How to Find XSS on Modern Web Applications: A Bug Bounty Guide

Поделиться
HTML-код
  • Опубликовано: 9 фев 2025
  • Tired of outdated XSS tutorials that don’t work on real bug bounty programs? In this video, we dive deep into finding Cross Site Scripting (XSS) vulnerabilities on modern web applications like those built with React. Learn how developers are building secure frontends and discover hands-on techniques to identify XSS vulnerabilities even in today’s hardened environments.
    Whether you're a beginner in cybersecurity or an experienced bug hunter, this guide will help you refine your approach and stay ahead of the curve. 🚀
    🔍 What You'll Learn:
    How modern applications handle XSS
    The basics of Cross Site Scripting and common attack vectors
    How React secures applications by default
    Hands-on examples of finding XSS vulnerabilities in React apps
    Subscribe to Bugbounty With Marco for more cybersecurity insights!
    My links:
    👉 www.hackerone....
    👉 / bugbountywithmarco
    #BugBounty #Cybersecurity #XSS #WebSecurity #ReactJS #EthicalHacking

Комментарии • 34

  • @DatBoii2Dizzy
    @DatBoii2Dizzy Месяц назад +3

    Thanks for the video
    I’m learning so much from this community
    I can’t wait to give back

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      Thanks! What topic would you like to see next?

    • @DatBoii2Dizzy
      @DatBoii2Dizzy Месяц назад

      @@bugbountywithmarco SQL injections is what I’m on RUclips looking up now

  • @poiuymnbvc8339
    @poiuymnbvc8339 Месяц назад +1

    Bro great video, i truely love the pace…keep it man..

  • @guilhermeamorim4937
    @guilhermeamorim4937 Месяц назад +2

    Excelente vídeo, não pude deixar de notar que você é brasileiro. Estou começando agora, ainda na busca do meu primeiro bug

  • @PrimordialLegend
    @PrimordialLegend Месяц назад +1

    Thanks, nice work. Keep going!

  • @poiuymnbvc8339
    @poiuymnbvc8339 Месяц назад +1

    Can you make a series for hunting xss?? Showing how to exploit xss in different ways

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      @@poiuymnbvc8339 that’s something I wanted to do. I have some application that I developed myself that i can use for demonstration

  • @SumitYadav-lr5vy
    @SumitYadav-lr5vy Месяц назад +1

    Can you start a series in which you explain bugs which a not hunted by many hunter

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      @@SumitYadav-lr5vy of course! I have a scheduled video here about non common vulnerabilities

  • @imperim
    @imperim Месяц назад +1

    Thanks, nice explanation

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      nice to know that! Is there any other vulnerability you would like to see in the perspective of a web software engineer?

    • @imperim
      @imperim Месяц назад +1

      I am just beginner in this field so just learning from internet Portswigger labs, RUclips, you etc any help appreciate

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      nice to know that, i’ll be posting about other bugs soon

    • @imperim
      @imperim Месяц назад +1

      Thanks

  • @shubham_srt
    @shubham_srt Месяц назад +1

    keep making more videos

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      thanks for the feedback. What topic would you like to see next?

  • @imperim
    @imperim Месяц назад +1

    hey i have noticied u reported many vulnerabilities in hacker one may i know what kind of those vulnerabilities are? do those are xss? or what

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад +1

      my top 3 most reported vulnerabilities is: business logic errors, IDOR, and Improper Access Control

    • @imperim
      @imperim Месяц назад

      @@bugbountywithmarco oh thanks & interesting

  • @tpevers1048
    @tpevers1048 Месяц назад +1

    So about doom xss

  • @SumitYadav-lr5vy
    @SumitYadav-lr5vy Месяц назад +1

    So as a beginner who just started bug Bounty what types of bugs will you recommend him to hunt for ?

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      @@SumitYadav-lr5vy i would suggest you to start with one of these: IDOR, Business Logic Errors or Broken Authorization.
      Specially business logic errors, that may not be as popular as the other ones.

    • @SumitYadav-lr5vy
      @SumitYadav-lr5vy Месяц назад +1

      @@bugbountywithmarco can you recommend me some recourse because business logic error doesn't have good resources?

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      @@SumitYadav-lr5vy actually to find a business logic error vulnerability you need to understand the business of the application you are testing.
      For example: a dating app allows the user to send messages to another user only when they have a match. But what if the user can actually send messages to a person before the match?

    • @SumitYadav-lr5vy
      @SumitYadav-lr5vy Месяц назад +1

      @@bugbountywithmarco it is like bac related issues

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      @@SumitYadav-lr5vy a little similar issue

  • @SumitYadav-lr5vy
    @SumitYadav-lr5vy Месяц назад +1

    After watching this video I think it is not worth it to look for xss zo which vulnerability should i learn apart from improper access control

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      my next video will be about some different xss techniques, maybe it can help you

  • @shubham_srt
    @shubham_srt Месяц назад +1

    none of your social links are working btw

    • @bugbountywithmarco
      @bugbountywithmarco  Месяц назад

      thanks for the tip. I believe this is happening because this channel was just created.
      You can find the clickable links in my channel page though