IBM - Live bug bounty hunting on Hackerone

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • Bug bounty hunting on Hackerone platform. IBM!
    #hacker #hacking #pentesting #cybersecurity #infosec #ethicalhacking

Комментарии • 166

  • @gotr00t0day
    @gotr00t0day  4 месяца назад +20

    My videos usually last long processing, that's why you can only see it in 360p, Once it's done processing it will become 4K.

    • @K-entertainment7570
      @K-entertainment7570 3 месяца назад

      Can you give your email ? I have some project if you intersted

    • @K-entertainment7570
      @K-entertainment7570 3 месяца назад

      Can you give your telegram i have some project if you interested

    • @Justanormalguy01
      @Justanormalguy01 3 месяца назад +2

      Hi! Can u make a tutorial on how to install the Spyhunt tool?

    • @LakeE.
      @LakeE. 3 месяца назад

      @@Justanormalguy01Do it yourself that’s how you learn the best 👍🏼

    • @fagbolapeter6967
      @fagbolapeter6967 13 дней назад

      Please what type of attack vulnrablity is this ?

  • @0xx0xx00x0
    @0xx0xx00x0 3 месяца назад +48

    i dont understand ANYTHING but i still watched the whole vid lol

  • @cyberacademics
    @cyberacademics 3 месяца назад +16

    Just found this gem of a channel! Super excited to watch your videos and thank you for your videos!

  • @Matheus-tg9op
    @Matheus-tg9op 4 месяца назад +62

    More bug bounty live videos pls !! Im Learning so much watching your videos

  • @RichardinSA
    @RichardinSA 2 месяца назад +6

    No talking just the good stuff? I'm hooked!

  • @badepapa2217
    @badepapa2217 24 дня назад +1

    Love the Fsociety terminal background 😁

  • @shubhamvirkar93
    @shubhamvirkar93 22 дня назад +2

    hey been watching since a few days . love the content . Just a small suggestion. add comments or notes or voiceover maybe? . Though I understand what you're doing not all of them could . Anyway good content bro. keep up the good work.

  • @TotoGlitcherYT64
    @TotoGlitcherYT64 7 дней назад

    love the wallpaper background ;)

  • @nmmorette
    @nmmorette 2 месяца назад +2

    nice content! thanks for sharing

  • @hatemaliyan3933
    @hatemaliyan3933 3 месяца назад +1

    Great, more of live bug bounty methodology videos 🎉

  • @dk70
    @dk70 2 месяца назад

    The music is: Homesteading on my small organic farm by day, hacking IBM during the night

  • @userme-z1x
    @userme-z1x Месяц назад

    i advise everyone to learn about networking and penetration testing, CCNA,OSCP

  • @glyslay4102
    @glyslay4102 3 месяца назад +1

    Great video. Make more livestreams.

  • @tilloevfaridun9135
    @tilloevfaridun9135 3 месяца назад +2

    When i install -r requirements i got this -->ERROR: Could not find a version that satisfies the requirement codecs (from versions: none) ERROR: No matching distribution found for codecs
    How to resolve? Thank you ~

    • @immo189
      @immo189 3 месяца назад

      cat the requirements,
      pip install install requirements separately
      run spyhunter after each install (I am assuming it's spyhunter)
      see the error and repeat install process for each lib or software etc that is required.

  • @thienngo2953
    @thienngo2953 3 месяца назад +1

    god save you. Bug bounty live. Unbelievable!

  • @Dani-Zsh
    @Dani-Zsh 3 месяца назад +4

    I'm sorry for my bad English, but I have a question.
    I know Apple is Unix based and has Zsh as shell, but are you connected via SSH to another pc or those tools can be used in apple?

    • @brolytim4303
      @brolytim4303 3 месяца назад

      i think the OS doesnt care much, cuz tools are programmed with python, so if ur SO can run python u you wouldnt have problems

    • @themay2319
      @themay2319 3 месяца назад

      These tools look like they are all ran in python. It doesn't matter if you are on Mac, Windows, or Linux, as long as it can run python, you can do this method.

    • @lit1numyt_
      @lit1numyt_ 2 месяца назад

      Personally I'm using the M1 macbook. It's not about the OS, it's about the structure the computer are based on. Like my macbook using the M1 chip built on ARM structor, I had have quite a hard time running a lot of tool because most of them are all built on x86 structor (most computer and cpu like Intel and AMD uses the x86 structor). My solution so far was to use an old laptop, install ubuntu and ssh into it like @Dani-Zsh, but it has some drawback of only viable through LAN cause I'm a college student and I can't mess with the dorm room network to open a NAT port for remote uses. Another solution that best work for me was to use a AWS cloud computer. They has x86 base and are free for low-end rig (750hours each month for a year. after a year just shut it down and create a new account) and they already has a public ip, PEM key made easy for remote use.

    • @lit1numyt_
      @lit1numyt_ 2 месяца назад

      Older macbook that uses intel chip are fine tho

  • @aatankbadboy3941
    @aatankbadboy3941 3 месяца назад +10

    Bro you can add notes in which you shortly describe your steps

  • @bugbouty
    @bugbouty 4 месяца назад +4

    bro make a video about finding origin ip and after how to find xss,sqli,ssrf etc with that origin ip address

    • @atlasdevelopment8683
      @atlasdevelopment8683 2 месяца назад

      If you mean origin ip, as in the backend of a website. Use Censys, Fofa, Zoomeye.

  • @funexpressions6498
    @funexpressions6498 3 месяца назад

    especially for this video i subscribed

  • @JohnKim_24
    @JohnKim_24 5 дней назад

    Siiiiiiiiiiickkkkkk

  • @aliuzun8885
    @aliuzun8885 2 месяца назад +1

    Only recon but its k ty.

  • @brolytim4303
    @brolytim4303 3 месяца назад +1

    buen video bro, sabes de alguna buena academia en español? o toca traducir jeje saludos desde Argentina!

    • @gotr00t0day
      @gotr00t0day  3 месяца назад

      Puedes encontrar muchas en Google jeje. Solo toca buscar, se que también hay muchos vídeos que enseñan seguridad informática en español en RUclips. Buena suerte ;)

  • @andresbarrera3298
    @andresbarrera3298 3 месяца назад +7

    im starting to learn i didnt notice you activated vpn before scan.. do u use vpn before starting scans?

    • @bo_68
      @bo_68 3 месяца назад +1

      These "attacks" are completely legal. Companies will ask hackerone to connect with hackers to find network vulnerabilities, such as bug bounties

    • @andresbarrera3298
      @andresbarrera3298 3 месяца назад

      @@bo_68 but the guys i saw using vpn said they use vpn just if the tools to use make blacklisted your main ip while scanning

    • @bo_68
      @bo_68 3 месяца назад

      @@andresbarrera3298 As you can see, the author has not been blocked by ibm, if he was blocked he would have changed to using VPN. hahaha

    • @bo_68
      @bo_68 3 месяца назад

      @@andresbarrera3298 It depends on the scanning blocking mechanism set up by each service

  • @runmirage
    @runmirage 3 месяца назад

    well done! do you also use some linux distro or you only main macos

  • @alphacentauri8035
    @alphacentauri8035 3 месяца назад +1

    This is hypnotizing

  • @rebelavie7772
    @rebelavie7772 2 месяца назад

    hi.. what themes or config (figlet?) do you use in your terminal? The fsociety in the background is really cool...

    • @harc3rz
      @harc3rz 2 месяца назад

      In MacOS you can simply go to terminal settings and change your background to any photo you like (change the blur of the background, opacity etc.). The rest is ZSH.

  • @CatalystClassroom
    @CatalystClassroom 4 месяца назад +1

    very good video bro, where are you from?

  • @Lrnr1234
    @Lrnr1234 Месяц назад

    Bro, do we need to create an account with the target also before we start testing?

  • @abiodunolabode959
    @abiodunolabode959 12 дней назад

    Name is Jay...I WILL come back to this comment the day i find my first bug. I will work towards this and make it happen cos im down on my fuckin ass right now.

  • @kamilwielgus4917
    @kamilwielgus4917 3 месяца назад +1

    please forgive me total lack of skills and possible nonsense coming out my comment. Great stuff you do here. Right now its black magic for me, im just a guy who enters this industry at the late age....but the stuff you do is great and the music in the background makes it more interesting. If you are willing to write some analytic guideline would be great. What i see you run spyhunt and httpx which you constantly modify on the go to fit the scope, which is great adjustment. I understand you inject some payloads, right ? To check vulnerabilities and adjust your pentesting tools, right ? I see you did something with Burp. I tried once at school to get a cookies info or something. What music you play by the way, some spotify playlist ?:)

    • @gotr00t0day
      @gotr00t0day  3 месяца назад +3

      I write my own tools, that's why you see me modifying spyhunt on the fly. Burpsuite is the go to to intercept traffic and really test the application for vulnerabilities.

  • @DT190-ks2vp
    @DT190-ks2vp 10 дней назад

    Hi, what is your tool for crawl url ?

  • @modymohab4549
    @modymohab4549 2 месяца назад

    Where did you learn bug bounty ?

  • @user-kf8wc7iv5t
    @user-kf8wc7iv5t 2 месяца назад

    good

  • @DexCode1337
    @DexCode1337 3 месяца назад +1

    fsociety💀💀💀💀

  • @thecarrot1728
    @thecarrot1728 2 месяца назад +2

    why are so many people so shocked you're using macos lol

    • @gotr00t0day
      @gotr00t0day  2 месяца назад

      Idk lol, only if they knew that MacOS is based on Unix just like Linux.

  • @cameronrich2536
    @cameronrich2536 3 месяца назад

    Can you help me please i spent luteral days trying to get spyhunt installed properly and now i get a stupid traceback error nomatrer what i name the file im trying to save to

  • @Hvleos
    @Hvleos 4 месяца назад

    when did u start doing bug bounties? Like when did you feel ready for them?

    • @gotr00t0day
      @gotr00t0day  3 месяца назад +6

      Once you learn the owasp top ten, you can start hunting for the vulnerabilities

  • @Fuadkamalkamal
    @Fuadkamalkamal 4 месяца назад

    more videos please :)

  • @shafeeqbasheer4784
    @shafeeqbasheer4784 Месяц назад

    Didnt have a clue what I was watching. But was interesting regardless😅 Btw I didnt quite get whether there was a bug or not xD can someone tell me

    • @louisbarasa5741
      @louisbarasa5741 Месяц назад

      He got bugs in the first ten minutes of the video, 3 bugs to be specific, 2 access control issues and another sub domain vulnerability.........

  • @aritdutta8400
    @aritdutta8400 Месяц назад

    Are you using M1/M2/M3 or Intel chip processor ??? Use any cloud VM and connect through ssh or the whole lab set up on your original host???

    • @gotr00t0day
      @gotr00t0day  Месяц назад

      I’m using the iMAC M3 16GB of RAM and 512 SSD which is awesome

    • @aritdutta8400
      @aritdutta8400 Месяц назад

      ​@@gotr00t0day I'm using M1!
      The whole lab set up on your local host??? or Use any cloud VM and connect through ssh???

    • @aritdutta8400
      @aritdutta8400 Месяц назад

      @@gotr00t0day I'm using M1.
      This whole Lab setup on your local system (imac) or u are using cloud vm which you connect through ssh????

    • @gotr00t0day
      @gotr00t0day  Месяц назад

      @@aritdutta8400 no

    • @aritdutta8400
      @aritdutta8400 Месяц назад

      @@gotr00t0day That's mean you setup the whole lab on your local system (imac) ??

  • @9kk
    @9kk 4 месяца назад

    Is there a second part?

  • @alidashti5385
    @alidashti5385 Месяц назад

    hi thanks for sharing
    btw what is ur hackerone handle ?

  • @dollaz4647
    @dollaz4647 3 месяца назад +1

    I have no idea wtf any of ts is.

  • @abdelrahmanfarghly7135
    @abdelrahmanfarghly7135 3 месяца назад

    what is your hackerone acc???

  • @user-pw5cc6bj4r
    @user-pw5cc6bj4r 3 месяца назад

    nice terminal

  • @aceagiotakrl
    @aceagiotakrl 3 месяца назад

    Where did you acquire all this knowledge?

  • @khunjame7
    @khunjame7 3 месяца назад

    I am using macbook too can you tell me how to get all the tools that you use thanks.

    • @gotr00t0day
      @gotr00t0day  3 месяца назад

      You can either brew install them or clone the repo from github

  • @squertalplush6255
    @squertalplush6255 2 месяца назад

    How did you learn how do this and how did u install the kali on mac os

  • @potcleanx7693
    @potcleanx7693 3 месяца назад

    can you explain what your doing like it would much better if you do

  • @jaxjaxgaming8033
    @jaxjaxgaming8033 3 месяца назад

    hello, i would like to know what specs do you have for your mbp, is 18gb enough ?

    • @gotr00t0day
      @gotr00t0day  3 месяца назад +2

      16GB is enough, 512GB SSD with the M3 chip and wireless Magic Keyboard / mouse. ;)

  • @moh3507
    @moh3507 3 месяца назад

    please release more videos please

  • @natureandskies9140
    @natureandskies9140 3 месяца назад

    Brother all the tools you use i have already installed but i can't install burpsuite bcoz i am using my phone to do these things,i have installed all the things on my cloud shell,can you tell me any subprogram like burpsuite which i can use on my phone or on my terminal?

    • @alphacentauri8035
      @alphacentauri8035 3 месяца назад

      i think mitmproxy can also intercept and modify requests and it's command line based.

  • @Fractal_reComm
    @Fractal_reComm 3 месяца назад

    visão avançada

  • @princebablubiever2593
    @princebablubiever2593 3 месяца назад

    Bro did you customize kali linux to look like mac os or is it actually mac os

    • @gotr00t0day
      @gotr00t0day  3 месяца назад

      It’s actually macOS ;)

    • @MDKhairulIslamBablu
      @MDKhairulIslamBablu 2 месяца назад

      ​@@gotr00t0day How did you do it means Macs can't be used for hacking or penetration testing but how did you do it and do you have any related videos

    • @gotr00t0day
      @gotr00t0day  2 месяца назад

      @@MDKhairulIslamBablu Mac’s can be used for hacking and coding, not sure why people think otherwise lol ;)

    • @MDKhairulIslamBablu
      @MDKhairulIslamBablu 2 месяца назад

      @@gotr00t0day brother please upload a video about how can we make our Mac os as a Hacking Machine please 🥺

    • @gotr00t0day
      @gotr00t0day  2 месяца назад

      @@MDKhairulIslamBablu Ok ;)

  • @Diedlonely
    @Diedlonely 18 дней назад

    Linux in iphone😭😭😭

  • @Dramon11
    @Dramon11 4 месяца назад

    the spyhunt version 1.7 where can i found it ?

    • @immo189
      @immo189 3 месяца назад

      he has a github page

  • @atakanyanar18
    @atakanyanar18 3 месяца назад +1

    only enum right ?

    • @gotr00t0day
      @gotr00t0day  3 месяца назад

      Yeah, is mostly reconnaissance, I don’t like exploiting anything on the live, unless is CTF or something like that

    • @atakanyanar18
      @atakanyanar18 3 месяца назад

      @@gotr00t0day i got dude thanks :) keep going on

  • @songenjoyer2655
    @songenjoyer2655 2 месяца назад

    where can i find the music background?

    • @userme-z1x
      @userme-z1x Месяц назад

      on youtube, only you write music background

  • @gangbang7354
    @gangbang7354 3 месяца назад

    can someone please tell me which OS is this Parrot or Kali? or any other linux distro

    • @filmrolls3165
      @filmrolls3165 3 месяца назад

      This is just macos & using it's terminal

  • @ozzysraiyan1096
    @ozzysraiyan1096 3 месяца назад

    hello , can you help me roadmap study for search bug bounty. Thank you very much

    • @userme-z1x
      @userme-z1x Месяц назад

      i think you can professional hunter when you study ccna, oscp and more certificate

  • @0xanubis
    @0xanubis 4 месяца назад

    Damn Bro your video is 360p and without audio

    • @gotr00t0day
      @gotr00t0day  4 месяца назад

      Is processing, its always 4K.

    • @0xanubis
      @0xanubis 3 месяца назад

      Good to hear that continue
      and btw you are awesome@@gotr00t0day

  • @IRateStuff
    @IRateStuff 3 месяца назад

    can you provide dirsearch txt?

  • @denverledinosor3694
    @denverledinosor3694 2 месяца назад

    is it legal to share those info ?

    • @MsIlRusso
      @MsIlRusso 2 месяца назад

      as long as the company is aware of the vulnerability and fix it i think pretty safe.

  • @0xgreyhound
    @0xgreyhound 3 месяца назад

    hello

  • @jaimec5672
    @jaimec5672 3 месяца назад

    How do u install spyhunt it keeps giving me errors

    • @gotr00t0day
      @gotr00t0day  3 месяца назад

      Open an issue request on github and I’ll look at it

    • @jaimec5672
      @jaimec5672 3 месяца назад

      @@gotr00t0day done

  • @therealer_
    @therealer_ 3 месяца назад

    how did you installed dirsearch on mac?

  • @smartrahman6245
    @smartrahman6245 3 месяца назад

    I need your desktop wallpaper and terminal

    • @gotr00t0day
      @gotr00t0day  3 месяца назад

      The desktop wallpaper was made by a friend of mine, and the terminal background you can find on google by searching Fsociety ;)

  • @zcsz.
    @zcsz. 2 месяца назад

    what's with this music bro are you hacking or riding an elevator

  • @Ox7H3_L1ON
    @Ox7H3_L1ON 3 месяца назад +1

    day this is the error I get when I try and install spyhunt "ERROR: Could not find a version that satisfies the requirement codecs (from versions: none)
    ERROR: No matching distribution found for codecs "
    Your assistance will be highly appreciated

    • @immo189
      @immo189 3 месяца назад

      run apt update first, then run install and if you have errors see my response further up

  • @kamalchan9756
    @kamalchan9756 18 дней назад

    you will be blind before 40 use dark mode bro

  • @infosx4875
    @infosx4875 4 месяца назад

    Post more, in the near future I'll start hackerone challenges. I'm studying JAVA, what lang do you code?

  • @youtubersnews81
    @youtubersnews81 2 месяца назад

    V1.8

  • @bitGbit
    @bitGbit 3 месяца назад +1

    Music way too distracting

    • @gotr00t0day
      @gotr00t0day  3 месяца назад +2

      Sorry, a lot of people like it with the background music lol

  • @luv1099
    @luv1099 4 месяца назад

    360p 😪

  • @bruno-devs
    @bruno-devs 3 месяца назад

    github of the tools used in the video?

    • @gotr00t0day
      @gotr00t0day  3 месяца назад +1

      www.github.com/gotr00t0day/spyhunt ;)

  • @jesusangelchavezhuaman2543
    @jesusangelchavezhuaman2543 3 месяца назад

    Can you pass me your Kali Linux style?

    • @alphacentauri8035
      @alphacentauri8035 3 месяца назад +1

      This is not kali, it's macbookpro with macos..

  • @mohmino4532
    @mohmino4532 4 месяца назад

    nice vid but i have tried to install ur tool but it doesn't work and i got this error :
    Found nodejs
    Found npm
    Traceback (most recent call last):
    File "/home/djamelof/bugbounty-tool/spyhunt/install.py", line 34, in
    command("npm install broken-link-checker -g")
    NameError: name 'command' is not defined. Did you mean: 'commands'?

    • @gotr00t0day
      @gotr00t0day  4 месяца назад +1

      Fixed, you can pull now to update.

    • @mohmino4532
      @mohmino4532 3 месяца назад

      @@gotr00t0day thnx i will give it try again than i will tell u what happend

  • @CyberTechwithNikhil
    @CyberTechwithNikhil 3 месяца назад

    Bro your telegram channel link?

  • @nlegendgaming8324
    @nlegendgaming8324 3 месяца назад

    Your telegram?

  • @Anonymous-Hack3r
    @Anonymous-Hack3r 3 месяца назад

    please share spyhunt repo link