Live Hacking Tutorial: How to Think Like a Bug Bounty Hunter

Поделиться
HTML-код
  • Опубликовано: 21 ноя 2024

Комментарии • 122

  • @alexandrosmitsouli8763
    @alexandrosmitsouli8763 3 месяца назад +6

    Good content brother, good vibe I almost felt we were together on this , I have been learning on my own for the last 3 months , and I am aiming in starting gaining some spare money from bug bounty ( in my own pace ), you were really helpful , hope to see you live as well

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  3 месяца назад +2

      Hey m8 big thanks for the kind words! I'm planning to add some more structure to the channel :)

  • @im_hunter87
    @im_hunter87 11 месяцев назад +67

    Thats how i exploited my university's website 🤣.
    best method : learn from practical experiments. ❤

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  11 месяцев назад +6

      Whaha love it 😂

    • @benatobeqiraj6483
      @benatobeqiraj6483 11 месяцев назад

      Ur a god teach me masterr

    • @goblinninja1234
      @goblinninja1234 10 месяцев назад +1

      What did you do to the website

    • @im_hunter87
      @im_hunter87 10 месяцев назад

      @@goblinninja1234 just got access of my classmate's account(with their permission). and then reported to our HOD, about it.

    • @futuretrunks6927
      @futuretrunks6927 9 месяцев назад

      I did that too when i was in my school, i got access to the admin cpanel acc through sql injection

  • @RohitRajput-xm8hg
    @RohitRajput-xm8hg 9 месяцев назад +10

    "SEAN, professional pizza maker (and eater!), can cut your hair also if required."LMAO🤣

  • @afggg8194
    @afggg8194 Месяц назад +1

    thanks for this. did you do any certifications which utilised ur knowledge to do pen testing or was it all self taught using platforms and yt vids?

  • @Nightmare-23
    @Nightmare-23 11 месяцев назад +8

    Would be great if you create the python program for retriving the values from the form.

  • @coolperzon63
    @coolperzon63 10 месяцев назад +7

    what is your notion template? you mentioned that you use notion and Im curious

  • @willson1646
    @willson1646 11 месяцев назад +35

    Would love to see a video like this where you implement/script a scraper tool to automate the process. Great content 👍🏻

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  11 месяцев назад +6

      Thanks m8! And that is a great video idea wil add that to the list 🙏😁

    • @soFrostyy
      @soFrostyy 9 месяцев назад

      Yes would like to see

  • @skysunset877
    @skysunset877 10 месяцев назад +4

    Thank you so much for the good information!👍👍 I'm a bugbounty novice, and it's been a great help. By the way, are there any restrictions on the scan tools you use to run a bugbounty? I'd like you to let me know if you've experienced any examples

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  10 месяцев назад

      Hey m8 that depends from
      The company, like some just doesn’t like automated scans and then they are restricted to 1 request a sec😁

  • @amoh96
    @amoh96 11 месяцев назад +3

    im beginner bug hunter new to this channel want more videos about mindset and manuel aproach for bug bounty & more vidoes related to bug bounty i really hate automation i love manuel work and dig deep thank you brother

  • @lilham9044
    @lilham9044 7 месяцев назад

    GREAT VIDEO!!!..... How did you kno to type that in the GET REQUEST in Burp Suite?

  • @gazbowyer8617
    @gazbowyer8617 8 месяцев назад

    Thankyou, followed along and learnt a lot, keep up the awesome work , 👍

  • @YA-xv9ig
    @YA-xv9ig 10 месяцев назад +5

    great work ! I hope you continue making clips like this

  • @thenarrowgate3063
    @thenarrowgate3063 8 месяцев назад +1

    I love how much fun your having while hacking, I'm the same way I get excited every time I come across an anomaly I can exploit 👏👍

  • @kokurate
    @kokurate 11 месяцев назад +4

    That's a very good tutorial, really appreciate it. Anyway, could you share your wordlist you usually use when doing bug bounty?

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  11 месяцев назад +3

      You can use seclist for a lot of labs and in real the best is to make custom list for a target you can use a Python program or a language model 😁

    • @davidharding3465
      @davidharding3465 11 месяцев назад

      You could use cewl to create a wordlist specific to the target.

  • @nassvandrunen6020
    @nassvandrunen6020 Год назад +1

    Will try the export target= It seems Nice

  • @SazidHossain-y2h
    @SazidHossain-y2h Год назад +2

    Wonderful Hacking Tutorial Brother. Learned a lot. Tnx

  • @febzey445
    @febzey445 9 месяцев назад

    Great introduction to this type of activity

  • @Max-wn1ed
    @Max-wn1ed 10 месяцев назад +1

    Can you make a video on how to start, explore and find career path in cybersecurity.?

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  9 месяцев назад

      Yea sure maybe I call
      Tell my story I got hired because of a project I made en the motivation 😁

  • @shubhambajaj4939
    @shubhambajaj4939 Год назад +5

    are there other areas in cybersecurity except for bug bounty hunting? I really like infrastructure network bug hunting but not sure if they have a similar type of bounty programs.

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Год назад

      Yea you can become a network expert and protect networks or try to find some bugs in it. Euh that is mostly done by a company because it has a lot more risk to just let everyone in the network. But there are great courses with labs😁

    • @user-wf9oc4bq3e
      @user-wf9oc4bq3e 11 месяцев назад

      ⁠@@CyberSquad-JoinTheSquadagreed. Cause it kind pf related to the LAW. One wrong step then might go inside

    • @watchmo2310
      @watchmo2310 7 месяцев назад

      @@shubhambajaj4939dude said teach him one to one lmaooo

  • @Tyagi174
    @Tyagi174 10 месяцев назад +2

    One question sir i wanted to come into bug bounty does i need to learn networking or just strt with practicals and tut on RUclips

  • @0xdiato
    @0xdiato 11 месяцев назад +2

    amazing job, i learned a lot. PLS DO MORE VIDEO LIKE THIS!!!!

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  11 месяцев назад +1

      Thanks a lot yes I wil try and focus more and more and these videos 😁

  • @khalnayakgamer6607
    @khalnayakgamer6607 11 месяцев назад +2

    Very nice video 🎉

  • @parwatsingh677
    @parwatsingh677 10 месяцев назад +1

    Thank you 😊

  • @tonyjo5224
    @tonyjo5224 2 месяца назад

    18:00 you set target url here, you missed fastfood part between bugbountytraining and /admin. Maybe you could found more vulns

  • @onyxdetailing9163
    @onyxdetailing9163 Год назад +3

    awesome video. quality content.

  • @diefer8093
    @diefer8093 Год назад +1

    Good job bro. Thanks for this information.

  • @behenuemichael6051
    @behenuemichael6051 8 месяцев назад +1

    doesn't scanning puts a pressure on the webpage server? don't we send requests continously while scanning ?

    • @epokal1
      @epokal1 3 месяца назад

      afaik, only verbose and continuous scanning does this

  • @ESPECTRO.1
    @ESPECTRO.1 10 месяцев назад +1

    Produto da ferramenta e paga correto?

  • @RichardinSA
    @RichardinSA 11 месяцев назад +1

    I like your style!

  • @GeraldPajulas
    @GeraldPajulas 10 месяцев назад +1

    After downloaded a bootatble kali linux distro. Then watching this is 👌

  • @Khalid-bm4fw
    @Khalid-bm4fw Год назад +2

    Cool
    Just do more video like this.
    Thanks a lot

  • @aryamannkhare9505
    @aryamannkhare9505 10 месяцев назад +1

    Amazing Vide! Loved it:)

  • @scriptkiddie-fo3vo
    @scriptkiddie-fo3vo Год назад +1

    ur videos are really helpfull thanks u will be soon big W guy

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Год назад +1

      Thanks m8 loved the response! Just wanne help people to change their lives 😁

  • @nazuko2721
    @nazuko2721 3 месяца назад

    how did you directly copy url from windows to linux?

    • @thegaminggoblin1197
      @thegaminggoblin1197 Месяц назад +1

      That's what i was thinking. When I was in school we had a specific VM that allowed this but I can't find it

  • @MustafaGains
    @MustafaGains Год назад +2

    Great 👍🏿

  • @raven-vr5yz
    @raven-vr5yz 4 месяца назад +1

    I'm not a pro, but I immediately thought about exploiting ssrf with that redirection url...

  • @denimsahu7718
    @denimsahu7718 7 месяцев назад

    What i don't understand is even tho you found that xxs valun but since there is no way to make you js add to the website source code unlike having xxs valun when placing a order or something which results in our malicious js code being saved into data base and getting executed whenever someone opens out order but in this website case there nothing like that so can someone please explain me how it will help us? Yeah it a valn but not that useful since we just can't go and hijack someone user or admin session using this , I'm a beginner so please help if I'm not seeing the bigger picture here

  • @Yash.Lonewolf
    @Yash.Lonewolf Год назад +1

    excellent

  • @dalo1100
    @dalo1100 Месяц назад

    im a noob, but for the part where he exploited the redirect, would anyone visiting the site be hit by the alert box?

  • @aryzen2781
    @aryzen2781 7 месяцев назад

    how many bugs have you found doing bug bounties?

  • @cyberman6021
    @cyberman6021 Год назад +1

    Rare content, thank you i like it :)

  • @warri0rs16
    @warri0rs16 Год назад +2

    Nice video can you make more videos on SQL injection,ssrf and xss

  • @galliharmada617
    @galliharmada617 10 месяцев назад +1

    its awesome!

  • @shashankk7827
    @shashankk7827 11 месяцев назад

    admin.php is a file, so there is no use of doing dirb on it because its not a folder…am i right?

    • @as3ad.
      @as3ad. 11 месяцев назад

      It depends on the dirb-busting tool used. GoBuster does not support file extensions, but there are tools that do e.g. FeroxBuster, which you can specify extensions to search for (e.g. php,html,asp,aspx, txt). Ferox will use the words in the specified wordlist, and append the extensions when fuzzing.

  • @TheCalax
    @TheCalax 11 месяцев назад

    What if the Bug Bounty Program only allows me to scan like, 2 requests per second? This all is gonna take ages

  • @MediaClipGames
    @MediaClipGames 9 месяцев назад

    i was like why does he not check order number 1-3 it would probally be snowy or the other guy emails

  • @razdingz
    @razdingz Год назад +1

    this good - here take joint bro

  • @ZERO247-1
    @ZERO247-1 4 месяца назад

    19:30

  • @yaboy7120
    @yaboy7120 Год назад +2

    can you talk more about your origins 😃

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  11 месяцев назад +1

      Sure what you like to know? Discord wil be up soon to have a chat 😁

  • @mohdbilal5672
    @mohdbilal5672 Месяц назад

    if it's clickable it's hackable

  • @h5e
    @h5e Год назад

    Pls part 2

  • @Lucifersatan001
    @Lucifersatan001 5 месяцев назад

    How to hack Aviator

  • @jhonwick-s9x
    @jhonwick-s9x Год назад

    are you a professional hacker??

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  Год назад +4

      Hey I’m a junior application security engineer so yes but still learning every day😁

  • @sheronizes6993
    @sheronizes6993 9 месяцев назад +1

    in reality, burp will intercept one million useless request and just create an account recquire a lot of patience

  • @TheFuture36520
    @TheFuture36520 11 месяцев назад

    Imagine hacking someone via a RUclips comment 😂

  • @neeroseg.pradhan9311
    @neeroseg.pradhan9311 Год назад +1

    Hello bro

  • @Relax_sound121
    @Relax_sound121 6 месяцев назад

    How to hack aviator game round plz help me

  • @TeslaWorkshop
    @TeslaWorkshop 8 месяцев назад

    you missed many more vulnerabilities

  • @Maik.iptoux
    @Maik.iptoux 11 месяцев назад +3

    20:30 You missed multiple times that you use the wrong url on dir buster, and I notice this on smartphone...

  • @tranquilla-videos
    @tranquilla-videos 8 месяцев назад

    is this is how we perform Bunty Bounty?

  • @RAN522-p5o
    @RAN522-p5o 11 месяцев назад

    ruclips.net/video/mALRt5SXMeI/видео.html

  • @Kulwazoldik
    @Kulwazoldik 11 месяцев назад

    Can you help me hack an application lovley pet؟؟

  • @bobbydrillboid
    @bobbydrillboid 6 месяцев назад +2

    honestly a horrible video, you talk through it and do stuff as if we fully understand everything you are using and talking about, but that is far from the truth. I don't know much about this stuff at all and I'm trying to learn how to do it, but if you don't explain how to use every single thing piece of everything than I get completely lost and want to close the video because I cant follow along. For example, I don't know how to work burpsuite or set it up, so when you're clicking around and doing things i cant follow along. You should include the entire process of EVERYTHING I don't care how long the video gets, I need you to talk to me like I know nothing about this stuff at all, because that's kind of the case.

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  6 месяцев назад +1

      I will try making some more basic vids mate 😁

    • @Schizohandlers
      @Schizohandlers 5 месяцев назад +1

      Skill issue

    • @alan-t7b
      @alan-t7b 4 месяца назад +1

      There are other resources to learn how to use the tools you are unfamiliar with. You could look up a video on setting up a Kali Linux VM to start.. learning is a process.

  • @Towersfam43232
    @Towersfam43232 11 месяцев назад +1

    guy thinks hes a hacker using typical programs. Dude cmon your brain smaller then your biceps for sure

    • @CyberSquad-JoinTheSquad
      @CyberSquad-JoinTheSquad  11 месяцев назад +2

      I don’t think aim a hacker, I work in the field of cybersecurity and I don’t ask you to watch my videos. I love to see some videos where you show your skills and maybe I can learn some of that😁

  • @nimaism
    @nimaism Год назад +1

    nice bro

  • @bigerrncodes
    @bigerrncodes 7 месяцев назад

    Order ID 42069 lol

  • @RAN522-p5o
    @RAN522-p5o 11 месяцев назад

    ruclips.net/video/mALRt5SXMeI/видео.html