How to Find XSS on Modern Web Applications: A Bug Bounty Guide

แชร์
ฝัง
  • เผยแพร่เมื่อ 17 ธ.ค. 2024

ความคิดเห็น • 27

  • @PrimordialLegend
    @PrimordialLegend วันที่ผ่านมา +1

    Thanks, nice work. Keep going!

  • @poiuymnbvc8339
    @poiuymnbvc8339 3 วันที่ผ่านมา +1

    Bro great video, i truely love the pace…keep it man..

  • @shubham_srt
    @shubham_srt 2 วันที่ผ่านมา +1

    keep making more videos

    • @bugbountywithmarco
      @bugbountywithmarco  2 วันที่ผ่านมา

      thanks for the feedback. What topic would you like to see next?

  • @imperim
    @imperim 3 วันที่ผ่านมา +1

    Thanks, nice explanation

    • @bugbountywithmarco
      @bugbountywithmarco  3 วันที่ผ่านมา

      nice to know that! Is there any other vulnerability you would like to see in the perspective of a web software engineer?

    • @imperim
      @imperim 3 วันที่ผ่านมา +1

      I am just beginner in this field so just learning from internet Portswigger labs, TH-cam, you etc any help appreciate

    • @bugbountywithmarco
      @bugbountywithmarco  3 วันที่ผ่านมา

      nice to know that, i’ll be posting about other bugs soon

    • @imperim
      @imperim 3 วันที่ผ่านมา +1

      Thanks

  • @poiuymnbvc8339
    @poiuymnbvc8339 3 วันที่ผ่านมา +1

    Can you make a series for hunting xss?? Showing how to exploit xss in different ways

    • @bugbountywithmarco
      @bugbountywithmarco  3 วันที่ผ่านมา

      @@poiuymnbvc8339 that’s something I wanted to do. I have some application that I developed myself that i can use for demonstration

  • @tpevers1048
    @tpevers1048 22 ชั่วโมงที่ผ่านมา +1

    So about doom xss

  • @SumitYadav-lr5vy
    @SumitYadav-lr5vy 3 วันที่ผ่านมา +1

    Can you start a series in which you explain bugs which a not hunted by many hunter

    • @bugbountywithmarco
      @bugbountywithmarco  3 วันที่ผ่านมา

      @@SumitYadav-lr5vy of course! I have a scheduled video here about non common vulnerabilities

  • @SumitYadav-lr5vy
    @SumitYadav-lr5vy 3 วันที่ผ่านมา +1

    So as a beginner who just started bug Bounty what types of bugs will you recommend him to hunt for ?

    • @bugbountywithmarco
      @bugbountywithmarco  3 วันที่ผ่านมา

      @@SumitYadav-lr5vy i would suggest you to start with one of these: IDOR, Business Logic Errors or Broken Authorization.
      Specially business logic errors, that may not be as popular as the other ones.

    • @SumitYadav-lr5vy
      @SumitYadav-lr5vy 3 วันที่ผ่านมา +1

      @@bugbountywithmarco can you recommend me some recourse because business logic error doesn't have good resources?

    • @bugbountywithmarco
      @bugbountywithmarco  3 วันที่ผ่านมา

      @@SumitYadav-lr5vy actually to find a business logic error vulnerability you need to understand the business of the application you are testing.
      For example: a dating app allows the user to send messages to another user only when they have a match. But what if the user can actually send messages to a person before the match?

    • @SumitYadav-lr5vy
      @SumitYadav-lr5vy 3 วันที่ผ่านมา +1

      @@bugbountywithmarco it is like bac related issues

    • @bugbountywithmarco
      @bugbountywithmarco  3 วันที่ผ่านมา

      @@SumitYadav-lr5vy a little similar issue

  • @imperim
    @imperim 3 วันที่ผ่านมา +1

    hey i have noticied u reported many vulnerabilities in hacker one may i know what kind of those vulnerabilities are? do those are xss? or what

    • @bugbountywithmarco
      @bugbountywithmarco  3 วันที่ผ่านมา +1

      my top 3 most reported vulnerabilities is: business logic errors, IDOR, and Improper Access Control

    • @imperim
      @imperim วันที่ผ่านมา

      @@bugbountywithmarco oh thanks & interesting

  • @shubham_srt
    @shubham_srt 2 วันที่ผ่านมา +1

    none of your social links are working btw

    • @bugbountywithmarco
      @bugbountywithmarco  วันที่ผ่านมา

      thanks for the tip. I believe this is happening because this channel was just created.
      You can find the clickable links in my channel page though