My First Bug Bounty - Gitter $1,000 one-click DoS

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 พ.ย. 2024

ความคิดเห็น • 79

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  3 ปีที่แล้ว +3

    Welcome to the comment section!
    First, thanks for watching!
    Make sure you are subscribed if you liked the video!
    th-cam.com/users/BugBountyReportsExplained
    Follow me on twitter:
    twitter.com/gregxsunday
    ✉️ Sign up for the mailing list ✉️
    mailing.bugbountyexplained.com/
    ☕️ Support my channel ☕️
    www.buymeacoffee.com/bountyexplained
    🖥 Get $100 in credits for Digital Ocean 🖥
    m.do.co/c/cc700f81d215

  • @y.vinitsky6452
    @y.vinitsky6452 4 ปีที่แล้ว +16

    thank you for posting your story it's really encouraging

  • @theanonymous9110
    @theanonymous9110 3 ปีที่แล้ว +1

    Man thanks u make it a lot easier to understand than any videos I’ve seen so far, you get right down to the point exactly thanks again...

  • @weefunkster
    @weefunkster 4 ปีที่แล้ว +12

    I am fullstack web developer for the last 3 years, just now dipping my toes into security. Was wondering how long you have been doing this? Also, how long do you think it would take a green dev like myself to get their first bounty?

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  4 ปีที่แล้ว +27

      hi, at the time of finding this I had one year experience in pentesting. As a web developer your are in a good position because you understand the web stuff. However, I would not recommend you starting with bug bounty as it's rather competitive field and not finding bugs might be discouraging. You should take a look into resources like pentrsterlab and potrswigger websec academy and then after a few months you might find your first bug.

  • @ancap1348
    @ancap1348 4 ปีที่แล้ว +4

    ótimo vídeo, você minha espiração . Brasil aqui .
    : )

  • @sy-hungdoan4859
    @sy-hungdoan4859 4 ปีที่แล้ว +3

    Very interesting !!! Looking forward to your next BBR :D

  • @CuteLittleHen
    @CuteLittleHen 4 ปีที่แล้ว +3

    Great catch! Is the database you were able to view in the internal gitter server you locally set up?

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  4 ปีที่แล้ว +1

      yes, the mongo is easy to set up using docker-compose and it exposes the web interface i've shown on port 27017.

  • @xaero212
    @xaero212 3 ปีที่แล้ว +1

    Congratulations, you inspire!

  • @unknownuser1806_
    @unknownuser1806_ 4 ปีที่แล้ว +2

    congratulations bro.. And your channel is unique and aswome too.

  • @ii7990
    @ii7990 4 ปีที่แล้ว +5

    Good job! How many hours went into that?

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  4 ปีที่แล้ว +7

      i think i spent about 8 hours working to get the environment ready on my PC. Then, I gave up and tried on my VPS and it worked straight away. The testing was about three 8-hour days.

  • @green_quirk
    @green_quirk 4 ปีที่แล้ว +2

    Thanks, bro. Nice explanation.

  • @soumyapoddar4711
    @soumyapoddar4711 3 ปีที่แล้ว

    I am lucky, that I found this channel, :)

  • @shantanudash7
    @shantanudash7 4 ปีที่แล้ว +2

    This was really awesome.

  • @Sloottools
    @Sloottools 2 ปีที่แล้ว

    How many websites can we scan at the same time

  • @alexvolkov7232
    @alexvolkov7232 3 ปีที่แล้ว

    Elegant work well explained:) Congrats on your $1000 bounty. Subbed!

  • @yashwanthd1998
    @yashwanthd1998 4 ปีที่แล้ว +1

    Yeah fb also has redirect uri for every appid

  • @WutDaHek69420
    @WutDaHek69420 4 ปีที่แล้ว +1

    I thought it was a "GTA BOUNTY" after i read the title XD

  • @manmoon7396
    @manmoon7396 3 ปีที่แล้ว

    Good job... Keep it up.

  • @rujor
    @rujor 4 ปีที่แล้ว

    Is it just me, or is the fix actually that they added the 'try'--it looks like they're still parsing undefined (**edit:** "still attempting to access "protocol" on undefined") in this edgecase, the test just produces a warning as far as I can see 🤔.

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  4 ปีที่แล้ว

      the problem was just using undefined.something and it threw an error that you wanted a property of undefined. They fixed just that here.

    • @rujor
      @rujor 4 ปีที่แล้ว +1

      Sure, I was just commenting on your explanation that they fixed it by "validating that there is a 'registeredRedirectUri'", when in fact its the try/catch that graciously handles the error now 🙂. The "validation" just produces a warning, and the attempt to access `.protocol` is still allowed to happen as far as I can see.

  • @aneesh219
    @aneesh219 2 ปีที่แล้ว

    I have a Vulnerabilityreport of myn, 1st bounty......
    Can you please make a video???

  • @amolgangurde5714
    @amolgangurde5714 4 ปีที่แล้ว +1

    Nice findings

  • @VincentOldMark
    @VincentOldMark 3 ปีที่แล้ว

    Subscribed!

  • @hasanvalentino4129
    @hasanvalentino4129 4 ปีที่แล้ว

    U gotta get bonus from URL redirection

  • @klara4536
    @klara4536 4 ปีที่แล้ว

    Great Job!!! :)

  • @piyushsingh6184
    @piyushsingh6184 3 ปีที่แล้ว

    Could You Please Upload The Captions..??
    Auto-Generated Caption Would Also Work..!!

  • @hirthicshyam9290
    @hirthicshyam9290 4 ปีที่แล้ว

    What are the essential programing languages I should learn to become Ethical Hacker?

  • @c.pradeepreddy3647
    @c.pradeepreddy3647 4 ปีที่แล้ว

    i am astudent and want to be a ethical hacker and do bug bounty where do you think i should start from

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  4 ปีที่แล้ว

      I'd suggest owasp testing guide as a starting point and getting some practice on pentrsterlab and potrswigger's websec academy

  • @aneeltripathy7420
    @aneeltripathy7420 2 ปีที่แล้ว

    how do I open the web application's file in visual studio code ?

  • @venom0.543
    @venom0.543 3 ปีที่แล้ว

    can you share you methodology it would be a great help

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  3 ปีที่แล้ว

      I don't think I'm good enough to give you methodology. For this bug I just installed the app locally, I was finding interesting spots and reading the source code

    • @venom0.543
      @venom0.543 3 ปีที่แล้ว

      From my view you are great at both source codes analysis and pentesting .if you have time, make a video how you approach a target it would be a great help for noobies like me 😂

  • @subhashxd9895
    @subhashxd9895 4 ปีที่แล้ว +1

    wow great

  • @xs8104
    @xs8104 ปีที่แล้ว

    I am gonna assume that you have tried and realized that nosql injection isn't possible

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  ปีที่แล้ว +1

      what makes you think nosql injection was present? just the sheer fact they use a nosql database?

    • @xs8104
      @xs8104 ปีที่แล้ว

      I thought the client_id parameter's value will be part of request to mongodb. Will it not?

    • @xs8104
      @xs8104 ปีที่แล้ว

      Sorry if i appeared unfriendly and I appreciate your eloquent videos

  • @devtavmakadiya9510
    @devtavmakadiya9510 3 ปีที่แล้ว

    hyy bro i want to exploit graphql ?? any idea how?

  • @fuzzme9381
    @fuzzme9381 4 ปีที่แล้ว

    Hi, can you add english subtitle ? Thanks

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  4 ปีที่แล้ว

      hi, I honestly don't know why YT add auto-generated subtitles to some of my videos and not to others. For now, I have to rely on that. Maybe with time, I will hire someone to add subtitles to my videos.

    • @fuzzme9381
      @fuzzme9381 4 ปีที่แล้ว

      @@BugBountyReportsExplained OK thanks you

  • @mrayoub5564
    @mrayoub5564 4 ปีที่แล้ว

    It's complicated

  • @Hackedpw
    @Hackedpw 4 ปีที่แล้ว

    Ok

  • @meczykowo7378
    @meczykowo7378 4 ปีที่แล้ว

    Po polsku nie możesz?

  • @AjayKumar-xl4jc
    @AjayKumar-xl4jc 4 ปีที่แล้ว

    /super $