My Methodology

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ต.ค. 2024

ความคิดเห็น • 62

  • @Maia1337
    @Maia1337 4 ปีที่แล้ว +10

    Well done, Katie! Congratulations on the audio upgrade. :D

  • @RahulSharma-er8zz
    @RahulSharma-er8zz 3 ปีที่แล้ว +1

    Really liked your view on manual stuff

  • @meispi9457
    @meispi9457 4 ปีที่แล้ว +6

    Sound is...
    AMAAAAZZZZZIIIINNNNGGG!!!!!

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +4

      I'm so glad I sorted it, thanks for sticking with bad audio era, the future looks bright!

  • @ashisbanerjee4584
    @ashisbanerjee4584 4 ปีที่แล้ว +3

    You really great, no one says their's methodology.

  • @haydene3802
    @haydene3802 3 ปีที่แล้ว +1

    Love these videos! I like how you make these techniques and things more human. Guides and other videos seem so intimidating, this is a lot more realistic for learning

  • @pentestical
    @pentestical 4 ปีที่แล้ว +2

    Such a clean audio, damn. Thanks for this amazing content!

  • @francisdonald4298
    @francisdonald4298 3 ปีที่แล้ว +1

    Can you make live bughunting videos for better understanding on live targets??!!!!!

  • @MrMoudugenou
    @MrMoudugenou 4 ปีที่แล้ว +1

    Cool video !

  • @velurubharath8929
    @velurubharath8929 4 ปีที่แล้ว +1

    As always, nice and short video.

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +4

      Glad you enjoyed it! I'm trying to make sure I get some shorter more bite sized videos out so I can continue making videos weekly!

  • @AkshayBhujbal-h9m
    @AkshayBhujbal-h9m 23 วันที่ผ่านมา

    Notes:
    Methodology:
    1. figure out what an application/feature does.
    2. click every button and link. (Sometimes do some fuzzing)
    3. identify Interesting endpoints.
    The Cycle:
    Try exploit>Doesn't work?(if it works exploit it)>workout why>change exploit.

  • @0x1h0b
    @0x1h0b 4 ปีที่แล้ว

    Looks like we are soon getting a live stream talk... nice video and audio😅😍

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      Yes we are! I have all the equipment now I can't wait to live hack some stuff!

  • @skull_cyber
    @skull_cyber 4 ปีที่แล้ว

    and one last question, what is endpoint and how find it or get knowledge bout it.

  • @joshgordon7299
    @joshgordon7299 4 ปีที่แล้ว

    Awesome

  • @carolbolger2009
    @carolbolger2009 4 ปีที่แล้ว

    Thank you for this great content. It is perfect for someone like me who is beginning bug hunting, even though I have been a developer for a long time. I would like to know what your basic set up includes, such as OS, VPN, and other essentials.

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      My setup: I use OSX or Windows, and Burp Suite Professional (for the ability to search), discord and slack to ask for help. I don’t use anything fancy until I need to, never used Kali but I am familiar with the command line and Linux, I just prefer standard OSs

  • @kallikantzaros
    @kallikantzaros 4 ปีที่แล้ว

    thaaaankkkk youuuuu sooooo muuuuchhh

  • @learnfirst-1
    @learnfirst-1 2 ปีที่แล้ว

    You r great 🥰👍👍

  • @corporatemurrell
    @corporatemurrell 4 ปีที่แล้ว

    Love these vids, keep it up!

  • @karansh491
    @karansh491 4 ปีที่แล้ว +1

    Hello ma'am, great videos.
    And I'm a computer science student doing BCA. Am i worthy for bug bounty? I'm learning for 2-3 months now, but I don't know what to do now, like I'm kindof blank maybe.

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +4

      If it’s something you want to pursue of course you are worthy! I would say you need to think critically about what you’re learning and why. Are you learning about specific bugs? Are you then trying out CTFs? And then are you looking for those bugs in the wild? That’s the phases you should go through: 1) Learn what bugs are out there 2) Learn how to spot and exploit them 3) Practice finding those bugs. I will say that it can take a really long time to find your first bug, and don’t feel like you’re not good enough to be a bug hunter when it takes MOST people MONTHS to find their first bug.

    • @karansh491
      @karansh491 4 ปีที่แล้ว

      @@InsiderPhD thank you ma'am.
      you're the best :)

  • @imkir4n
    @imkir4n 4 ปีที่แล้ว

    100th like well done Katie!

  • @learnfirst-1
    @learnfirst-1 2 ปีที่แล้ว

    How many bug you find ??

  • @PabloSilva-ph6mk
    @PabloSilva-ph6mk 4 ปีที่แล้ว +1

    Me: a
    Katie: CHAOTIC!

  • @tomyroom2832
    @tomyroom2832 4 ปีที่แล้ว

    Thanks, this is a polite methodology
    Can you complete the special course for us " How To Do Recon "

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +4

      It will come on soon, I have a day job in addition to the hacking, so in order to make sure I can make videos weekly I need to mix shorter videos every other week as a mixture between topics I know very well with those I don’t. It will come out, I’ve just written the API enumeration video today :)

    • @tomyroom2832
      @tomyroom2832 4 ปีที่แล้ว +1

      Thank you and I appreciate this, and I wish you luck

  • @meispi9457
    @meispi9457 4 ปีที่แล้ว +2

    I have a question
    I am not very good at XSS and I ignore it while doing hunting because I find it quite boring (the impact is interesting, finding them is not)
    Any suggestions?

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +7

      I am also not a fan of XSS, I find them quite boring and the amount of bypasses you need to find and keep up to date with is meh. I recently learned how to use XSS to bypass the SOP policy on a mobile app though and that really got me excited. So my suggestions: Take a look at some really impressive XSS attacks to help you get excited for XSS again or just don't focus on it for a bit, maybe go for a deep dive into something where you don't typically find XSS like mobile or hardware hacking, upskill in something else!
      Personally, I just ignore XSS unless I really understand how a filter works. It took me MONTHS to find my first XSS!

    • @meispi9457
      @meispi9457 4 ปีที่แล้ว

      @@InsiderPhD Thanks for the response 😊

  • @skull_cyber
    @skull_cyber 4 ปีที่แล้ว

    Seriously much informative but I have a query how do I identify how the server is responding and fault in response.

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      You look for the response code, here's a list en.wikipedia.org/wiki/List_of_HTTP_status_codes

    • @skull_cyber
      @skull_cyber 4 ปีที่แล้ว

      @@InsiderPhD thnxxx.......

  • @cypherphage4294
    @cypherphage4294 4 ปีที่แล้ว

    Hi...how do you approach learning a new topic ? Can we get a video on that...pls

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      Great video idea! For sure I’ll make this :D

  • @swapnilpawar2311
    @swapnilpawar2311 4 ปีที่แล้ว

    Great video Big fan, can you make video of your bug hunting

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      I'm really hoping to do this, but I am not sure how to do it without breaking disclosure policies!

    • @swapnilpawar2311
      @swapnilpawar2311 4 ปีที่แล้ว +1

      @@InsiderPhD That's Ok , I know you'll find way 😊😊

  • @josephnimsara3169
    @josephnimsara3169 4 ปีที่แล้ว +2

    madam katie can you please bring a video which is showing about real life bug bounty i mean make a video doing a real pentest for a real site

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      This is something I wanna do, but I'm trying to find a way that keeps everything confidential

    • @josephnimsara3169
      @josephnimsara3169 4 ปีที่แล้ว

      @@InsiderPhD sry for troubling you are best of best the thing i want tell is most of the youtubers do there videos while pentesting vulnerable web like =owasp jucy shop but we dont understand how to use them for real life bug bounties

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +2

      This is the problem I have too. CTFs suck for actually demonstrating bug bounties, no web developer in 2020 is leaving SQL injection in their work. It’s why I want to show the actual hacking process, but I don’t want to break confidentiality, I’ve had ideas but I’m not sure how to solve it yet

    • @josephnimsara3169
      @josephnimsara3169 4 ปีที่แล้ว

      @@InsiderPhD thaq u very much you are the pentest ever message to a beginner SUCH KINDLY

    • @josephnimsara3169
      @josephnimsara3169 4 ปีที่แล้ว

      i think you are the best person ever if can please message to to this email because i has lot of problems please i will not trouble you promise please cyber.plauge212@gmail.com

  • @newuser2474
    @newuser2474 4 ปีที่แล้ว

    I love you

  • @zamanttonoy6639
    @zamanttonoy6639 4 ปีที่แล้ว

    love from bangladeshi followers :)

  • @pentestical
    @pentestical 4 ปีที่แล้ว

    I'm not here because of Bug Bounty tips, I'm here for audio engineering tips

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +3

      New setup is a Audio-Technica AT2020 & Scarlet Solo interface! Plus a fancy mic stand with some acoustic foam to stop echos!

  • @aravindv6765
    @aravindv6765 4 ปีที่แล้ว +1

    Can you make SQL injection video

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      I’ll add your suggestion to the coming soon pile :)

    • @aravindv6765
      @aravindv6765 4 ปีที่แล้ว

      @@InsiderPhD I am waiting ♥️

    • @davidt01
      @davidt01 4 ปีที่แล้ว +1

      Is SQL injection still worth it to look for?

  • @spydev-sudo
    @spydev-sudo 2 ปีที่แล้ว

    why dont you add your face cam on your videos

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 ปีที่แล้ว

    :)