The 3 Tools You Need // How To Bug Bounty

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ก.ย. 2024

ความคิดเห็น • 80

  • @MikeTyson-ms2cl
    @MikeTyson-ms2cl ปีที่แล้ว +67

    I promise someday in future, I will become a great hacker and a great bug bounty hunter and i will make it into top 100 best hackers

    • @NahamSec
      @NahamSec  ปีที่แล้ว +14

      You got this!

    • @axelvirtus2514
      @axelvirtus2514 ปีที่แล้ว +6

      Tyson go fight old man 🤣

    • @amoh96
      @amoh96 ปีที่แล้ว

      @handsinthepocketsguy2036 HEHE

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked ปีที่แล้ว

      ​@@axelvirtus2514 Mike Tyson xD Haha. Just that age reversal is around the corner in mainstream science, so let's see his age reverse. Hehe

    • @Fixenet5
      @Fixenet5 11 หลายเดือนก่อน

      How are you doing right now ?
      I am also on the same path as you :)

  • @samk1491
    @samk1491 ปีที่แล้ว +22

    *TLDR*
    You only really need a handful of free tools to get going with bug bounties.
    Asset Discovery:
    amass
    subfinder
    Fuzzing/Dir Brute Forcing:
    ffuf
    dirsearch
    Proxy Tool:
    Burp Suite
    ZAP

  • @xzuky0233
    @xzuky0233 ปีที่แล้ว +12

    I just started learning hacking. Thanks so much for making these videos man! They're really helpful for me!

    • @NahamSec
      @NahamSec  ปีที่แล้ว +3

      Thanks for watching!

  • @abdonito8254
    @abdonito8254 ปีที่แล้ว +15

    We need live or video about all recon before start hunt (ports, subdomaine .....) New tools + ai ...

    • @CM-xr9oq
      @CM-xr9oq ปีที่แล้ว +1

      Dude, he has done so many videos on that....

    • @ahmedahmedx9600
      @ahmedahmedx9600 ปีที่แล้ว

      Yes its a good idea

    • @abdonito8254
      @abdonito8254 ปีที่แล้ว

      @@CM-xr9oq can you share with me links ❤️

    • @NahamSec
      @NahamSec  ปีที่แล้ว +10

      Check out my video that’ll get released later this week!

  • @qazwacook1983
    @qazwacook1983 ปีที่แล้ว +5

    Would be awesome to see a video of you doing recon and, looking for bugs with just these 3 tools!

  • @محمّد.09
    @محمّد.09 10 หลายเดือนก่อน +2

    This is a great reminder to quit your obcession and getting overwhelmed by automation tools. Focus on improving your skill more and more.

  • @coolkalli8574
    @coolkalli8574 ปีที่แล้ว +1

    a full in-depth video about content discovery using ffuf or feroxbuster like multiple technology sites need which kind of wordlists and how to find those sites to be precise like which targets to choose to perform content discovery. could be really helpful. Thanks a lot for your videos.

  • @recepby
    @recepby ปีที่แล้ว +2

    Asset Discovery: amass + subfinder
    Content Discovery(Fuzzing/Directory Bruteforcing): ffuf + dirsearch
    Proxy Tool: Burp Suite + ZAP

  • @jessicaphillips8096
    @jessicaphillips8096 ปีที่แล้ว +2

    Clear and juicy... Thank you 😊

  • @eritech
    @eritech ปีที่แล้ว +1

    Thanks for everything you do, Nahom, It would helpful if you do a video exclusively on burpsuite or any of the tools you use. I really like the advice not to focus on too many tools.

    • @NahamSec
      @NahamSec  ปีที่แล้ว +1

      Great suggestion! Will try and make something soon!

  • @rahmat_qurishi
    @rahmat_qurishi ปีที่แล้ว +2

    Great as always♥️could you please make a video about api security🙂

  • @siliconrobot6522
    @siliconrobot6522 4 หลายเดือนก่อน +1

    I saw some bug bounty programs asking bug hunters not to use automation hacking tools like burpsuite and metasploit!! Is it fair to ask people to reinvente the wheel in order to find bugs for some companies that will accept it or refuse it at the end if all the big efforts he made?

  • @G3msFinder
    @G3msFinder ปีที่แล้ว

    Thanks bro, we will be thankful if you do the video's of all all these tools

  • @AyushXtha
    @AyushXtha ปีที่แล้ว +2

    You are a good man. ThankYou😊

  • @kaleykaley2389
    @kaleykaley2389 ปีที่แล้ว +3

    we want this tools used one by one plzz make video on this

  • @jruok
    @jruok ปีที่แล้ว

    Thanks NahamSec! Video was short and sweet. I appreciate when you project the names of the tools on the screen bc sometimes the caption doesn't translate what you're saying correctly (my hearing sucks lol). Just a thought but could AI be used for those trivial tasks that are usually automated? Sorry if this was addressed in another video.

  • @zivintoplomjer8889
    @zivintoplomjer8889 ปีที่แล้ว +1

    hey man, thanks for the video. would you be down to share some POC videos on disclosed vulns, like how you actually found the bug and showed impact?

    • @NahamSec
      @NahamSec  ปีที่แล้ว

      Maybe - Hard to do it without the program's permission.

  • @Frawkesish
    @Frawkesish ปีที่แล้ว

    I would love to see a more indepth video on the devtools honestly.. its free and messy but it seems you found some success with it in your video talking about making 10k in a week.

  • @wizardff358
    @wizardff358 ปีที่แล้ว

    You're my Idol. please make playlist on these 3 category in details video for beginners🥺💖💖

  • @akashsarkar9579
    @akashsarkar9579 ปีที่แล้ว

    Yes sir I really want to learn Bug Bounty hunting. Please show us the basics of all tools.

  • @Death_User666
    @Death_User666 ปีที่แล้ว

    You sir are a legend and have a guaranteed spot in heaven

  • @bibekand
    @bibekand ปีที่แล้ว +3

    please create video of each tools

  • @mf-11111
    @mf-11111 11 หลายเดือนก่อน +1

    Amass
    Subfinder
    FFUF
    BurpSuite

  • @ahsan-li7sh
    @ahsan-li7sh ปีที่แล้ว

    I love all your videos, i have also bought your Udemy course. Please make a video all these tools you mentioned. Specially burp suite professional! Thanks in advance!

  • @haksauc3
    @haksauc3 ปีที่แล้ว

    Ok so I’m new. I’m curious, like how do you know when you’ve found a bug. Is it just like when you find a vulnerability? If u find u can do command injection. That’s the bug?

  • @santiagotaboada4584
    @santiagotaboada4584 ปีที่แล้ว

    Great video!! Could you please do a video about how to use Amass? I know that it’s a super powerful tool but the syntax is a bit confusing. Thank you in advance :)

    • @EverettJWashington
      @EverettJWashington ปีที่แล้ว

      Agree here. Been trying to use that to its full potential and curious on his take on it. I read some stuff that Hakluke recommended in regards to using it, which included adding a lot of API keys, but then read that ReconFTW was even better but that one seems to be even more complicated as it combines a ton of recon tools together including amass! Anyway, any info on either would be good. (Particularly to maximize recon results)

  • @peternavarroiii3944
    @peternavarroiii3944 ปีที่แล้ว

    Good stuff. This got me thinking, could you use burp suite to verify if a link on a suspicious email is phishing?

  • @SyedImran-qf1eh
    @SyedImran-qf1eh ปีที่แล้ว

    Thanks Nahamsec,
    I would like to also do this bug hunting. But before starting we need to learn something like how networking works.
    Can you give me some advice on this.
    Thanks

  • @chizzlemo3094
    @chizzlemo3094 ปีที่แล้ว

    My big frustration is that when bug teachers show how bugs work its always on a contrived app like DVWA and doesnt feel realistic, but of course only recon is legal for live yt

  • @HassanRaza-ek3mv
    @HassanRaza-ek3mv ปีที่แล้ว

    Thank you for this informative video.

  • @user-or9sh5pr9y
    @user-or9sh5pr9y ปีที่แล้ว

    I have always been you fan . I have been away from bug bounty for quite a some time now , How to restart

  • @mdashifuzzamanshawon
    @mdashifuzzamanshawon ปีที่แล้ว

    Awesome. Very very informative...

  • @Dr_Aways
    @Dr_Aways ปีที่แล้ว

    thanks pro , can you share how do ecternal recon for wild scope

  • @microburn
    @microburn ปีที่แล้ว

    You said you pay for burp but you don’t use any of burp paid functionality! All of that intruder stuff you can do for free!
    Solid stuff tho. Keep it up

  • @medofc1300
    @medofc1300 ปีที่แล้ว

    We need live about
    What after recon

  • @bugs-lk3jf
    @bugs-lk3jf ปีที่แล้ว

    Like a Boss ...

  • @CodeAcademia00
    @CodeAcademia00 ปีที่แล้ว

    please make a video on how to use these tools

  • @Ajay-kz6zw
    @Ajay-kz6zw ปีที่แล้ว

    We need video how to test mannualy 🙂I believe you do.

  • @maheshfan8178
    @maheshfan8178 ปีที่แล้ว

    @NahamSec please make a video on the tools..your explanation is simply awesome

  • @learn-with-noob-007
    @learn-with-noob-007 ปีที่แล้ว

    Sir did you just release a full bug Bounty course and for that we have to be a member??

    • @NahamSec
      @NahamSec  ปีที่แล้ว

      No. It's from my stream on Sunday, it's available to Members fro now.

  • @smitrabadiya234
    @smitrabadiya234 ปีที่แล้ว

    Bug bounty basic on tools please

  • @mominul0x01
    @mominul0x01 ปีที่แล้ว

    Great

  • @vaseemakram6692
    @vaseemakram6692 ปีที่แล้ว

    Can't able to JOIN, it says => "can't open the link"

    • @NahamSec
      @NahamSec  ปีที่แล้ว

      What do you mean?

  • @didigaming-lc9zm
    @didigaming-lc9zm ปีที่แล้ว

    no hay para mac

  • @zahiruddinahmad55
    @zahiruddinahmad55 ปีที่แล้ว

    please make a video subdomain takeover

    • @NahamSec
      @NahamSec  ปีที่แล้ว +1

      You mean like this one? th-cam.com/video/MB4OssSHXDs/w-d-xo.html

  • @saikiran80555
    @saikiran80555 ปีที่แล้ว

    ✨Hi

  • @zahiruddinahmad55
    @zahiruddinahmad55 ปีที่แล้ว

    Hello Sir.

    • @NahamSec
      @NahamSec  ปีที่แล้ว +1

      Hello! 👋🏽

  • @vivekkhandagre9274
    @vivekkhandagre9274 ปีที่แล้ว +1

    wow 😍😚☺

  • @elronhalf-elven6491
    @elronhalf-elven6491 ปีที่แล้ว

    Probably get this question a lot, but do I really need to get a degree to become a SOC Analyst ? Should I be able to find a job if if get my Comptia Security+ and Network+ ? I understand showing some other skills is important too, but I feel like a 4 year degree will just be a waste of money for me. I can't afford it.

  • @weniweedeewiki.6237
    @weniweedeewiki.6237 ปีที่แล้ว

    4 tools if you include myself