How to Find XSS on Modern Web Applications: A Bug Bounty Guide

Поделиться
HTML-код
  • Опубликовано: 4 янв 2025

Комментарии • 34

  • @DatBoii2Dizzy
    @DatBoii2Dizzy 16 дней назад +1

    Thanks for the video
    I’m learning so much from this community
    I can’t wait to give back

    • @bugbountywithmarco
      @bugbountywithmarco  16 дней назад

      Thanks! What topic would you like to see next?

    • @DatBoii2Dizzy
      @DatBoii2Dizzy 16 дней назад

      @@bugbountywithmarco SQL injections is what I’m on RUclips looking up now

  • @guilhermeamorim4937
    @guilhermeamorim4937 12 дней назад +1

    Excelente vídeo, não pude deixar de notar que você é brasileiro. Estou começando agora, ainda na busca do meu primeiro bug

  • @poiuymnbvc8339
    @poiuymnbvc8339 21 день назад +1

    Bro great video, i truely love the pace…keep it man..

  • @PrimordialLegend
    @PrimordialLegend 19 дней назад +1

    Thanks, nice work. Keep going!

  • @imperim
    @imperim 22 дня назад +1

    Thanks, nice explanation

    • @bugbountywithmarco
      @bugbountywithmarco  22 дня назад

      nice to know that! Is there any other vulnerability you would like to see in the perspective of a web software engineer?

    • @imperim
      @imperim 21 день назад +1

      I am just beginner in this field so just learning from internet Portswigger labs, RUclips, you etc any help appreciate

    • @bugbountywithmarco
      @bugbountywithmarco  21 день назад

      nice to know that, i’ll be posting about other bugs soon

    • @imperim
      @imperim 21 день назад +1

      Thanks

  • @poiuymnbvc8339
    @poiuymnbvc8339 21 день назад +1

    Can you make a series for hunting xss?? Showing how to exploit xss in different ways

    • @bugbountywithmarco
      @bugbountywithmarco  21 день назад

      @@poiuymnbvc8339 that’s something I wanted to do. I have some application that I developed myself that i can use for demonstration

  • @tpevers1048
    @tpevers1048 19 дней назад +1

    So about doom xss

  • @SumitYadav-lr5vy
    @SumitYadav-lr5vy 21 день назад +1

    Can you start a series in which you explain bugs which a not hunted by many hunter

    • @bugbountywithmarco
      @bugbountywithmarco  21 день назад

      @@SumitYadav-lr5vy of course! I have a scheduled video here about non common vulnerabilities

  • @shubham_srt
    @shubham_srt 20 дней назад +1

    keep making more videos

    • @bugbountywithmarco
      @bugbountywithmarco  20 дней назад

      thanks for the feedback. What topic would you like to see next?

  • @imperim
    @imperim 21 день назад +1

    hey i have noticied u reported many vulnerabilities in hacker one may i know what kind of those vulnerabilities are? do those are xss? or what

    • @bugbountywithmarco
      @bugbountywithmarco  21 день назад +1

      my top 3 most reported vulnerabilities is: business logic errors, IDOR, and Improper Access Control

    • @imperim
      @imperim 19 дней назад

      @@bugbountywithmarco oh thanks & interesting

  • @SumitYadav-lr5vy
    @SumitYadav-lr5vy 21 день назад +1

    So as a beginner who just started bug Bounty what types of bugs will you recommend him to hunt for ?

    • @bugbountywithmarco
      @bugbountywithmarco  21 день назад

      @@SumitYadav-lr5vy i would suggest you to start with one of these: IDOR, Business Logic Errors or Broken Authorization.
      Specially business logic errors, that may not be as popular as the other ones.

    • @SumitYadav-lr5vy
      @SumitYadav-lr5vy 21 день назад +1

      @@bugbountywithmarco can you recommend me some recourse because business logic error doesn't have good resources?

    • @bugbountywithmarco
      @bugbountywithmarco  21 день назад

      @@SumitYadav-lr5vy actually to find a business logic error vulnerability you need to understand the business of the application you are testing.
      For example: a dating app allows the user to send messages to another user only when they have a match. But what if the user can actually send messages to a person before the match?

    • @SumitYadav-lr5vy
      @SumitYadav-lr5vy 21 день назад +1

      @@bugbountywithmarco it is like bac related issues

    • @bugbountywithmarco
      @bugbountywithmarco  21 день назад

      @@SumitYadav-lr5vy a little similar issue

  • @SumitYadav-lr5vy
    @SumitYadav-lr5vy 5 дней назад +1

    After watching this video I think it is not worth it to look for xss zo which vulnerability should i learn apart from improper access control

    • @bugbountywithmarco
      @bugbountywithmarco  5 дней назад

      my next video will be about some different xss techniques, maybe it can help you

  • @shubham_srt
    @shubham_srt 20 дней назад +1

    none of your social links are working btw

    • @bugbountywithmarco
      @bugbountywithmarco  20 дней назад

      thanks for the tip. I believe this is happening because this channel was just created.
      You can find the clickable links in my channel page though