse kisi chizz ka naa kro. Tab tak kuch nahi hota hai after all you are going to be secure them without any problems. But yes certification hona chahiyeh ek.

    • @krrishogx
      @krrishogx 2 роки тому +1

      So bhai certificate kha se lu can you please prefer any course for certification as am a newbie itni knowledge nhi h

    • @THEBBH
      @THEBBH  2 роки тому +1

      Cyber security ka le lo baki mujhe mail kro mai personally bana duga kaise krna start to end.

  • @itsm3dud39
    @itsm3dud39 2 роки тому +1

    what if the response was just - 404 Not Found nginx ??

    • @THEBBH
      @THEBBH  2 роки тому +2

      It's means you can't be able to take over. Check out the below link which domain you will be takeover.
      github.com/EdOverflow/can-i-take-over-xyz

    • @itsm3dud39
      @itsm3dud39 2 роки тому

      @@THEBBH thnx

  • @chetanmali5852
    @chetanmali5852 2 роки тому +1

    how you change namservers i dont undrrstand bro .! how it works ?

    • @THEBBH
      @THEBBH  2 роки тому

      I didn't change the name of the server i just check it. Please watch the video carefully bro.

    • @chetanmali5852
      @chetanmali5852 2 роки тому +1

      @@THEBBH can you try on hostinger domain hosting .

    • @THEBBH
      @THEBBH  2 роки тому

      You can check which subdomain you can take over bro.
      github.com/EdOverflow/can-i-take-over-xyz

  • @obscurehrs7762
    @obscurehrs7762 2 роки тому +4

    Brother I sent you a mail. 🙂

    • @THEBBH
      @THEBBH  2 роки тому

      Ok let i check and update you soon. Give me a time.

  • @trady_media7183
    @trady_media7183 2 роки тому +1

    wow

  • @geniusskills6151
    @geniusskills6151 2 роки тому +1

    brother can you make tutorial videos please

    • @THEBBH
      @THEBBH  2 роки тому

      About which topic same topic.

    • @geniusskills6151
      @geniusskills6151 2 роки тому

      @@THEBBH I watched most of your videos and they are about poc .. I want you to do some ways about how to find bugs and some of your methodology.pls

  • @muhammadidrisalfadany6512
    @muhammadidrisalfadany6512 8 місяців тому +1

    hello sir, I have just sent you a letter via your email

    • @THEBBH
      @THEBBH  8 місяців тому

      Let me check

  • @ٴٴٴٴۥۥٴٴٴٴۥۥٴٴٴٴۥۥٴٴٴٴۥۥٴٴٴٴٴٴ

    Are you on hackerone?

    • @THEBBH
      @THEBBH  2 роки тому +4

      I am using a Google dork for bounty and swags. Hackerone have a lot's of traffic. You can also use the dorks like. inurl: /responsible-disclosure/ bounty.