$0 👉🏼 $1,000/Month With Bug Bounties

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • Signup for Snyk's CTF today: snyk.co/nahamsecctf
    Hacking Full Time Blog Post:
    nahamsec.com/p...
    📚 Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training
    💵 Support the Channel:
    You can support the channel by becoming a member and get access exclusive content, behind the scenes, live hacking session and more!
    ☕️ Buy Me Coffee:
    www.buymeacoff...
    JOIN DISCORD:
    discordapp.com...
    🆓 🆓 🆓 $200 DigitalOcean Credit:
    m.do.co/c/3236...
    💬 Social Media
    - / nahamsec
    - / nahamsec
    - twitch.com/nah...
    - / nahamsec1
    #bugbounty #ethicalhacking #infosec #cybersecurity #redteam #webapp

Комментарии • 133

  • @shaunakkhosla3569
    @shaunakkhosla3569 10 месяцев назад +39

    where's the blog post where you talk about how to select a good BB target, also, would love to see a video on the automated method you briefly mentioned.

    • @NahamSec
      @NahamSec  10 месяцев назад +18

      Here you go! nahamsec.com/posts/hacking-full-time

    • @shaunakkhosla3569
      @shaunakkhosla3569 10 месяцев назад

      Thanks! you're a G@@NahamSec

  • @rdx8122
    @rdx8122 9 месяцев назад +29

    01:15 == Mindset
    - Through negativity out of the room when you are hunting, there are always bugs
    - Show some Impact on the company, No impact = no value of your bug
    - CTF approach
    04:20 == Approach
    07:34 == The right vehicle / Think before you pick a program
    09:58 == Collaboration is the key
    10:41 == Celebrate the Success / Enjoy the little moments
    Love you Nahamsec sir ! 🙌🙌💖💖

    • @Nohope__
      @Nohope__ 6 месяцев назад +1

      true true true true true

  • @ultrahdgood
    @ultrahdgood 7 месяцев назад +8

    00:04 Bug bounty hunting can change our lives and provide a new career path with significant financial opportunities.
    01:36 Approach bug bounty hunting with a positive attitude and focus on finding vulnerabilities.
    03:00 Bug bounty hunters have a relentless mindset and are always looking for solutions to problems
    04:28 Choosing between manual and automated bug hunting determines your approach
    05:53 Manual approach is recommended for new bug bounty hunters
    07:14 Choosing the right bug bounty program is crucial
    08:40 Use metrics to choose a good bug bounty program and consider the minimum bounty amount
    10:03 Collaborate with others to find more vulnerabilities and make more money together.

  • @vsulli
    @vsulli 10 месяцев назад +15

    I bet you've had feed back from noobs where ppl are frustrated that they are not finding vulns, but you should emphasize that ppl who have found a bug, written it up, submitted it to the bug program, and received a 'Duplicate,' should be praised for their progress.
    Think of all the skills that went into producing just the first report.
    > Recon
    > Training on what to look for
    > Mindset, CTF attitude of not giving up
    > Investigating the vagueness of information ( digging for diamonds in dirt) tuning your bounty senses
    > Hypothesis, investigation, and proof of concept
    > Writing a report.
    All of these things together need to be developed in concert in order to produce a report that could even qualify for a submission.
    Forget about the fact that in the end it turned out to be a "Duplicate," first time bug hunters should be proud that they are writing a turning in a report at all!!! 😍😍

    • @therelatableladka
      @therelatableladka 9 месяцев назад

      I feel motivated even though i haven't found one yet.

    • @dominusfalchion8020
      @dominusfalchion8020 6 месяцев назад

      @@therelatableladka Bro could we connect on discord

  • @brendan8665
    @brendan8665 10 месяцев назад +32

    1:50 | Looking For The Right Bugs (Mentality)
    4:21 | How Will You Look For Bugs? (Automated Approach)
    5:53 | (Manual Approach)
    7:32 | Picking the Right Bug Bounty Programs
    10:39 | Celebrate 🎉

  • @bxnny0374
    @bxnny0374 10 месяцев назад +12

    This is my goal. I've been studying so hard to reach it. Hope to find my first bug soon :)

    • @NahamSec
      @NahamSec  10 месяцев назад +4

      Best of luck!

    • @Moyocoyotzin700
      @Moyocoyotzin700 10 месяцев назад +1

      Can we be an accountable partners on bug bounty

    • @Moyocoyotzin700
      @Moyocoyotzin700 10 месяцев назад

      ​@@camelotenglishtuition6394
      Can we be accountable partners on bug bounty

    • @LearnTv-qy5xb
      @LearnTv-qy5xb 2 месяца назад

      @bxnny0374 did you find bug ?

  • @lucianjohr5569
    @lucianjohr5569 10 месяцев назад +4

    Thanks so so much Naham. Overwhelming for me as a beginner. But exciting and interesting. Thanks

  • @vsulli
    @vsulli 10 месяцев назад +3

    Nahamsec, regarding some hunters that are running a scan in the background and aggregating their data to find better vulnerabilities, can you talk you talk about how people setup systems that support their niche interests.
    It seems like we need to double down on the TTPs (tactics, techniques, procedures) that we are familiar with and learn how to leverage those interests when summing up the impact in our vulnerability reports.

  • @prospectchizororo5836
    @prospectchizororo5836 10 месяцев назад +42

    It seems simple as you're saying when you're saying it like this, but it's intimidating out there...

    • @helalsadat2077
      @helalsadat2077 4 месяца назад +1

      If it was easy everyone would be doing it

    • @anotherguy9402
      @anotherguy9402 4 месяца назад +3

      It's RUclips. He's the one making 1k a month from bug bounties but it actually from bug bounty vids RUclips ad revenue 😂

    • @edvandromauricio7353
      @edvandromauricio7353 4 месяца назад

      ​@@anotherguy9402 shut up bro 😂😂😂😂

  • @bayaspirinha
    @bayaspirinha 10 месяцев назад +2

    the more i learn, the more i realize i don't know anything, but it motivates me, so i dedicate more hours each day, i don't feel nowhere near ready to start doing bug bounty, but i know it will come.

    • @courier3567
      @courier3567 10 месяцев назад

      Eventually you'll be familiar with 100 things and you won't know how to use those things well but you'll know what they are after learning about 100 more things you'll start to realize how they work together and how you can chain the things you know together to get results it's a long process but each day it will get easier. The best thing you can do is just keep learning and really go deep look at other peoples comments and advice because it will really help you start making those connections in what you know and what to look for.

  • @user-sb3wm1xm7p
    @user-sb3wm1xm7p 9 месяцев назад +1

    You are one of the best, thnak you very much for all what you are offering to the comunity

  • @AnthonyMcqueen1987
    @AnthonyMcqueen1987 9 месяцев назад +1

    Large scopes is where the gold is and mix manual with automation that will make you a better hacker and focus on one vulnerability class at a time.

  • @chaospixxie
    @chaospixxie 10 месяцев назад +3

    Would love to see a video on using both manual and automated methods combined

    • @georgejones5019
      @georgejones5019 10 месяцев назад

      This. A combined or hybrid method, aggregating info to find higher value bugs.

  • @darthsidious3377
    @darthsidious3377 10 месяцев назад +1

    hey Ben i would like to see both aproaches in order to be able to adapt to every single situation possible

  • @Gamer-zo2dm
    @Gamer-zo2dm 10 месяцев назад +7

    We're waiting the manual vs automated video ❤❤

    • @NahamSec
      @NahamSec  10 месяцев назад +4

      Soon :)

  • @Hruthwik
    @Hruthwik 10 месяцев назад +2

    MANUAL APPRAOCH VIDEO NEEDED ASAP , THANKS

  • @haroonrehman8156
    @haroonrehman8156 7 месяцев назад

    7:18 YES we want to hear from you about this, If you have made a video please update description, comment section and the, I Button (recommendation/suggestion etc).

  • @castillorafi
    @castillorafi 10 месяцев назад

    honestly we can't choose between those two. So please please please do both, and if it's possible add a third video showing how you can mixte the two of them. thank you.

  • @adyp487
    @adyp487 10 месяцев назад +3

    You're a true inspiration, Ben! ❤

  • @shriyanssudhi4545
    @shriyanssudhi4545 10 месяцев назад +4

    Though automation is good, but I made more with manual

  • @Piyush-rz8kd
    @Piyush-rz8kd 10 месяцев назад

    Awesome video my mentor ❤❤🎉🎉

  • @christiangl6610
    @christiangl6610 10 месяцев назад +2

    I hope someday i'll be commenting here again celebrating my very first bounty.

  • @derciogulele8682
    @derciogulele8682 10 месяцев назад

    It is really great man. Don't get tired of us. We are working hard to get there...
    btw...what chair are you using? Maybe that can be a starting point lol

  • @yamizaki7
    @yamizaki7 7 месяцев назад

    I definitely want to hear more about combining automation with manual hacking.

  • @thatcyberlad
    @thatcyberlad 9 месяцев назад

    Thank you so much for an awesome video..!!

  • @loneliestwolf4228
    @loneliestwolf4228 10 месяцев назад +3

    Eagerly waiting for nahamsec to release his new membership video on hacking a target

  • @hussainmakda6143
    @hussainmakda6143 10 месяцев назад

    In next video please give us more information about both manual and automated approach and if possible please tell some tools for both approach which are used commonly, and one more thing you are creating great videos hacking and bug bounty programs , thank you for sharing great contents

  • @Mark71697
    @Mark71697 9 месяцев назад

    Definitely would love to know more about manual and automated. I am brand new to this.

  • @laurent9255
    @laurent9255 10 месяцев назад +1

    Sometimes i find p1 bugs ( example: ssti ) that cannot be exploited at all despite all my efforts . It is weird because i find these bugs very quickly but since i cannot exploit them i do not report and i get very frustrated. I know i should collaborate but for now i prefer learning on my own .

    • @jannmoon
      @jannmoon 10 месяцев назад

      if you cant exploit them then they probably arent bugs 😊

    • @laurent9255
      @laurent9255 10 месяцев назад

      My latest example: I could inject a ssti payload in email , playing with the "change email function". The payload was like +something{{7*7}} then i checked my emails and i received +something49 . Then i tried to read some template variables with this payload +something{{var1}}{{var2}}{{var3}} i received : +somethingFalseFalseFalse
      Obviously i didn't report since i could'nt go any further. As you mentioned for me it is not a real bug but though :(

    • @laurent9255
      @laurent9255 10 месяцев назад

      ho the payload was in fact ...{{var1 != null}}...

  • @OthmanAlikhan
    @OthmanAlikhan 7 месяцев назад

    Thanks for the video =)

  • @crunchied8
    @crunchied8 10 месяцев назад +2

    i would like manual more than automated I am looking at packet type bugs

  • @ahmedahmedx9600
    @ahmedahmedx9600 10 месяцев назад +2

    Hi nahamsec, how you deal with frustration when you started bbh ?

  • @nnofficial2414
    @nnofficial2414 3 месяца назад

    Thank you!

  • @josephblack7408
    @josephblack7408 10 месяцев назад +1

    Wish me a luck for my first bounty

  • @feedomomics8103
    @feedomomics8103 10 месяцев назад +1

    Love you ben ❤️

  • @gamingworld2328
    @gamingworld2328 9 месяцев назад

    thanks man🙏

  • @dominusfalchion8020
    @dominusfalchion8020 6 месяцев назад

    I would love to learn Manual testing, I've been struggling for over a year now haven't even started hacking still trying to understand vulns please teach us the manual approach

  • @jaypanchal9748
    @jaypanchal9748 10 месяцев назад

    both manual and automated approach like combination and make also some videos on some rare internal bug which is not disclosed by companies which was highest paid so talk about that also. thank you

  • @ethyhack
    @ethyhack 10 месяцев назад

    i want to know how much time should spend before given a up finding a vulnerability on a specific target.

  • @rickd8174
    @rickd8174 10 месяцев назад +11

    I've been studying my ass off. I'll be happy if I find a $100 bounty.

    • @avainnovations587
      @avainnovations587 10 месяцев назад +2

      Care to collaborate on the journey? Studying my ass off here too.

    • @rickd8174
      @rickd8174 10 месяцев назад

      @@avainnovations587 sorry I have to be able to do this on my own. Maybe after I'm comfortable knowing that I'm good enough to bring something to the table for collaboration.

    • @codeinspector
      @codeinspector 10 месяцев назад

      Studying my ass here also! I am I interested !

    • @avainnovations587
      @avainnovations587 10 месяцев назад

      @@codeinspector what's your Twitter handle or email?

    • @therelatableladka
      @therelatableladka 9 месяцев назад +1

      Studying my ass ass off man. I can feel you

  • @PhayulDigest
    @PhayulDigest 10 месяцев назад

    Thank you for this informative video, do you think it is good idea to pursue bug bounty after getting the OSCP?

  • @Nastale
    @Nastale 10 месяцев назад

    Thanks Nahamsec, I very appreciate if you go next video with manual method.

  • @olabodeolaleye1795
    @olabodeolaleye1795 10 месяцев назад +1

    Am the first to comment you are my mentor ❤🎉❤🎉 I love your great work bro

    • @olabodeolaleye1795
      @olabodeolaleye1795 10 месяцев назад

      I follow you every social media platform I have and the notifications are always on 😂😂😂😂

    • @NahamSec
      @NahamSec  10 месяцев назад +1

      You are the best

  • @srikumarnimmala1042
    @srikumarnimmala1042 2 дня назад

    Thanks

  • @MarcelN1980
    @MarcelN1980 9 месяцев назад

    Awesome! Will you update your coursev or create some more? 😊

  • @codedsprit
    @codedsprit 10 месяцев назад

    Traditional approach, same thing. But what if one don't have any machine to do further, the condition where I am standing 😢

  • @Zerefxstar
    @Zerefxstar 10 месяцев назад +1

    1st manual
    Then auto

  • @jxkz7
    @jxkz7 9 месяцев назад

    I want to know more about manaul bug bounty hunting. Can you upload thats type of videos

  • @ArSiddharth
    @ArSiddharth 10 месяцев назад +2

    1:18

  • @andreshernandez730
    @andreshernandez730 10 месяцев назад

    @NahamSec is your Udemy course still relevant, where do I start learning?

  • @webdesignsbytom
    @webdesignsbytom 8 месяцев назад +1

    wait full time and you only make a 1000 bucks?

  • @sigo2076
    @sigo2076 10 месяцев назад

    Manual vs. Automatic

  • @jaredelfaz2558
    @jaredelfaz2558 10 месяцев назад

    found my first bug, but couldn't move any further :(, should I quit hacking for a while and learn Web development and get back to hacking? or should I do both in parallel? what would you do if you were in my place?

    • @jaredelfaz2558
      @jaredelfaz2558 10 месяцев назад

      @@camelotenglishtuition6394 it was blind xss

  • @Anonymous-cx7ht
    @Anonymous-cx7ht 10 месяцев назад +1

    First again ❤

  • @TheBenchPressBoss
    @TheBenchPressBoss 10 месяцев назад

    Can you teach me im semi retired and been learnings python with no direction. Id like to make 1-2k month while doing ethical hacking.

  • @ucheugbomah2228
    @ucheugbomah2228 5 месяцев назад

    you are the best

  • @mehrankurd
    @mehrankurd Месяц назад

    thanks

  • @ragnarok55
    @ragnarok55 10 месяцев назад

    To days most of the companys before posting bug platform they are doing lot automated scannings using ai tools and internal security teams testings even 3rd party audits, after they are posting bug platforms me like new beginners can find any bug in real world success rate ???

  • @prabhuchristopher1795
    @prabhuchristopher1795 3 месяца назад

    How to buy course

  • @persiangopher
    @persiangopher 10 месяцев назад

    عاشقتم

  • @casualcaspero
    @casualcaspero 10 месяцев назад +3

    Duuude 1000$/mo in Poland and im reach AF

  • @Aditya_khedekar
    @Aditya_khedekar 10 месяцев назад +1

    manual

  • @ferdusalam7260
    @ferdusalam7260 7 месяцев назад

    manual like arch angel dougles day mindset .................

  • @lukeempty3386
    @lukeempty3386 10 месяцев назад

    Any idea when the course will get an update?

    • @NahamSec
      @NahamSec  10 месяцев назад

      Soon! Working on labs is taking a bit longer than expected

    • @lukeempty3386
      @lukeempty3386 10 месяцев назад

      @@NahamSec No worries. I've owned it a while and I'll wait for the update to go through it. Thanks for what you do man. Take it easy

  • @rdx8122
    @rdx8122 10 месяцев назад +1

    I don't freaking understand why man ? just why ? i mean Nahamsec sir posts a video and maybe he will be thinking : "Ohh let me give this knowledge to my community people ", but here whenever i watch his new video i get the Motivation to hack more and more with the right positive mindset of a bug bounty hunter like Nahamsec 😂😂, also with new and crystal-clear knowledge and critical thinking,, Thank you very very much sir, i don't know if you have this idea that your content is helping this much to the newbies out there like me, really thank you very much by heart 💖💖💖💖

    • @NahamSec
      @NahamSec  10 месяцев назад +1

      get to hacking!

    • @rdx8122
      @rdx8122 10 месяцев назад +1

      @@NahamSec For sure sir !
      Sir i have a doubt if you can answer me please, sir i have a bug bounty program, but this web application has very less functionality, the product of this company is mainly the android app of games (gambling games), but they do have this website in scope, but this website doesn't have any login/upload/download functionality, but what it has is apis, api of payment api and other 2 apis, and simply the android app, and currently i am not into android apps, so should i hack this website for findinf my first valid bug ??
      this website in based in my country india and this program is on indian bug bounty platform so many less people from outside india have looked on it, i tried, but should i spend some days into this program to find hidden assets if there are any, or just leave this and find a new program on hackerone ?

  • @Birch_Lv
    @Birch_Lv 10 месяцев назад +2

    Manual. 😅

  • @crusader_
    @crusader_ 10 месяцев назад

    Both videos

  • @arjunn7683
    @arjunn7683 10 месяцев назад

    BRO CAN CORS INCREASE IMPACT OF SUBDOMAIN TAKEOVER

  • @user-gj4rg5lr5k
    @user-gj4rg5lr5k 10 месяцев назад +1

    Avengers Assemble 😁😁

  • @meljithpereira5532
    @meljithpereira5532 10 месяцев назад

    Are you active on twitch !!!

    • @NahamSec
      @NahamSec  10 месяцев назад +2

      I will be back soon :)

  • @mr.bouttacheck6656
    @mr.bouttacheck6656 10 месяцев назад +1

    Manual

  • @ucheugbomah2228
    @ucheugbomah2228 5 месяцев назад

    i am late 😮‍💨

  • @rahmat_qurishi
    @rahmat_qurishi 10 месяцев назад +1

    ❤❤❤

  • @Mirza14
    @Mirza14 10 месяцев назад

    Hello, if I'm new to Bug Bounty Hunting, would you recommend Web 2 or Web 3 bug hunting?

    • @NahamSec
      @NahamSec  10 месяцев назад

      I don't do any web3.0, so Web 2 forsure

  • @sz2131
    @sz2131 6 месяцев назад

    Bug Bounty is a Myth. Don’t fall in to it by hearing these guys

  • @darkalpha2701
    @darkalpha2701 10 месяцев назад

    Manual pls

  • @geniusesml3700
    @geniusesml3700 10 месяцев назад

    manuel plz or 50 / 50

  • @SleepyAizawa69
    @SleepyAizawa69 14 дней назад

    Noice

  • @brunoeligiopavesi6987
    @brunoeligiopavesi6987 10 месяцев назад +1

    these videos are all the same. Nothing new. Same things repeated again again and again.

  • @cguzmanvisuals
    @cguzmanvisuals 10 месяцев назад

    First!

    • @NahamSec
      @NahamSec  10 месяцев назад

      😮‍💨

  • @ishowmonkey5918
    @ishowmonkey5918 10 месяцев назад

    HEHEEE yoo

    • @ishowmonkey5918
      @ishowmonkey5918 10 месяцев назад

      if you don't mind can you please make a video in the MANUAL approach. i feel like manual is harder to wrap the head around than automation

    • @NahamSec
      @NahamSec  10 месяцев назад

      Will do!

  • @TheDa6781
    @TheDa6781 5 месяцев назад

    Ask yourselves people why would someone teach people to become his competition?

    • @NahamSec
      @NahamSec  5 месяцев назад +1

      Because when I first started hacking, there wasn't a lot of resources for me to learn from. If it wasn't for me peers and friends publishing their write ups, I wouldn't have learned all the stuff I did! Those write-ups pushed me to the right direction. Not everyone has an agenda to teach you stuff to become their competition. :) And honestly, I don't think me giving you advice on how to approach bug bounties and learning how to hack is going to make someone my competition overnight.

  • @sssqqq-ik6hb
    @sssqqq-ik6hb 9 месяцев назад +2

    Free Palestine 🇵🇸

  • @MentalMarathon_
    @MentalMarathon_ 5 месяцев назад

    New to this comment section and a new subscriber. Would you recommend TCM bug bounty course or Hack The Box CBBH before trying

  • @loneliestwolf4228
    @loneliestwolf4228 10 месяцев назад +2

    manual approach please..........................!!!!!!!!!!!!!!!!!!!!!!!!

  • @iljabrudel6224
    @iljabrudel6224 10 месяцев назад

    Thank you for the video NahamSec, I would like to see a manual recorded approach how to for a target.
    I started like from your video How to (Bug Bounty Hunting in 2023)[ruclips.net/video/FDeuOhE5MhU/видео.html] with a VDP program (DoD) and trying to find any Bugs to build up confidence.
    For other viewers, you can re-evaluate your comfort level after watching the video by answering the following questions:
    1. Mindset for Bug Bounty Hunting
    How does a positive mindset impact bug bounty hunting?
    Why is it essential to leave negativity behind when approaching bug bounties?
    How do CTF players' mindsets benefit them in bug bounty hunting?
    2. Approach to Bug Bounty Hunting
    What are the pros and cons of automated vs. manual bug hunting?
    How can someone ensure their automated tools are up-to-date?
    Why might a manual approach be better for beginners?
    3. Choosing the Right Bug Bounty Program
    How can one determine if a bug bounty program is active and worthwhile?
    Why might larger companies or applications be more lucrative for bug hunters?
    How can metrics like the number of bugs paid and average bounty amounts influence one's choice of a program?
    4. Celebrating Small Wins
    Related Questions:
    Why is it important to celebrate small achievements in bug bounty hunting?
    How can celebrating small wins impact one's motivation and drive?
    What are some ways to celebrate these wins?

  • @bobanmilisavljevic7857
    @bobanmilisavljevic7857 10 месяцев назад +1

    Thank you for the info! 🦾🥳

  • @user-ey3kk3nv7q
    @user-ey3kk3nv7q 9 месяцев назад

    Manual