Easy IDOR hunting with Autorize? (GIVEAWAY)

แชร์
ฝัง
  • เผยแพร่เมื่อ 3 ส.ค. 2024
  • I've said it once and I'll say it again APIs are some of the best applications to hunt on, and now I've worked at a platform I have some data to back me up that IDORs are fantastic first bugs and they are EVERYWHERE! But, when we test a real API vs a lab or CTF there are so many endpoints and resources and stuff to test, so what if we could make IDOR hunting easier? What if we could automate it? Well this is what Autorize is designed to do! This free Burp extension allows us to automatically make a second request to test if our attacker account can do something to affect our victim. It's such a useful tool to have installed I 100% recommend it especially if you're a beginner.
    Did you know this episode was sponsored by Intigriti? Sign up with my link go.intigriti.com/katie I'm so pleased with everyone's positive response to the Intigriti sponsorship and I'm so pleased you folks are finding bugs and even finding your first bugs! Thank you for being awesome!
    This month as a thank you for bearing with me as I get back into video making we're doing a giveaway! To win one of the following prizes please enter via a comment on this video with an answer to: What bug or type of hacking do you want to know more about? And the text: #bountypls
    1x Lifetime Membership to www.bugbountyhunter.com/
    5x 1 month memberships PentesterLab Pro
    5x 2 months Try Hack Me Premium
    10x InsiderPhD Swag Pack

ความคิดเห็น • 260

  • @dhruvkandpal9909
    @dhruvkandpal9909 2 ปีที่แล้ว +6

    Great video, Katie! Loved it as always.
    My favourite bug bounty tools are burp suite, all tomnomnom's tools, amass and the ones I developed on my own! (LazyFuzzZ, Wordlist Weaver, Fu-JS) #bbhammer

  • @Vinayak123-q8p
    @Vinayak123-q8p 2 ปีที่แล้ว

    amazing, this could be probably one of the biggest information that i have ever been given

  • @wingwing2683
    @wingwing2683 2 ปีที่แล้ว +1

    Thanks so much sharing!

  • @svrajput14
    @svrajput14 ปีที่แล้ว

    Really nice tip on how to use tool effectively !!

  • @iamkaustubh
    @iamkaustubh 2 ปีที่แล้ว

    Wowww Thanks katie 🔥🔥🔥🔥it really encourages people more thanks for video

  • @prashant.singh08
    @prashant.singh08 2 ปีที่แล้ว +5

    Thanks for doing so much for the community ❤️
    It'll be great to have more videos about DOM based vulnerabilities #bountypls

  • @gf32768
    @gf32768 2 ปีที่แล้ว +3

    Awesome video, as always!
    Favourite tool - Burp Suite - even if the only features it had were the proxy history and Repeater, it'd still be amazing.
    ##bbhammer

  • @arrheniusangipaelongan8693
    @arrheniusangipaelongan8693 2 ปีที่แล้ว +5

    Thanks for all your videos Katie!❤ I got my first bug from your IDOR video. My favorite tool is burp! #bbhammer

  • @champagnepete3386
    @champagnepete3386 2 ปีที่แล้ว

    Great video, good resource!!

  • @Death_User666
    @Death_User666 8 หลายเดือนก่อน

    You are my favorite bug bounty channel

  • @chitraa87
    @chitraa87 2 ปีที่แล้ว +1

    Thanks for doing amazing video katie. My fav bug bounty tool is burp ofcourse. I'm looking forward more automation videos like this..#bbhammer

  • @link-ed
    @link-ed 2 ปีที่แล้ว +2

    Thanks for the video! The tool that I use the most is fuff, cause of it's speed and simplicity. Burp is another indispensable tool as well! #bbhammer

  • @asantoshkumarachary2692
    @asantoshkumarachary2692 ปีที่แล้ว

    Thanks for this video Katie

  • @saite2560
    @saite2560 ปีที่แล้ว

    nice video i've watched quite a few of em. clear well rehearsed script.. this video actually tries to show us something. well rounded video.
    i wish more of your videos showed us how to actually do this stuff like this video. you do great on the speaking side of teaching tho, need more hands on tho.

  • @amandabarbosasobrinho5878
    @amandabarbosasobrinho5878 2 ปีที่แล้ว +1

    Hey Katie, as always, awesome video! My favorite bug bounty tool is Burp, for sure! #bbhammer

  • @singularityfinale7680
    @singularityfinale7680 2 ปีที่แล้ว +3

    You videos are both no bs info and free which is great for broke student like me. Well my favorite tool is Burpsuite #bbhammer
    And I think I will give Autorize a try.

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 ปีที่แล้ว

    Thank you for the video

  • @syedbukhari4761
    @syedbukhari4761 2 ปีที่แล้ว +2

    Great video Katie, my favourite tool is Amass & Wireshark; would love to see more videos on Business logic flaws & XXE flaws.
    #bountypls

  • @brucezhang4967
    @brucezhang4967 2 ปีที่แล้ว +3

    Thanks Kate! I want to know more about SSRF and businesss logic.#bountypls And my favourite bug bounty tool is absolutely BurpSuite!!! #bbhammer

  • @vanquisherstraveltube
    @vanquisherstraveltube 2 ปีที่แล้ว +2

    You are really a great teacher.
    I am following your videos and learning a lot. Thank you so much!
    *Burp* is my favorite tool
    #bbhammer

  • @rami1785
    @rami1785 2 ปีที่แล้ว +1

    Thanks for all your videos Katie , My favorite tool is burp #bbhammer .

  • @jovensqueprosperam
    @jovensqueprosperam 2 ปีที่แล้ว

    Thanks for this channel

  • @sangeethaa5101
    @sangeethaa5101 2 ปีที่แล้ว +2

    I want more videos explaining bugs with dem websites not just presentations. Thank You, Katie. #bountypls #bbhammer

  • @italoamaya8230
    @italoamaya8230 2 ปีที่แล้ว

    thank you so much

  • @DieTeewurst
    @DieTeewurst 2 ปีที่แล้ว +1

    Thank you for your great Videos! My favorite Bug bount tool is burp for sure! So much functionality in one tool! #bbhammer

  • @0xff1337
    @0xff1337 2 ปีที่แล้ว

    why you're so late katie. i was waiting for this video for so long

  • @amitabhgupta21
    @amitabhgupta21 2 ปีที่แล้ว +3

    Started following you Katie and I am blown by the content u and
    other fellow u tubers are providing by the way my favourite BB tools are - Burp Pro,Rustscan,amass and nuclei
    #Bbhammer

  • @p.k5016
    @p.k5016 2 ปีที่แล้ว +1

    Thank you Katie for this amazing video. My favourite bug bounty tool is Burpsuite. #bbhammer

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 ปีที่แล้ว +1

    Started learning following your recon videos. My go to tool for now is Burpsuite community edition. #bbhammer

  • @ainter216
    @ainter216 2 ปีที่แล้ว

    Thank you very much for the video! My favourite toos is Burp Suite, it is so powerful and you can do so many things. #bbhammer

  • @vikasrushi3714
    @vikasrushi3714 2 ปีที่แล้ว +1

    Thanks :) my favourite bug bounty tool are Amass and FFUF #bbhammer

  • @AnNafiMedia
    @AnNafiMedia 6 หลายเดือนก่อน

    great video

  • @webapplicationsecurity1853
    @webapplicationsecurity1853 2 ปีที่แล้ว +1

    Thanks for the video, have been using this tool for a while now. This is my favourite tool: Autorize allows to check most of the access Logic tests. #bbhammer

  • @sekmekci
    @sekmekci ปีที่แล้ว

    Thanks for the video. Information part is starting at 3:49

  • @sadabesher2886
    @sadabesher2886 2 ปีที่แล้ว

    Burp and ffuf is my favorite tool

  • @meletismichael2495
    @meletismichael2495 2 ปีที่แล้ว +1

    You are precious for the community! pls go more in depth on chaining vulnerabilities! #bountypls

  • @stablewater
    @stablewater ปีที่แล้ว +1

    Thanks for this great knowledge. I am currently learning IDOR and I've been able to use autorize and I got "enforced" in some areas. What next am I to do next. How do I exploit this for bug bounty?

  • @ronny_xavier
    @ronny_xavier 2 ปีที่แล้ว

    Thanks as always Katie. My fav tool is Burp definitely. #bbhammer

  • @deepeshrane8412
    @deepeshrane8412 2 ปีที่แล้ว

    Awesome video, I love to use Amass and burp suite!! #bbhammer

  • @sudokom
    @sudokom 2 ปีที่แล้ว +1

    My favourite bugbounty tools are FFuF, Dirsearch, and Burpsuite with this extentions such as autorize #bbhammer

    • @sudokom
      @sudokom 2 ปีที่แล้ว

      ... And also obsidian #bbhammer

  • @ndmath
    @ndmath 2 ปีที่แล้ว +1

    Thank you Katie. I'd love to know more about Burp. #bountypls

  • @mohammedsaneem4179
    @mohammedsaneem4179 2 ปีที่แล้ว +2

    Great video as always. Would love to see videos based on chaining of bugs #bountypls

  • @RahulKumar-vy4lu
    @RahulKumar-vy4lu 2 ปีที่แล้ว +2

    Great video as always. I would love to have more videos about XSS & chaining of bugs. #bountypls

  • @VincentOldMark
    @VincentOldMark 2 ปีที่แล้ว +1

    My favourite tool is of course burp suite #bbhammer You are great Katie!

  • @jarvis9092
    @jarvis9092 2 ปีที่แล้ว +2

    Please never stop creating content like these😍..It would be helpfull if you would increase your volume as i felt the audio is lower than other youtube videos..My favourite tool is BurpSuite #bbhammer

  • @TechRideGamer
    @TechRideGamer 2 ปีที่แล้ว

    Thanks for this one its more than awesome.
    By favourite tool is Amass, fuff and in extensions autorepeater & Param Miner this are lit. #bbhammer

  • @SergeantDaynes
    @SergeantDaynes 2 ปีที่แล้ว +3

    Awesome video as usual. As for the types of bugs/hacking I want to learn about…SSRFs, broken access controls, business logic, and APIs! #bountypls

  • @ambsambs2973
    @ambsambs2973 2 ปีที่แล้ว +2

    It'll be good if we get videos on web cache related vulnerabilities also once again thanks for making good contents for the community! #bountypls

  • @subhadipnag6028
    @subhadipnag6028 2 ปีที่แล้ว

    Your video is really awesome :)
    Always love for Burp Suite tool for damn sure !! #bbhammer

  • @DevilAlpacca
    @DevilAlpacca 2 ปีที่แล้ว

    Awesome, will definitely use the burp addon. Fav tool #bbhammer #bountypls

  • @gauravdeore9477
    @gauravdeore9477 2 ปีที่แล้ว +1

    #bbhammer
    According to me burpsuite repeater is the best tool for hacking. We can perform any attack with it.

  • @Silly_lilly926
    @Silly_lilly926 2 ปีที่แล้ว +1

    Thanks Kate ❤️ for this giveaway I'm so inspired by you and Aditi Singh and my favourite tool is FFUF love data exposed ❤️ #bbhammer

  • @ksr608
    @ksr608 2 ปีที่แล้ว +1

    Thank you for all your videos! My favourite tool is amass and burpsuite. #bbhammer. It'll be good to see more videos on subdomain takeover with an example. #bountypls

  • @tomj1883
    @tomj1883 2 ปีที่แล้ว

    Thanks for the videos!!! My favorite tool is burp for sure #bbhammer

  • @sien1337
    @sien1337 2 ปีที่แล้ว

    my favorite bb tool is Burp, you can just do so much with it! #bbhammer

  • @p3g4sus
    @p3g4sus 2 ปีที่แล้ว +2

    I would love to see more videos on recon methadology for beginners . #bountypls

  • @don-ce8ig
    @don-ce8ig 2 ปีที่แล้ว

    Thanks for making content! My favourite bug bounty tool is burpsuite #bbhammer

  • @eraedith696
    @eraedith696 2 ปีที่แล้ว

    Fav tool is Burpsuite because it has some automation and also manual testing which is good and it's also beginner friendly tool and many more to learn.... Thank you❤
    #bbhammer

  • @kbsavage77
    @kbsavage77 2 ปีที่แล้ว

    Welcome back! I'd love to learn more about SSRF #bountypls

  • @papajohn2821
    @papajohn2821 2 ปีที่แล้ว +2

    Mobile application security is what I am practicing for a month now. And videos on that topic will be great to learn from. #bountypls

  • @mayank-ir7tm
    @mayank-ir7tm 2 ปีที่แล้ว +1

    My favourite bug bounty tool is ffuf combined with burp. I can bypass the speed limit of Intruder during fuzzing using -replay-proxy in ffuf which gives me the benifit of higher fuzzing speeds of ffuf and all the packets are captured in burp proxy too due to -replay-proxy flag set in ffuf.
    #bbhammer

  • @user-qe5ru6mv3l
    @user-qe5ru6mv3l 11 หลายเดือนก่อน

    Burpsuite is my fav

  • @user-ov2ll4vc7j
    @user-ov2ll4vc7j 2 ปีที่แล้ว

    Katie thanks for the video. I would like to learn more about hacking APIs. #bbhammer

  • @morphsec
    @morphsec 2 ปีที่แล้ว +1

    Subdomain takeovers would be nice, saw a lot of good reports but never seemed to fully understand them. #bountypls
    Burp and Amass is the bread and butter for me. #bbhammer

  • @gk_eth
    @gk_eth 2 ปีที่แล้ว

    Mostly there r auth bearer token for APIs which also needs to be add in cookies section?

  • @kovanbakr
    @kovanbakr 2 ปีที่แล้ว

    thankyou,
    My favourite bug bounty tool is Burpsuite. #bbhammer

  • @shameeluddin3563
    @shameeluddin3563 2 ปีที่แล้ว

    Just found your channel searching for cybersec stuff.
    My favorite tool so far is burp.
    #bbhammer

  • @IrfanAli-vp5mh
    @IrfanAli-vp5mh 2 ปีที่แล้ว

    Next video idea suggestion: Burp autorepeater

  • @tajsec498
    @tajsec498 2 ปีที่แล้ว

    my favorite tool is burp suite, nmap :)) thanks for great contents
    #bbhammer

  • @andymarty80
    @andymarty80 2 ปีที่แล้ว

    I'd like to see videos on Anti-CSRF bypass, 2FA/MFA bypass or prediction.

  • @tXambe
    @tXambe 2 ปีที่แล้ว

    Thanks very much for your videos and my favourite tool is burpsuite #bbhammer

  • @maapi
    @maapi หลายเดือนก่อน

    I'm having an issue with autorize picking up requests that should be out of scope. Anyone else have this issue? This leads to a lot of extra requests to parse through, which really slows me down

  • @kavishshah1988
    @kavishshah1988 2 ปีที่แล้ว

    Have only used Burp suite till now so I guess that's my favourite tool as of yet #bbhammer

  • @darshannn10
    @darshannn10 2 ปีที่แล้ว

    Fav bug bounty tools - Burp, amass, nuclei, ffuf #bbhammer

  • @sudarshsaraswathula1401
    @sudarshsaraswathula1401 2 ปีที่แล้ว

    Thanks a lot for the vid. My favourite tool is ffuf #bbhammer

  • @faique2995
    @faique2995 2 ปีที่แล้ว +3

    Thank you for holding my hands and taking me to this level in cyber security, Be healthy and happy😁
    #bountypls

  • @tharunbaalaji8306
    @tharunbaalaji8306 2 ปีที่แล้ว +1

    I like to see more vedios on business logic bugs , like taking a public program and understanding the business logic of the functionalities.#bbhammer #bountypls

  • @adamkimbro
    @adamkimbro 2 ปีที่แล้ว

    #bbhammer My favorite tool burp. Thanks for your videos!!!

  • @gonzalogermano2312
    @gonzalogermano2312 2 ปีที่แล้ว

    Thanks Katie my favorite tools is burpsuite #bbhammer

  • @fatihburaktoprak769
    @fatihburaktoprak769 ปีที่แล้ว

    My favorite is always Burp Suite! #bbhammer

  • @pr0xy_
    @pr0xy_ 2 ปีที่แล้ว

    my favorite bug bounty tools are amass and burp suite. #bbhammer

  • @pushpinderkaur6570
    @pushpinderkaur6570 2 ปีที่แล้ว

    Thank you for this video. I would love to know more about cloud security esp AWS. #bountypls

  • @Diddy81
    @Diddy81 2 ปีที่แล้ว

    My favorite BugBounty tool has to be Burp Suite #bbhammer

  • @johnnywarnink437
    @johnnywarnink437 2 ปีที่แล้ว

    Burp has to be my favourite tool! #bbhammer

  • @fng2971
    @fng2971 2 ปีที่แล้ว

    Thanks for the video, my favorite tools are burp & amass #bbhammer

  • @edoardottt
    @edoardottt 2 ปีที่แล้ว +1

    Burpsuite, nuclei, Cariddi, Gau, gxss, ffuf and google dorks #bbhammer

  • @mohammadisbah1458
    @mohammadisbah1458 10 หลายเดือนก่อน

    @Inderderphd
    Have you find idor vulnerability which leads to privilege escalation? Could you please tell me the scenario.

    • @InsiderPhD
      @InsiderPhD  10 หลายเดือนก่อน

      Usually it's permission related - create mutliple accounts with different permission levels, and try and do an admin action as a regular user

  • @bonenaing333
    @bonenaing333 2 ปีที่แล้ว

    Thanks for sharing. Burpsuite of course i am just the beginner #bbhammer

  • @tommydave2908
    @tommydave2908 2 ปีที่แล้ว

    I'd like to learn more about SSRFs, and maybe web cache poisoning, sounds cool. #bountypls

  • @danzosow5703
    @danzosow5703 2 ปีที่แล้ว

    Great 👍 topics I like nuclei thank you for your time and efforts
    #bbhammer

  • @kushagraaa
    @kushagraaa 2 ปีที่แล้ว

    Hey Katie, glad you are back again. Could you please make a detailed video on NOSQL injection attacks. My favourite tool is httpx by projectdiscovery due to it offering so many cool features.
    Have a great day. #bountypls #bbhammer

  • @serlibr4312
    @serlibr4312 2 ปีที่แล้ว

    Lovely video.......Burp for sure #bbhammer

  • @sandiyochristan
    @sandiyochristan 2 ปีที่แล้ว

    Thanks Kate ❤ for this giveaway I'm so inspired by you #bountypls #bbhammer

  • @roxneil1974
    @roxneil1974 2 ปีที่แล้ว

    katie, i'm new to bug hunter, i'm still practicing about the web security system, i have joined in ingriti but i don't know what i can and can't do when looking for bugs, can you give a little direction and tips on how to work in intigriti please,,

  • @albertinifrancis8594
    @albertinifrancis8594 2 ปีที่แล้ว

    Awesome content, my favorite tool is gobuster #bbhammer

  • @matthewhowes6270
    @matthewhowes6270 2 ปีที่แล้ว

    Burp,Ffuf, Nuclei, Aquatone and Nmap
    #betterlatethannever
    #bbhammer

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 ปีที่แล้ว

    Beginner here ;)

  • @mikhailmaksimov8247
    @mikhailmaksimov8247 2 ปีที่แล้ว

    My fav to the moment is chrome dev tools ;) #bbhammer thank you Katie for another awesome video ;) and I desperately need this zseanos bbh membership :)

  • @RahulKumar-vy4lu
    @RahulKumar-vy4lu 2 ปีที่แล้ว

    My go-to was always Burpsuite. #bbhammer

  • @christsili6554
    @christsili6554 2 ปีที่แล้ว

    Definitely Burp Suite! #bbhammer