Over 10k Achieved in Web3 Bounties

Поделиться
HTML-код
  • Опубликовано: 8 авг 2022
  • My first unique medium severity finding and passing 10k in rewards on Code4rena.

Комментарии • 48

  • @harrytr.277
    @harrytr.277 Год назад +7

    Thanks for the motivation! Consistency will definitely pay off!

  • @francoisguyot789
    @francoisguyot789 Год назад +7

    Congrats ! That's amazing

  • @apostle5135
    @apostle5135 Год назад +6

    big fan)) congrats !

  • @jrsantos1737
    @jrsantos1737 Год назад

    Bro, you're doing well despite of limited hours and having full time job, keep it up. Thank you for sharing your journey.
    You mentioned about hours spent details, this could help me on how to assess my progress also and time need to put up on this endeavor. Goodluck to both of us! Trying to break the barrier to get into Web3 security despite lack of tech and coding background.

    • @andyli
      @andyli  Год назад +1

      Thanks man, good luck to you!

  • @nang88
    @nang88 Год назад +1

    jeez you're a beast

  • @internetkids5813
    @internetkids5813 Год назад +4

    Great stuff

  • @katelibra
    @katelibra Год назад +2

    awsome....

  • @umerjamal3392
    @umerjamal3392 Год назад

    it's really inspirational to see your progress, congrats, just wanted to know which approach do you follow and what your suggestion about it for beginners, like read a lot of reports and then try to find those bugs in code or try to understand whole codebase and then try to break it(which is more tough i think)?

    • @andyli
      @andyli  Год назад

      First read a lot of reports to learn all the common findings people submit. Then dig deeper to try and find unique and creative bugs.

  • @soaphornseuo8630
    @soaphornseuo8630 Год назад +1

    ☺️☺️☺️

  • @spyboy3924
    @spyboy3924 Год назад

    Keep going 👍

  • @imalebowski
    @imalebowski Год назад +3

    The reason you're unhappy with the plateu is because you're a junior pentester. You're pushing against a narrower knowledge/experience base than if you had a bigger background in cryptography or financial app testing. You need to find the optimal amount of time to put in that works for you. For 10 hours a week you're doing really well. Is it worth going back through higher findings you struggled with now you have a few mediums under your belt?

    • @andyli
      @andyli  Год назад +2

      Thanks, good perspective. I will spend a bit more time on fully understanding some of the more higher findings. Need to get more familiar with a testing framework as well.

  • @harshitsharma9474
    @harshitsharma9474 Год назад +2

    Bro can you make a tutorial series on slither and Hardhat... Most of the tutorial out there are... Just simple ones... Introductory...

    • @andyli
      @andyli  Год назад +2

      Patrick Collins has a Solidity tutorial that covers hardhat. I am not an expert in slither, but will look into it

    • @imalebowski
      @imalebowski Год назад +2

      Patrick Ventuzelo (Fuzzing Labs) has a good video on slither. It was great for 0.5 but hasn't kept up to date.

  • @rokinot5523
    @rokinot5523 Год назад +1

    The "last 60 days" can be quite misleading given that half the contests in the last 60 days were not awarded yet. As of now that category more closely resembles mid july~mid may payouts. Don't get discouraged!

    • @andyli
      @andyli  Год назад

      Oh yes, good point!

  • @yahiakhaled4373
    @yahiakhaled4373 Год назад

    Hey @Andy Li ...,
    What about making a video on how to start doing an Audit for a contest from how to know the scope and clone the repo or get the right code to audit till start doing the audit ?
    Is that suitable for U ?

    • @andyli
      @andyli  Год назад +1

      Yeah I have been considering doing a video like this

    • @yahiakhaled4373
      @yahiakhaled4373 Год назад

      @@andyli Thanks Man

  • @funmaker4531
    @funmaker4531 Год назад +1

    Hi bro,
    I having some doubts !!!
    how to deploy the smart contract from etherscan to remix ???

    • @andyli
      @andyli  Год назад

      if you mean deploy a contract from remix, you need to connect your metamask then select the network

  • @yahiakhaled4373
    @yahiakhaled4373 Год назад +1

    teach us how u do auditing or explain how you find your findings... now I'm studying Sans course for blockchain security any other recommendations?

    • @yahiakhaled4373
      @yahiakhaled4373 Год назад

      Just if u loved what u learn u will allow Ur self to continue ..
      I know that he has a road map I just wabt to see how it works by seeing someone doing it .. like PoCs on utube for web 2 bugs

    • @andyli
      @andyli  Год назад +1

      I explained some of my thoughts when I found the 3k bug video

    • @yahiakhaled4373
      @yahiakhaled4373 Год назад

      Of course U did
      And that was helpful
      But I think we need to how it be done from the beginning till u report a finding
      Which tools u used
      Somethings like this Andy

    • @andyli
      @andyli  Год назад

      @@albincsergo2775 the sans course is a super expensive paid course, free resources are better
      secureum.substack.com/
      ethernaut.openzeppelin.com/
      and watch my beginner road map video

    • @markshine6402
      @markshine6402 Год назад

      @@andyli hi i am doing pen-200 right now , would that be of any help ?

  • @fuckyouxx
    @fuckyouxx Год назад +2

    can you teach complete audting? and interacting

    • @andyli
      @andyli  Год назад

      I made a video for that, beginner road map

  • @shpockboss3834
    @shpockboss3834 Год назад

    What tools do you use to find bugs in a contract

    • @andyli
      @andyli  Год назад

      Manual review

  • @pxng0linhxcker927
    @pxng0linhxcker927 Год назад

    did you make your script in JS or Python or something else?

    • @andyli
      @andyli  Год назад +1

      It was in Go. I made a video about it

  • @markshine6402
    @markshine6402 Год назад

    Can you give me some url to learn this. Please help me

    • @andyli
      @andyli  Год назад

      Check out some of my other videos, I made a beginner road map with resources i used