An IDOR Vulnerability on INSTAGRAM! 49500$ Rewarded!

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • Get 10,000 free mins to build mobile and web app: bit.ly/3uuotSV
    Learn more about ZEGOCLOUD API & SDK: bit.ly/3Fy5HAm
    How to build iOS, Android and Web app: bit.ly/3hf7xfX
    Check out my FREE course on SQL Injection for Beginners with hands-on training and completion certificate: bit.ly/3MTMQ2Q
    Neeraj Sharma's writeup: infosecwriteup...
    Neeraj Sharma, a 20-year-old Security Enthusiast from India has discovered a critical IDOR (Insecure Direct Object References) vulnerability on Instagram which allowed an attacker to change the thumbnail of any instagram reel without any authorization!
    Facebook offered him 49500$ for reporting this bug and also added him to the Hall Of Fame.
    Facebook's Bug Bounty Hall of Fame: / thanks
    Thanks for watching!
    SUBSCRIBE for more videos!
    Join my Discord: / discord
    Follow me on Instagram: / teja.techraj
    Website: techraj156.com​​​​​
    Blog: blog.techraj15...
  • НаукаНаука

Комментарии • 107

  • @TechRaj156
    @TechRaj156  2 года назад +6

    Check out my FREE course on SQL Injection for Beginners, you also get a completion certificate: bit.ly/3MTMQ2Q

  • @24host99
    @24host99 2 года назад +45

    That bounty hunt was so rewardable

  • @Jay-gf4pt
    @Jay-gf4pt 2 года назад +56

    Your explanation was perfect, thanks for the video

  • @mangakadomingos292
    @mangakadomingos292 2 года назад +14

    I like the way you explain, clear as clean water, keep it up.

  • @imkir4n
    @imkir4n 2 года назад +15

    perfect explanation and awesome finding!!

  • @adarshverma3372
    @adarshverma3372 2 года назад +7

    That’s why all your action should be user centric in the backend

  • @rakno12
    @rakno12 2 года назад +32

    Damn...that looked so simple!!!

  • @dimlight1172
    @dimlight1172 2 года назад +9

    Thanks for the explanation brother!! Got to learn many new stuff.

  • @nadakuditigopikrishna6587
    @nadakuditigopikrishna6587 Год назад +4

    Thank you bro! you explained very well. your presentation skills are awesome.

  • @rakeshpanchal8007
    @rakeshpanchal8007 2 года назад +5

    Your explanation was perfect, thanks for the video bro

  • @Child0ne
    @Child0ne 2 года назад +2

    Your channel is coming a lot good bro

  • @noorjay1363
    @noorjay1363 2 года назад +1

    Crazy.. I never think that thumbnail can be hacked.

  • @_Thomas_Shelby_
    @_Thomas_Shelby_ 2 года назад +1

    yesterday loi has posted it full form :-Insecure direct object reference

  • @grahampawar
    @grahampawar 2 года назад +7

    Please bring more such examples 🙏🧑‍💻

  • @d-balldragonballs4901
    @d-balldragonballs4901 2 года назад +4

    Can you please explain..how did you bypass ssl pinning in genny.....

  • @jaisaljaisu8332
    @jaisaljaisu8332 2 года назад +1

    mahn , appreciate your work .. thanks for this :)

  • @Shadow-xi2sv
    @Shadow-xi2sv Год назад +1

    Really nice explanation! Thanks!

  • @0RIPPER0
    @0RIPPER0 2 года назад +5

    Lol 🤣 Beluga is hacked ... Now his Hecker friend will come to save his ass..

  • @nafeeskhan007
    @nafeeskhan007 2 года назад +3

    Nice detail explanation 👌 👍 thumb up. Keep it up 👍

  • @itsmmdoha
    @itsmmdoha 2 года назад +2

    Damn!
    Great video 🔥

  • @badmashito4059
    @badmashito4059 2 года назад +3

    Damn it was a awesome finding !!

  • @davbj7707
    @davbj7707 2 года назад

    Great vid man

  • @hridaybhatia5643
    @hridaybhatia5643 2 года назад +1

    Superb video sir loved it 😍😍

  • @saleemahmed8302
    @saleemahmed8302 4 месяца назад

    Wonderfully explained. Thanks a lot.

  • @Riborwahz
    @Riborwahz 2 года назад +3

    Who else not indian but Indian
    Well not the small letter i 😂

  • @paritoshkumar4465
    @paritoshkumar4465 2 года назад +25

    Bro why don't you start a complete course of coding from beginning to expert level.
    Ex- coding + connectivity to database related video.
    I know coding then what to learn after coding i don't know
    That make hoch poch in my brain.

  • @ItzHerobrine
    @ItzHerobrine 2 года назад

    I love how the comment section has no bots

  • @photographymaniac2529
    @photographymaniac2529 2 года назад +1

    Awesome find definitely

  • @imvjsai
    @imvjsai 2 года назад

    Good one Anna. Keep going

  • @JohnPaulBuce
    @JohnPaulBuce 2 года назад +1

    trolling session

  • @IDontModWTFz
    @IDontModWTFz 2 года назад +1

    I wonder what other sites are vulnerable to this attack?

  • @robot67799
    @robot67799 2 года назад

    Woah! It's so cool!

  • @shivajivarma
    @shivajivarma 2 года назад +1

    Hi @Tech taj what is your mic setup? Can you share amazon link for it?
    FYI. Looks like your website is down. Its showing WIZ service error.

  • @hackersvision2811
    @hackersvision2811 2 года назад +5

    My mentor is here again with another motivating hacking video ✌️✌️

  • @OthmanAlikhan
    @OthmanAlikhan 2 года назад

    Thanks for the video =)

  • @GameWithSNAKE
    @GameWithSNAKE 2 года назад +2

    New subscriber ❤️

  • @AskLichy
    @AskLichy 2 года назад

    M ardam kale but video motham chusa.... ❤️

  • @_AayushKumar
    @_AayushKumar 2 года назад

    Great. Explanation

  • @didyouknowamazingfacts2790
    @didyouknowamazingfacts2790 3 месяца назад

    I'm a little confused by the difference between a BOLA and IDOR vulnerability?

  • @vinothn4228
    @vinothn4228 2 года назад

    Cool mannnn😍

  • @Yash15361
    @Yash15361 10 месяцев назад

    love your content :}

  • @nyctophilialone
    @nyctophilialone 2 года назад

    So this vulnerability doesn't work now, right?

  • @funfillers249
    @funfillers249 2 года назад +2

    Is it's patched?

  • @ncr.jat.samaaj
    @ncr.jat.samaaj 10 месяцев назад +1

    billo bagge bagge bilya da ki kregi bagge bagge bilya da ki kregi " kuch nahi kregi bhai bass bounty dilvayegi 😂"

  • @niravchauhan2278
    @niravchauhan2278 2 года назад

    Subscribed✌️

  • @acousticamar8109
    @acousticamar8109 2 года назад

    Moral:- Bug Kahi Bhi Ho Sakta Hai 🥲

  • @rigbyb
    @rigbyb 2 года назад

    good video thank you

  • @zeeshandil2917
    @zeeshandil2917 2 года назад

    so easy and so powerful

  • @dhanushariah5330
    @dhanushariah5330 2 года назад

    More such videos bud!

  • @surendarmurthi551
    @surendarmurthi551 2 года назад

    Bro neenga dhan unlucky bug hunter channel host ah

  • @bisen6475
    @bisen6475 2 года назад

    Beluga👀

  • @praveenkurup8894
    @praveenkurup8894 2 года назад

    Please make A video to access server with shodan

  • @TechnicalRex
    @TechnicalRex 2 года назад

    Awesome

  • @zedvn3792
    @zedvn3792 6 месяцев назад

    Could you please tell me how to use burpsuite in the android emulator like in the exploit video ?

  • @belharra5756
    @belharra5756 2 года назад

    Lets say i am hunting for price manipulation idor but the request is encrypted with % any way to decore it ?

  • @mixwood1130
    @mixwood1130 2 года назад

    Is it possible to reproduce the vulnerability?

  • @helloworld4402
    @helloworld4402 2 года назад

    Make more videos like this

  • @raphaelziade5422
    @raphaelziade5422 10 месяцев назад

    Hi, what the name of that Phone sim that he used...?

  • @yuuki-1829
    @yuuki-1829 2 года назад

    Fixed?

  • @remy2885
    @remy2885 2 года назад

    Raj i really appreciate ur videos very clear and interesting, could u make a vid about evilnginx2? i think it would be great to learn about it for alot of people.

  • @vrushabhpatil2867
    @vrushabhpatil2867 2 года назад

    Well r u studying right now or doing some cybersecurity job

  • @magenta8979
    @magenta8979 2 года назад

    Dark market probably 100k$

  • @harshzala7019
    @harshzala7019 2 года назад

    Can we try now

  • @MalikRabichon
    @MalikRabichon Год назад

    i don't trust on the bug bounty program , the rewards are not two much !

  • @rivu____2329
    @rivu____2329 2 года назад

    Can this Practice can we do after this?

  • @unknown_3293
    @unknown_3293 Год назад

    awsome prank to people

  • @chupkaryaar1677
    @chupkaryaar1677 2 года назад

    damn! copy of network chuck btw loved your videos

  • @akhilv3487
    @akhilv3487 2 года назад

    More videos plz

  • @thewolf-ps1qz
    @thewolf-ps1qz 2 года назад

    poor beluga account 🥺🙏

  • @igu642
    @igu642 9 месяцев назад

    ❤❤

  • @rishabhrana3773
    @rishabhrana3773 2 года назад

    I know him

  • @proxy5061
    @proxy5061 2 года назад

    37lakhs ✌️✌️

  • @latesthitstch9428
    @latesthitstch9428 2 года назад

    Wow

  • @lesleybw
    @lesleybw 2 года назад

    🤯

  • @aashita6850
    @aashita6850 2 года назад +1

    Woaaaaaah! How does something like this even hits in the mind?

    • @BlueEdgeTechno
      @BlueEdgeTechno 2 года назад +3

      It doesn't, they try a bunch of different methods until something seems odd.

    • @aashita6850
      @aashita6850 2 года назад +2

      @@BlueEdgeTechno Ah! I guess Patience is the key!!

  • @ft.Atulkumarsingh
    @ft.Atulkumarsingh 2 года назад

    Some websites has listed amount to 4500USD??

    • @adityamehra4412
      @adityamehra4412 2 года назад

      No its 49500USD

    • @adityamehra4412
      @adityamehra4412 2 года назад +1

      i know because he is my friend

    • @nitinkumarsaini....
      @nitinkumarsaini.... 2 года назад

      @@adityamehra4412 o really , you are also hacker

    • @ft.Atulkumarsingh
      @ft.Atulkumarsingh 2 года назад

      @@adityamehra4412 okay, I was confused that some websites are saying 49k and some are 4500 thanks for conformation.

    • @ft.Atulkumarsingh
      @ft.Atulkumarsingh 2 года назад +2

      @@adityamehra4412 tell him congrats from me.

  • @ClashWithHuzefa
    @ClashWithHuzefa 2 года назад

    😎

  • @jeanandre3651
    @jeanandre3651 2 года назад

    wtf 🤯

  • @itscorneveryday6344
    @itscorneveryday6344 2 года назад +1

    Bro i did report 4 Idor's but haven't got response it's been 24 hours for the first Idor..
    are they gonna response me or not?
    it says it is private and only participants can view it...
    when they gonna response me please answer...

  • @utensilapparatus8692
    @utensilapparatus8692 2 года назад

    1337

  • @passiveearner726
    @passiveearner726 2 года назад

    Second

  • @PepesCashino
    @PepesCashino 2 года назад

    He sound like an indian scammer

  • @pinkpantherkidsofficial9058
    @pinkpantherkidsofficial9058 2 года назад

    Your explanation was not good no thanks for the video

  • @savagegirl9357
    @savagegirl9357 2 года назад

    First

  • @akshaychordia8724
    @akshaychordia8724 2 года назад

    Hi @Beluga