Learn Bug Bounty Hunting with These Resources!

แชร์
ฝัง
  • เผยแพร่เมื่อ 20 ธ.ค. 2024

ความคิดเห็น • 60

  • @muhammadnomanilyas7920
    @muhammadnomanilyas7920 หลายเดือนก่อน +1

    I feel alot motivated when i see your vids , Thanks Katie!.

  • @flavioferlin3127
    @flavioferlin3127 5 หลายเดือนก่อน

    Howdy to all. Dear Katie, bless your heart. Thank you, kudos.

  • @linuxluminary
    @linuxluminary 4 หลายเดือนก่อน +1

    Thank you so much for the motivation, I started bug hunting on bugcrowd in July and so far I have reported over 15 bugs and all of them got either duplicate or information or not applicable. I am watching your videos to get motivated 😉😉😉

    • @serhanesaidi3140
      @serhanesaidi3140 2 หลายเดือนก่อน

      kudos to you cheer up i belive in you

    • @linuxluminary
      @linuxluminary 2 หลายเดือนก่อน

      @@serhanesaidi3140 thanks dear! Really it means a lot 💕💕

    • @InsiderPhD
      @InsiderPhD  2 หลายเดือนก่อน +1

      Dupes are GOOD - that means you're finding the right stuff BUT you're just not fast enough, that's when you've gotta play the bb meta of finding new scope before other people, recon helps a lot with that.
      Informational/not applicable is super dependent on the client, it's usually a risk they're happy to accept not necessarily that you haven't found an issue. Keep on it there are so many people out there who haven't even been brave enough to report a single bug, you're smashing it compared to them.

  • @asuhayda1
    @asuhayda1 6 หลายเดือนก่อน

    I really appreciate your point of view on this topic. I'm just getting started learning cybersecurity and found your video to be super helpful. Thanks!

  • @jemimaho.4827
    @jemimaho.4827 23 วันที่ผ่านมา

    Thank you so much for making this! Super useful.

  • @M3dU5aXX_Ray_Tierney
    @M3dU5aXX_Ray_Tierney 5 หลายเดือนก่อน

    Katie, you are a life saver!!! I could not wrap my brain around these for college exam!!❤🎉

  • @L30x408
    @L30x408 2 หลายเดือนก่อน

    Your content is gold thanks!!!!

  • @Aditya_khedekar
    @Aditya_khedekar ปีที่แล้ว +2

    was waiting for your video from so long

  • @Meimei025
    @Meimei025 ปีที่แล้ว

    So powerful insight, thanks sister ^^

  • @alexandersoltesz8103
    @alexandersoltesz8103 ปีที่แล้ว +2

    Awesome, thank you so much! As for the tools, I've been debating if I should stick to burp or give a shot to Caido. I tried it out and fell in love with it, so clean, well structured and works great with Postman which is really effective for api hacking, so it's reassuring to hear other people are excited for it and its further developments too!

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว +1

      Rhynorator is a big fan too especially because it works on his Chromebook!

  • @damiencalloway
    @damiencalloway ปีที่แล้ว +2

    Was there meant to be a link in the description? I cannot find it, can you please provide the link to the blog post?

  • @harpocrat3s
    @harpocrat3s ปีที่แล้ว

    Great video, thanks for the useful information

  • @dub161
    @dub161 10 หลายเดือนก่อน +1

    Can you make a video on bug bounty setup? I have concern regarding IP ban and stuff.

    • @InsiderPhD
      @InsiderPhD  10 หลายเดือนก่อน +1

      I wouldn’t worry as long as you aren’t constantly hitting a server with payloads you won’t get an IP ban

  • @sergeantosiris
    @sergeantosiris ปีที่แล้ว

    Great pointers as always!

  • @asynciome6737
    @asynciome6737 10 หลายเดือนก่อน

    Your videos are amazing I learned so much and man idk what to say anywhere I can donate? ❤

    • @InsiderPhD
      @InsiderPhD  10 หลายเดือนก่อน

      You can but don’t worry about it :) the best thing you can do is sign up for a Bugcrowd account and start hacking ;)

  • @walle1st
    @walle1st ปีที่แล้ว +1

    Hi Katie, what courses would you recommend for the recon and burpsuite phases?

  • @taiwomiracleveecthor2617
    @taiwomiracleveecthor2617 ปีที่แล้ว

    Thank you so much Ma

  • @eyephpmyadmin6988
    @eyephpmyadmin6988 ปีที่แล้ว +1

    My first "hack" was the most by the textbook CTF style almost like the developer just wanted it hacked, it was my school counties website (that they scrapped but kept online) had a search box with sqli and unhashed passwords and everyone used the same password for the super expensive golden door login site they had. I was 15 and got super popular bc of it but I wasnt even proud of myself for it was too easy. Yes I got arrested (not charged as adult thank God) 120 community service, two weeks juve, nothing that connects to Internet for year(like they could enforce that😂) I deleted everyones absents made people pass classes and it was the last month of school

  • @vipinsharma1984
    @vipinsharma1984 ปีที่แล้ว

    Great..very useful!

  • @Alexander007A
    @Alexander007A ปีที่แล้ว +1

    Hello KATIE thank you for your all helpful videos i learned so much from them and its very good for a beginners like me
    you also teach us how to stick to them and keep our passion for it . but i learn idor and how its works but i didn't know where i can found and how i chose a website for idor can you explain us plz

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว +2

      I’m actually going to do a livestream with Bugcrowd soon but any time you can see an ID as a number or a UUID (/resource/1, post=1) you wanna be checking for IDORs Tumblr is a great program to start with

    • @Alexander007A
      @Alexander007A ปีที่แล้ว

      @@InsiderPhD yes .. I understand these concept from your lectures and as well as web security academy labes now I just want land hands on practice.. please help me

    • @Alexander007A
      @Alexander007A ปีที่แล้ว

      @@InsiderPhD where I can find website to Scan?? Hacker one?

  • @asuhayda1
    @asuhayda1 6 หลายเดือนก่อน

    You mentioned putting several links in the description but there aren't any there.

  • @sudani0zak
    @sudani0zak ปีที่แล้ว

    Thanks 😊

  • @mr__whale
    @mr__whale 3 หลายเดือนก่อน

    Awesome

  • @rahmat_qurishi
    @rahmat_qurishi ปีที่แล้ว

    You are the best❤😊

  • @lawlietchang2556
    @lawlietchang2556 ปีที่แล้ว

    thank prof.

  • @arnd12940
    @arnd12940 ปีที่แล้ว

    Amazing

  • @maremeaxi3344
    @maremeaxi3344 ปีที่แล้ว

    great!

  • @birbalkumar3040
    @birbalkumar3040 ปีที่แล้ว

    Sir own cryptocurrency mining ke liya language pat hai par start kaha se kare code🤔🤔

  • @MJ-vx5cz
    @MJ-vx5cz ปีที่แล้ว

    Hey thank you for the good work ❤
    I am trying to to jump in to bug bounty
    I tried to test an api of an app but I can't figure out how too see the api end points the app when i change the proxy of the wifi the app refuses to work I tried to install it in android simulator but they have some kind of security that will not allow you to install in simulator

    • @MJ-vx5cz
      @MJ-vx5cz ปีที่แล้ว

      Any advice?

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว +2

      I have some videos on this, but it’s usually because you need to break the ssl the app is using, the most reliable way is to use another tool called Frida use this scrip t codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida/ with this tutorial infosecwriteups.com/hail-frida-the-universal-ssl-pinning-bypass-for-android-e9e1d733d29?gi=642ecc6dad06

    • @MJ-vx5cz
      @MJ-vx5cz ปีที่แล้ว

      @@InsiderPhD thank you 🙏

  • @mfinixone1417
    @mfinixone1417 ปีที่แล้ว +4

    My problem is that I have to stop learning and start hacking

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว +2

      You can make the jump, just try and explore the next bug bounty programme you see, just try and map out in your notes which requests power which functionality and what kind of bugs you might want to look for :)

  • @manan5
    @manan5 ปีที่แล้ว +1

    hey wheres the blog post link?

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว +3

      Didn’t get released in time :( should have it out before the weekend

  • @lowkeylyesmith
    @lowkeylyesmith ปีที่แล้ว

    Hi,
    I have a question that is very close to my heart.
    You have extremely much knowledge and also show a lot in your videos, but I'm just despairing. I really want to get into the Bug Bounty Hunter business as a side job, but I have no idea where and what to start.
    It kills me that I am apparently too stupid for it. I work as an IT forensics engineer in a government agency, before that I worked as a software engineer for a large food company in Austria, I have an IT technician and computer scientist degree, I graduated as a data scientist and business analyst, I had several trainings in databases and C# etc ... and am now too stupid to start as a Bug Bounty Hunter.
    I would like to ask you for advice and tell me what I am doing wrong or what other courses I should take. In the meantime I have several Udemy courses, got the APIsec University course, ... I am at the end of my rope.
    Sorry to bother you with this, but I didn't know what else to do.
    Thanks and best regards from Austria
    René

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว +2

      You're probably not too stupid to do anything, you already have a successful career - that's proof enough. You have a whole DEGREE that has taught you SO much about how to approach problems. When you started programming what improved your programming the most? Was it course after course showing you the basics of how objects work? NO IT WAS ACTUALLY PROGRAMMING.
      Stop taking courses and actually start hacking, look at websites, understand how they're built and what goes into an action like logging in to a website. Don't just spam payloads but think about the type of security constraints an application has implemented and how you might bypass them. Focus on training yourself to think like a hacker, you're looking at a black box, what's on the other side? You have a BIG advantage with your skillset! Don't expect a bug in your first 10 hours of looking at a real client, just explore the website, break down features into each request/response you need. Think about how what kind of security measures should be in place, if you were implementing it how would you do it? What mistakes would a junior make?

  • @Mark_1991_1
    @Mark_1991_1 ปีที่แล้ว

    Sound

  • @bertrandfossung1216
    @bertrandfossung1216 ปีที่แล้ว

    First to comment 🎉

  • @itsm3dud39
    @itsm3dud39 ปีที่แล้ว +1

    cybermentor dont do bug hunting

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว

      No but they're making a lot of API security videos at the moment!

  • @riteshraiharikarai3441
    @riteshraiharikarai3441 ปีที่แล้ว

    Hello mam,
    How are you?
    Mam I also want to do bug bounty and ethical hacking.
    Can you guide me the road map and suggest some books?
    Mam I am unable to create effective virus +malicious with python.
    How can I solve it?

  • @TylerDurden-dd1tq
    @TylerDurden-dd1tq ปีที่แล้ว

    You are absolutely wasting your time if you are bug bounty hunting for money instead of curiosity or passion.

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว

      Agreed, I think anyone looking for a quick buck is going to be disappointed

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked ปีที่แล้ว

    Early. :3

  • @ANiME_LoVE3r
    @ANiME_LoVE3r ปีที่แล้ว +1

    Thank you a lot
    How can I dm you?

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว +1

      Yup on Twitter or my email is on my website :)

  • @agapic445
    @agapic445 ปีที่แล้ว

    Hi i really want to contact you to tell you something just because i feel it might brighten your day in the future, basically i want to share a story of mine i am not even interested in getting a reply or a feedback just i want to tell you so later on i can give an update that hopefully it makes you understand more how are people like you are significant to the community
    is there anyway please? ( i don't trust telling it publicly)

    • @InsiderPhD
      @InsiderPhD  ปีที่แล้ว

      Katie@insiderphd.dev