Easy IDOR hunting with Autorize? (GIVEAWAY)

Поделиться
HTML-код
  • Опубликовано: 26 окт 2024

Комментарии • 261

  • @dhruvkandpal9909
    @dhruvkandpal9909 2 года назад +6

    Great video, Katie! Loved it as always.
    My favourite bug bounty tools are burp suite, all tomnomnom's tools, amass and the ones I developed on my own! (LazyFuzzZ, Wordlist Weaver, Fu-JS) #bbhammer

  • @link-ed
    @link-ed 2 года назад +2

    Thanks for the video! The tool that I use the most is fuff, cause of it's speed and simplicity. Burp is another indispensable tool as well! #bbhammer

  • @gf32768
    @gf32768 2 года назад +3

    Awesome video, as always!
    Favourite tool - Burp Suite - even if the only features it had were the proxy history and Repeater, it'd still be amazing.
    ##bbhammer

  • @Vinayak123-q8p
    @Vinayak123-q8p 2 года назад

    amazing, this could be probably one of the biggest information that i have ever been given

  • @arrheniusangipaelongan8693
    @arrheniusangipaelongan8693 2 года назад +5

    Thanks for all your videos Katie!❤ I got my first bug from your IDOR video. My favorite tool is burp! #bbhammer

  • @chitraa87
    @chitraa87 2 года назад +1

    Thanks for doing amazing video katie. My fav bug bounty tool is burp ofcourse. I'm looking forward more automation videos like this..#bbhammer

  • @rami1785
    @rami1785 2 года назад +1

    Thanks for all your videos Katie , My favorite tool is burp #bbhammer .

  • @brucezhang4967
    @brucezhang4967 2 года назад +3

    Thanks Kate! I want to know more about SSRF and businesss logic.#bountypls And my favourite bug bounty tool is absolutely BurpSuite!!! #bbhammer

  • @wingwing2683
    @wingwing2683 2 года назад +1

    Thanks so much sharing!

  • @CyberTron08
    @CyberTron08 2 года назад +5

    Thanks for doing so much for the community ❤️
    It'll be great to have more videos about DOM based vulnerabilities #bountypls

  • @sangeethaa5101
    @sangeethaa5101 2 года назад +2

    I want more videos explaining bugs with dem websites not just presentations. Thank You, Katie. #bountypls #bbhammer

  • @stablewater
    @stablewater Год назад +1

    Thanks for this great knowledge. I am currently learning IDOR and I've been able to use autorize and I got "enforced" in some areas. What next am I to do next. How do I exploit this for bug bounty?

  • @singularityfinale7680
    @singularityfinale7680 2 года назад +3

    You videos are both no bs info and free which is great for broke student like me. Well my favorite tool is Burpsuite #bbhammer
    And I think I will give Autorize a try.

  • @sekmekci
    @sekmekci 2 года назад

    Thanks for the video. Information part is starting at 3:49

  • @Death_User666
    @Death_User666 10 месяцев назад

    You are my favorite bug bounty channel

  • @webapplicationsecurity1853
    @webapplicationsecurity1853 2 года назад +1

    Thanks for the video, have been using this tool for a while now. This is my favourite tool: Autorize allows to check most of the access Logic tests. #bbhammer

  • @saite2560
    @saite2560 2 года назад

    nice video i've watched quite a few of em. clear well rehearsed script.. this video actually tries to show us something. well rounded video.
    i wish more of your videos showed us how to actually do this stuff like this video. you do great on the speaking side of teaching tho, need more hands on tho.

  • @vikasrushi3714
    @vikasrushi3714 2 года назад +1

    Thanks :) my favourite bug bounty tool are Amass and FFUF #bbhammer

  • @svrajput14
    @svrajput14 Год назад

    Really nice tip on how to use tool effectively !!

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 года назад +1

    Started learning following your recon videos. My go to tool for now is Burpsuite community edition. #bbhammer

  • @mayank-ir7tm
    @mayank-ir7tm 2 года назад +1

    My favourite bug bounty tool is ffuf combined with burp. I can bypass the speed limit of Intruder during fuzzing using -replay-proxy in ffuf which gives me the benifit of higher fuzzing speeds of ffuf and all the packets are captured in burp proxy too due to -replay-proxy flag set in ffuf.
    #bbhammer

  • @amitabhgupta21
    @amitabhgupta21 2 года назад +3

    Started following you Katie and I am blown by the content u and
    other fellow u tubers are providing by the way my favourite BB tools are - Burp Pro,Rustscan,amass and nuclei
    #Bbhammer

  • @ainter216
    @ainter216 2 года назад

    Thank you very much for the video! My favourite toos is Burp Suite, it is so powerful and you can do so many things. #bbhammer

  • @meletismichael2495
    @meletismichael2495 2 года назад +1

    You are precious for the community! pls go more in depth on chaining vulnerabilities! #bountypls

  • @p.k5016
    @p.k5016 2 года назад +1

    Thank you Katie for this amazing video. My favourite bug bounty tool is Burpsuite. #bbhammer

  • @iamkaustubh
    @iamkaustubh 2 года назад

    Wowww Thanks katie 🔥🔥🔥🔥it really encourages people more thanks for video

  • @syedbukhari4761
    @syedbukhari4761 2 года назад +2

    Great video Katie, my favourite tool is Amass & Wireshark; would love to see more videos on Business logic flaws & XXE flaws.
    #bountypls

  • @ndmath
    @ndmath 2 года назад +1

    Thank you Katie. I'd love to know more about Burp. #bountypls

  • @0xff1337
    @0xff1337 2 года назад

    why you're so late katie. i was waiting for this video for so long

  • @sadabesher2886
    @sadabesher2886 2 года назад

    Burp and ffuf is my favorite tool

  • @DieTeewurst
    @DieTeewurst 2 года назад +1

    Thank you for your great Videos! My favorite Bug bount tool is burp for sure! So much functionality in one tool! #bbhammer

  • @amandabarbosasobrinho5878
    @amandabarbosasobrinho5878 2 года назад +1

    Hey Katie, as always, awesome video! My favorite bug bounty tool is Burp, for sure! #bbhammer

  • @ksr608
    @ksr608 2 года назад +1

    Thank you for all your videos! My favourite tool is amass and burpsuite. #bbhammer. It'll be good to see more videos on subdomain takeover with an example. #bountypls

  • @sudokom
    @sudokom 2 года назад +1

    My favourite bugbounty tools are FFuF, Dirsearch, and Burpsuite with this extentions such as autorize #bbhammer

    • @sudokom
      @sudokom 2 года назад

      ... And also obsidian #bbhammer

  • @jarvis9092
    @jarvis9092 2 года назад +2

    Please never stop creating content like these😍..It would be helpfull if you would increase your volume as i felt the audio is lower than other youtube videos..My favourite tool is BurpSuite #bbhammer

  • @vanquisherstraveltube
    @vanquisherstraveltube 2 года назад +2

    You are really a great teacher.
    I am following your videos and learning a lot. Thank you so much!
    *Burp* is my favorite tool
    #bbhammer

  • @SergeantDaynes
    @SergeantDaynes 2 года назад +3

    Awesome video as usual. As for the types of bugs/hacking I want to learn about…SSRFs, broken access controls, business logic, and APIs! #bountypls

  • @mohammedsaneem4179
    @mohammedsaneem4179 2 года назад +2

    Great video as always. Would love to see videos based on chaining of bugs #bountypls

  • @asantoshkumarachary2692
    @asantoshkumarachary2692 Год назад

    Thanks for this video Katie

  • @RahulKumar-vy4lu
    @RahulKumar-vy4lu 2 года назад +2

    Great video as always. I would love to have more videos about XSS & chaining of bugs. #bountypls

  • @vivekkashyap7293
    @vivekkashyap7293 2 года назад +3

    My comment is keep deleting automatically??😭😭? Why #bbhammer
    stored css that was awesome moment and in September 2021 i got another credentials in API url by your api playlist
    Then in December 2021 i got IDOR by autorize 😅❤️❤️ (also i would like to see more idor,api etc videos some real live testing on idor,api also videos on career making in hacking how to easily get in bugcrowd,hackerone, integrity etc ) but similarly in all of these is they are not high bounties I'm trying to get good skills , so much thank you for this give away hanks to you and all bug Bounty mentors for sharing their skills with youngsters #bbhammer
    😅

  • @p3g4sus
    @p3g4sus 2 года назад +2

    I would love to see more videos on recon methadology for beginners . #bountypls

  • @champagnepete3386
    @champagnepete3386 2 года назад

    Great video, good resource!!

  • @sien1337
    @sien1337 2 года назад

    my favorite bb tool is Burp, you can just do so much with it! #bbhammer

  • @roxneil1974
    @roxneil1974 2 года назад

    katie, i'm new to bug hunter, i'm still practicing about the web security system, i have joined in ingriti but i don't know what i can and can't do when looking for bugs, can you give a little direction and tips on how to work in intigriti please,,

  • @papajohn2821
    @papajohn2821 2 года назад +2

    Mobile application security is what I am practicing for a month now. And videos on that topic will be great to learn from. #bountypls

  • @faique2995
    @faique2995 2 года назад +3

    Thank you for holding my hands and taking me to this level in cyber security, Be healthy and happy😁
    #bountypls

  • @VincentOldMark
    @VincentOldMark 2 года назад +1

    My favourite tool is of course burp suite #bbhammer You are great Katie!

  • @tharunbaalaji8306
    @tharunbaalaji8306 2 года назад +1

    I like to see more vedios on business logic bugs , like taking a public program and understanding the business logic of the functionalities.#bbhammer #bountypls

  • @IrfanAli-vp5mh
    @IrfanAli-vp5mh 2 года назад

    Next video idea suggestion: Burp autorepeater

  • @gauravdeore9477
    @gauravdeore9477 2 года назад +1

    #bbhammer
    According to me burpsuite repeater is the best tool for hacking. We can perform any attack with it.

  • @Silly_lilly926
    @Silly_lilly926 2 года назад +1

    Thanks Kate ❤️ for this giveaway I'm so inspired by you and Aditi Singh and my favourite tool is FFUF love data exposed ❤️ #bbhammer

  • @ronny_xavier
    @ronny_xavier 2 года назад

    Thanks as always Katie. My fav tool is Burp definitely. #bbhammer

  • @darshannn10
    @darshannn10 2 года назад

    Fav bug bounty tools - Burp, amass, nuclei, ffuf #bbhammer

  • @andymarty80
    @andymarty80 2 года назад

    I'd like to see videos on Anti-CSRF bypass, 2FA/MFA bypass or prediction.

  • @deepeshrane8412
    @deepeshrane8412 2 года назад

    Awesome video, I love to use Amass and burp suite!! #bbhammer

  • @DevilAlpacca
    @DevilAlpacca 2 года назад

    Awesome, will definitely use the burp addon. Fav tool #bbhammer #bountypls

  • @kavishshah1988
    @kavishshah1988 2 года назад

    Have only used Burp suite till now so I guess that's my favourite tool as of yet #bbhammer

  • @TheConstantLearnerGuy
    @TheConstantLearnerGuy 2 года назад

    Thank you for the video

  • @morphsec
    @morphsec 2 года назад +1

    Subdomain takeovers would be nice, saw a lot of good reports but never seemed to fully understand them. #bountypls
    Burp and Amass is the bread and butter for me. #bbhammer

  • @TechRideGamer
    @TechRideGamer 2 года назад

    Thanks for this one its more than awesome.
    By favourite tool is Amass, fuff and in extensions autorepeater & Param Miner this are lit. #bbhammer

  • @shameeluddin3563
    @shameeluddin3563 2 года назад

    Just found your channel searching for cybersec stuff.
    My favorite tool so far is burp.
    #bbhammer

  • @Diddy81
    @Diddy81 2 года назад

    My favorite BugBounty tool has to be Burp Suite #bbhammer

  • @maapi
    @maapi 4 месяца назад

    I'm having an issue with autorize picking up requests that should be out of scope. Anyone else have this issue? This leads to a lot of extra requests to parse through, which really slows me down

  • @eraedith696
    @eraedith696 2 года назад

    Fav tool is Burpsuite because it has some automation and also manual testing which is good and it's also beginner friendly tool and many more to learn.... Thank you❤
    #bbhammer

  • @gk_eth
    @gk_eth 2 года назад

    Mostly there r auth bearer token for APIs which also needs to be add in cookies section?

  • @subhadipnag6028
    @subhadipnag6028 2 года назад

    Your video is really awesome :)
    Always love for Burp Suite tool for damn sure !! #bbhammer

  • @italoamaya8230
    @italoamaya8230 2 года назад

    thank you so much

  • @pr0xy_
    @pr0xy_ 2 года назад

    my favorite bug bounty tools are amass and burp suite. #bbhammer

  • @tomj1883
    @tomj1883 2 года назад

    Thanks for the videos!!! My favorite tool is burp for sure #bbhammer

  • @kovanbakr
    @kovanbakr 2 года назад

    thankyou,
    My favourite bug bounty tool is Burpsuite. #bbhammer

  • @gonzalogermano2312
    @gonzalogermano2312 2 года назад

    Thanks Katie my favorite tools is burpsuite #bbhammer

  • @kbsavage77
    @kbsavage77 2 года назад

    Welcome back! I'd love to learn more about SSRF #bountypls

  • @jovensqueprosperam
    @jovensqueprosperam 2 года назад

    Thanks for this channel

  • @ambsambs2973
    @ambsambs2973 2 года назад +2

    It'll be good if we get videos on web cache related vulnerabilities also once again thanks for making good contents for the community! #bountypls

  • @ShaneCaldwell11C
    @ShaneCaldwell11C 2 года назад +1

    My favorite BugBounty tool is definitely Burp Suite! It's a monster. #bountypls

  • @tXambe
    @tXambe 2 года назад

    Thanks very much for your videos and my favourite tool is burpsuite #bbhammer

  • @edoardottt
    @edoardottt 2 года назад +1

    Burpsuite, nuclei, Cariddi, Gau, gxss, ffuf and google dorks #bbhammer

  • @mohammadisbah1458
    @mohammadisbah1458 Год назад

    @Inderderphd
    Have you find idor vulnerability which leads to privilege escalation? Could you please tell me the scenario.

    • @InsiderPhD
      @InsiderPhD  Год назад

      Usually it's permission related - create mutliple accounts with different permission levels, and try and do an admin action as a regular user

  • @kevohvokeh-n6f
    @kevohvokeh-n6f Год назад

    Burpsuite is my fav

  • @mooreprr8067
    @mooreprr8067 2 года назад

    Favorite tools are Burp, Amass, All of Tomnomnom's Tools ,Cariddi #bbhammer

  • @don-ce8ig
    @don-ce8ig 2 года назад

    Thanks for making content! My favourite bug bounty tool is burpsuite #bbhammer

  • @adamkimbro
    @adamkimbro 2 года назад

    #bbhammer My favorite tool burp. Thanks for your videos!!!

  • @fatihburaktoprak769
    @fatihburaktoprak769 2 года назад

    My favorite is always Burp Suite! #bbhammer

  • @sandiyochristan
    @sandiyochristan 2 года назад

    Thanks Kate ❤ for this giveaway I'm so inspired by you #bountypls #bbhammer

  • @tommydave2908
    @tommydave2908 2 года назад

    I'd like to learn more about SSRFs, and maybe web cache poisoning, sounds cool. #bountypls

  • @devangsolanki4622
    @devangsolanki4622 2 года назад

    Thank you for the giveaway!!
    My favourite tool is burpsuite! because Its so simple and powerfull. #bbhammer

  • @matthewhowes6270
    @matthewhowes6270 2 года назад

    Burp,Ffuf, Nuclei, Aquatone and Nmap
    #betterlatethannever
    #bbhammer

  • @pushpinderkaur6570
    @pushpinderkaur6570 2 года назад

    Thank you for this video. I would love to know more about cloud security esp AWS. #bountypls

  • @user-ov2ll4vc7j
    @user-ov2ll4vc7j 2 года назад

    Katie thanks for the video. I would like to learn more about hacking APIs. #bbhammer

  • @RahulKumar-vy4lu
    @RahulKumar-vy4lu 2 года назад

    My go-to was always Burpsuite. #bbhammer

  • @bonenaing333
    @bonenaing333 2 года назад

    Thanks for sharing. Burpsuite of course i am just the beginner #bbhammer

  • @saminbinhumayun858
    @saminbinhumayun858 10 месяцев назад

    do we get Cookies from the admin account or the low-privileged account?

    • @InsiderPhD
      @InsiderPhD  10 месяцев назад +1

      Low privileged account always! Your low privileged is always your attacker

  • @tajsec498
    @tajsec498 2 года назад

    my favorite tool is burp suite, nmap :)) thanks for great contents
    #bbhammer

  • @sudarshsaraswathula1401
    @sudarshsaraswathula1401 2 года назад

    Thanks a lot for the vid. My favourite tool is ffuf #bbhammer

  • @old2235
    @old2235 2 года назад

    My favourite bugbounty tool is still Burpsuite #bbhammer

  • @tommydave2908
    @tommydave2908 2 года назад

    My favorite bug bounty tool is most definitely burp #bbhammer

  • @shamim_12
    @shamim_12 2 года назад

    Well my favorites are FFUF and Dirsearch #bbhammer

  • @svg98
    @svg98 2 года назад

    My favorite tool is your channel (and Burpsuite) #bbhammer

  • @fng2971
    @fng2971 2 года назад

    Thanks for the video, my favorite tools are burp & amass #bbhammer