Easy IDOR hunting with Autorize? (GIVEAWAY)

แชร์
ฝัง
  • เผยแพร่เมื่อ 29 ธ.ค. 2024

ความคิดเห็น • 261

  • @dhruvkandpal9909
    @dhruvkandpal9909 2 ปีที่แล้ว +7

    Great video, Katie! Loved it as always.
    My favourite bug bounty tools are burp suite, all tomnomnom's tools, amass and the ones I developed on my own! (LazyFuzzZ, Wordlist Weaver, Fu-JS) #bbhammer

  • @Vinayak123-q8p
    @Vinayak123-q8p 2 ปีที่แล้ว

    amazing, this could be probably one of the biggest information that i have ever been given

  • @sekmekci
    @sekmekci 2 ปีที่แล้ว

    Thanks for the video. Information part is starting at 3:49

  • @gf32768
    @gf32768 2 ปีที่แล้ว +3

    Awesome video, as always!
    Favourite tool - Burp Suite - even if the only features it had were the proxy history and Repeater, it'd still be amazing.
    ##bbhammer

  • @saite2560
    @saite2560 2 ปีที่แล้ว

    nice video i've watched quite a few of em. clear well rehearsed script.. this video actually tries to show us something. well rounded video.
    i wish more of your videos showed us how to actually do this stuff like this video. you do great on the speaking side of teaching tho, need more hands on tho.

  • @link-ed
    @link-ed 2 ปีที่แล้ว +2

    Thanks for the video! The tool that I use the most is fuff, cause of it's speed and simplicity. Burp is another indispensable tool as well! #bbhammer

  • @brucezhang4967
    @brucezhang4967 2 ปีที่แล้ว +3

    Thanks Kate! I want to know more about SSRF and businesss logic.#bountypls And my favourite bug bounty tool is absolutely BurpSuite!!! #bbhammer

  • @chitraa87
    @chitraa87 2 ปีที่แล้ว +1

    Thanks for doing amazing video katie. My fav bug bounty tool is burp ofcourse. I'm looking forward more automation videos like this..#bbhammer

  • @stablewater
    @stablewater ปีที่แล้ว +1

    Thanks for this great knowledge. I am currently learning IDOR and I've been able to use autorize and I got "enforced" in some areas. What next am I to do next. How do I exploit this for bug bounty?

  • @arrheniusangipaelongan8693
    @arrheniusangipaelongan8693 2 ปีที่แล้ว +5

    Thanks for all your videos Katie!❤ I got my first bug from your IDOR video. My favorite tool is burp! #bbhammer

  • @Death_User666
    @Death_User666 ปีที่แล้ว

    You are my favorite bug bounty channel

  • @wingwing2683
    @wingwing2683 2 ปีที่แล้ว +1

    Thanks so much sharing!

  • @svrajput14
    @svrajput14 ปีที่แล้ว

    Really nice tip on how to use tool effectively !!

  • @rami1785
    @rami1785 2 ปีที่แล้ว +1

    Thanks for all your videos Katie , My favorite tool is burp #bbhammer .

  • @vikasrushi3714
    @vikasrushi3714 2 ปีที่แล้ว +1

    Thanks :) my favourite bug bounty tool are Amass and FFUF #bbhammer

  • @sangeethaa5101
    @sangeethaa5101 2 ปีที่แล้ว +2

    I want more videos explaining bugs with dem websites not just presentations. Thank You, Katie. #bountypls #bbhammer

  • @CyberTron08
    @CyberTron08 2 ปีที่แล้ว +5

    Thanks for doing so much for the community ❤️
    It'll be great to have more videos about DOM based vulnerabilities #bountypls

  • @iamkaustubh
    @iamkaustubh 2 ปีที่แล้ว

    Wowww Thanks katie 🔥🔥🔥🔥it really encourages people more thanks for video

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 ปีที่แล้ว +1

    Started learning following your recon videos. My go to tool for now is Burpsuite community edition. #bbhammer

  • @webapplicationsecurity1853
    @webapplicationsecurity1853 2 ปีที่แล้ว +1

    Thanks for the video, have been using this tool for a while now. This is my favourite tool: Autorize allows to check most of the access Logic tests. #bbhammer

  • @amandabarbosasobrinho5878
    @amandabarbosasobrinho5878 2 ปีที่แล้ว +1

    Hey Katie, as always, awesome video! My favorite bug bounty tool is Burp, for sure! #bbhammer

  • @gk_eth
    @gk_eth 2 ปีที่แล้ว

    Mostly there r auth bearer token for APIs which also needs to be add in cookies section?

  • @ainter216
    @ainter216 2 ปีที่แล้ว

    Thank you very much for the video! My favourite toos is Burp Suite, it is so powerful and you can do so many things. #bbhammer

  • @champagnepete3386
    @champagnepete3386 2 ปีที่แล้ว

    Great video, good resource!!

  • @syedbukhari4761
    @syedbukhari4761 2 ปีที่แล้ว +2

    Great video Katie, my favourite tool is Amass & Wireshark; would love to see more videos on Business logic flaws & XXE flaws.
    #bountypls

  • @sadabesher2886
    @sadabesher2886 2 ปีที่แล้ว

    Burp and ffuf is my favorite tool

  • @singularityfinale7680
    @singularityfinale7680 2 ปีที่แล้ว +3

    You videos are both no bs info and free which is great for broke student like me. Well my favorite tool is Burpsuite #bbhammer
    And I think I will give Autorize a try.

  • @meletismichael2495
    @meletismichael2495 2 ปีที่แล้ว +1

    You are precious for the community! pls go more in depth on chaining vulnerabilities! #bountypls

  • @sudokom
    @sudokom 2 ปีที่แล้ว +2

    My favourite bugbounty tools are FFuF, Dirsearch, and Burpsuite with this extentions such as autorize #bbhammer

    • @sudokom
      @sudokom 2 ปีที่แล้ว

      ... And also obsidian #bbhammer

  • @roxneil1974
    @roxneil1974 2 ปีที่แล้ว

    katie, i'm new to bug hunter, i'm still practicing about the web security system, i have joined in ingriti but i don't know what i can and can't do when looking for bugs, can you give a little direction and tips on how to work in intigriti please,,

  • @ksr608
    @ksr608 2 ปีที่แล้ว +1

    Thank you for all your videos! My favourite tool is amass and burpsuite. #bbhammer. It'll be good to see more videos on subdomain takeover with an example. #bountypls

  • @maapi
    @maapi 6 หลายเดือนก่อน

    I'm having an issue with autorize picking up requests that should be out of scope. Anyone else have this issue? This leads to a lot of extra requests to parse through, which really slows me down

  • @Snoopydogsz
    @Snoopydogsz 2 ปีที่แล้ว +1

    My favourite bug bounty tool is ffuf combined with burp. I can bypass the speed limit of Intruder during fuzzing using -replay-proxy in ffuf which gives me the benifit of higher fuzzing speeds of ffuf and all the packets are captured in burp proxy too due to -replay-proxy flag set in ffuf.
    #bbhammer

  • @DieTeewurst
    @DieTeewurst 2 ปีที่แล้ว +1

    Thank you for your great Videos! My favorite Bug bount tool is burp for sure! So much functionality in one tool! #bbhammer

  • @DevilAlpacca
    @DevilAlpacca 2 ปีที่แล้ว

    Awesome, will definitely use the burp addon. Fav tool #bbhammer #bountypls

  • @deepeshrane8412
    @deepeshrane8412 2 ปีที่แล้ว

    Awesome video, I love to use Amass and burp suite!! #bbhammer

  • @0xff1337
    @0xff1337 2 ปีที่แล้ว

    why you're so late katie. i was waiting for this video for so long

  • @amitabhgupta21
    @amitabhgupta21 2 ปีที่แล้ว +3

    Started following you Katie and I am blown by the content u and
    other fellow u tubers are providing by the way my favourite BB tools are - Burp Pro,Rustscan,amass and nuclei
    #Bbhammer

  • @mohammedsaneem4179
    @mohammedsaneem4179 2 ปีที่แล้ว +2

    Great video as always. Would love to see videos based on chaining of bugs #bountypls

  • @ndmath
    @ndmath 2 ปีที่แล้ว +1

    Thank you Katie. I'd love to know more about Burp. #bountypls

  • @vanquisherstraveltube
    @vanquisherstraveltube 2 ปีที่แล้ว +2

    You are really a great teacher.
    I am following your videos and learning a lot. Thank you so much!
    *Burp* is my favorite tool
    #bbhammer

  • @sien1337
    @sien1337 2 ปีที่แล้ว

    my favorite bb tool is Burp, you can just do so much with it! #bbhammer

  • @asantoshkumarachary2692
    @asantoshkumarachary2692 ปีที่แล้ว

    Thanks for this video Katie

  • @mohammadisbah1458
    @mohammadisbah1458 ปีที่แล้ว

    @Inderderphd
    Have you find idor vulnerability which leads to privilege escalation? Could you please tell me the scenario.

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว

      Usually it's permission related - create mutliple accounts with different permission levels, and try and do an admin action as a regular user

  • @RahulKumar-vy4lu
    @RahulKumar-vy4lu 2 ปีที่แล้ว +2

    Great video as always. I would love to have more videos about XSS & chaining of bugs. #bountypls

  • @jarvis9092
    @jarvis9092 2 ปีที่แล้ว +2

    Please never stop creating content like these😍..It would be helpfull if you would increase your volume as i felt the audio is lower than other youtube videos..My favourite tool is BurpSuite #bbhammer

  • @abhishek-praveen
    @abhishek-praveen 2 ปีที่แล้ว +2

    I would love to see more videos on recon methadology for beginners . #bountypls

  • @andymarty80
    @andymarty80 2 ปีที่แล้ว

    I'd like to see videos on Anti-CSRF bypass, 2FA/MFA bypass or prediction.

  • @VincentOldMark
    @VincentOldMark 2 ปีที่แล้ว +1

    My favourite tool is of course burp suite #bbhammer You are great Katie!

  • @gonzalogermano2312
    @gonzalogermano2312 2 ปีที่แล้ว

    Thanks Katie my favorite tools is burpsuite #bbhammer

  • @pr0xy_
    @pr0xy_ 2 ปีที่แล้ว

    my favorite bug bounty tools are amass and burp suite. #bbhammer

  • @TechRideGamer
    @TechRideGamer 2 ปีที่แล้ว

    Thanks for this one its more than awesome.
    By favourite tool is Amass, fuff and in extensions autorepeater & Param Miner this are lit. #bbhammer

  • @darshannn10
    @darshannn10 2 ปีที่แล้ว

    Fav bug bounty tools - Burp, amass, nuclei, ffuf #bbhammer

  • @tomj1883
    @tomj1883 2 ปีที่แล้ว

    Thanks for the videos!!! My favorite tool is burp for sure #bbhammer

  • @kovanbakr
    @kovanbakr 2 ปีที่แล้ว

    thankyou,
    My favourite bug bounty tool is Burpsuite. #bbhammer

  • @SergeantDaynes
    @SergeantDaynes 2 ปีที่แล้ว +3

    Awesome video as usual. As for the types of bugs/hacking I want to learn about…SSRFs, broken access controls, business logic, and APIs! #bountypls

  • @matthewhowes6270
    @matthewhowes6270 2 ปีที่แล้ว

    Burp,Ffuf, Nuclei, Aquatone and Nmap
    #betterlatethannever
    #bbhammer

  • @gogreensongesters1800
    @gogreensongesters1800 2 ปีที่แล้ว

    Thank you Katie for this amazing video. My favourite bug bounty tool is Burpsuite. #bbhammer

  • @kbsavage77
    @kbsavage77 2 ปีที่แล้ว

    Welcome back! I'd love to learn more about SSRF #bountypls

  • @tXambe
    @tXambe 2 ปีที่แล้ว

    Thanks very much for your videos and my favourite tool is burpsuite #bbhammer

  • @th3r5n
    @th3r5n 2 ปีที่แล้ว +1

    I like to see more vedios on business logic bugs , like taking a public program and understanding the business logic of the functionalities.#bbhammer #bountypls

  • @kavishshah1988
    @kavishshah1988 2 ปีที่แล้ว

    Have only used Burp suite till now so I guess that's my favourite tool as of yet #bbhammer

  • @gauravdeore9477
    @gauravdeore9477 2 ปีที่แล้ว +1

    #bbhammer
    According to me burpsuite repeater is the best tool for hacking. We can perform any attack with it.

  • @ronny_xavier
    @ronny_xavier 2 ปีที่แล้ว

    Thanks as always Katie. My fav tool is Burp definitely. #bbhammer

  • @papajohn2821
    @papajohn2821 2 ปีที่แล้ว +2

    Mobile application security is what I am practicing for a month now. And videos on that topic will be great to learn from. #bountypls

  • @subhadipnag6028
    @subhadipnag6028 2 ปีที่แล้ว

    Your video is really awesome :)
    Always love for Burp Suite tool for damn sure !! #bbhammer

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 ปีที่แล้ว

    Thank you for the video

  • @shameeluddin3563
    @shameeluddin3563 2 ปีที่แล้ว

    Just found your channel searching for cybersec stuff.
    My favorite tool so far is burp.
    #bbhammer

  • @IrfanAli-vp5mh
    @IrfanAli-vp5mh 2 ปีที่แล้ว

    Next video idea suggestion: Burp autorepeater

  • @don-ce8ig
    @don-ce8ig 2 ปีที่แล้ว

    Thanks for making content! My favourite bug bounty tool is burpsuite #bbhammer

  • @adamkimbro
    @adamkimbro 2 ปีที่แล้ว

    #bbhammer My favorite tool burp. Thanks for your videos!!!

  • @bonenaing333
    @bonenaing333 2 ปีที่แล้ว

    Thanks for sharing. Burpsuite of course i am just the beginner #bbhammer

  • @sandiyochristan
    @sandiyochristan 2 ปีที่แล้ว

    Thanks Kate ❤ for this giveaway I'm so inspired by you #bountypls #bbhammer

  • @Diddy81
    @Diddy81 2 ปีที่แล้ว

    My favorite BugBounty tool has to be Burp Suite #bbhammer

  • @Silly_lilly926
    @Silly_lilly926 2 ปีที่แล้ว +1

    Thanks Kate ❤️ for this giveaway I'm so inspired by you and Aditi Singh and my favourite tool is FFUF love data exposed ❤️ #bbhammer

  • @morphsec
    @morphsec 2 ปีที่แล้ว +1

    Subdomain takeovers would be nice, saw a lot of good reports but never seemed to fully understand them. #bountypls
    Burp and Amass is the bread and butter for me. #bbhammer

  • @fatihburaktoprak769
    @fatihburaktoprak769 2 ปีที่แล้ว

    My favorite is always Burp Suite! #bbhammer

  • @Malware01
    @Malware01 2 ปีที่แล้ว

    Hey, my favourite bb tools are burpsuite, sql map #bbhammer

  • @saminbinhumayun858
    @saminbinhumayun858 ปีที่แล้ว

    do we get Cookies from the admin account or the low-privileged account?

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว +1

      Low privileged account always! Your low privileged is always your attacker

  • @eraedith696
    @eraedith696 2 ปีที่แล้ว

    Fav tool is Burpsuite because it has some automation and also manual testing which is good and it's also beginner friendly tool and many more to learn.... Thank you❤
    #bbhammer

  • @jovensqueprosperam
    @jovensqueprosperam 2 ปีที่แล้ว

    Thanks for this channel

  • @tajsec
    @tajsec 2 ปีที่แล้ว

    my favorite tool is burp suite, nmap :)) thanks for great contents
    #bbhammer

  • @sudarshsaraswathula1401
    @sudarshsaraswathula1401 2 ปีที่แล้ว

    Thanks a lot for the vid. My favourite tool is ffuf #bbhammer

  • @edoardottt
    @edoardottt 2 ปีที่แล้ว +1

    Burpsuite, nuclei, Cariddi, Gau, gxss, ffuf and google dorks #bbhammer

  • @svg98
    @svg98 2 ปีที่แล้ว

    My favorite tool is your channel (and Burpsuite) #bbhammer

  • @shamim_12
    @shamim_12 2 ปีที่แล้ว

    Well my favorites are FFUF and Dirsearch #bbhammer

  • @italoamaya8230
    @italoamaya8230 2 ปีที่แล้ว

    thank you so much

  • @LeonVQZ
    @LeonVQZ 2 ปีที่แล้ว

    I would like to know more about CSRF, I haven't been able to understand the impact or what it can lead to if the application is vulnerable to CSRF #bountypls

  • @pushpinderkaur6570
    @pushpinderkaur6570 2 ปีที่แล้ว

    Thank you for this video. I would love to know more about cloud security esp AWS. #bountypls

  • @devangsolanki4622
    @devangsolanki4622 2 ปีที่แล้ว

    Thank you for the giveaway!!
    My favourite tool is burpsuite! because Its so simple and powerfull. #bbhammer

  • @vivekkashyap7293
    @vivekkashyap7293 2 ปีที่แล้ว +3

    My comment is keep deleting automatically??😭😭? Why #bbhammer
    stored css that was awesome moment and in September 2021 i got another credentials in API url by your api playlist
    Then in December 2021 i got IDOR by autorize 😅❤️❤️ (also i would like to see more idor,api etc videos some real live testing on idor,api also videos on career making in hacking how to easily get in bugcrowd,hackerone, integrity etc ) but similarly in all of these is they are not high bounties I'm trying to get good skills , so much thank you for this give away hanks to you and all bug Bounty mentors for sharing their skills with youngsters #bbhammer
    😅

  • @dimuthdeja7859
    @dimuthdeja7859 2 ปีที่แล้ว

    Hi
    I am following your videos long time.
    My favourite tool is Burp-Suite. Thank you. #bbhammer

  • @prakashinfo
    @prakashinfo 2 ปีที่แล้ว

    My favorite bug bounty tool is nuclei..
    #bbhammer

  • @tommydave2908
    @tommydave2908 2 ปีที่แล้ว

    I'd like to learn more about SSRFs, and maybe web cache poisoning, sounds cool. #bountypls

  • @RahulKumar-vy4lu
    @RahulKumar-vy4lu 2 ปีที่แล้ว

    My go-to was always Burpsuite. #bbhammer

  • @old2235
    @old2235 2 ปีที่แล้ว

    My favourite bugbounty tool is still Burpsuite #bbhammer

  • @mooreprr8067
    @mooreprr8067 2 ปีที่แล้ว

    Favorite tools are Burp, Amass, All of Tomnomnom's Tools ,Cariddi #bbhammer

  • @0xff1337
    @0xff1337 2 ปีที่แล้ว

    my favorite tool is burp repeater and intruder #bbhammer #bountyplease

  • @faique2995
    @faique2995 2 ปีที่แล้ว +3

    Thank you for holding my hands and taking me to this level in cyber security, Be healthy and happy😁
    #bountypls

  • @mrpvr
    @mrpvr 2 ปีที่แล้ว

    I wanted to know more about XXE and SSRF Bugs #bountypls #bbhammer