Live Recon and Automation on Shopify's Bug Bounty Program with

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training
    Live Every Friday, Saturday Sunday and Monday on Twitch:
    / nahamsec
    Free $100 DigitalOcean Credit:
    m.do.co/c/3236...
    Follow me on social media:
    / nahamsec
    / nahamsec
    twitch.com/nah...
    hackerone.com/...
    / nahamsec1
    Github:
    github.com/nah...
    Nahamsec's Discord:
    discordapp.com...

Комментарии • 119

  • @kharbandaumang
    @kharbandaumang 3 года назад +62

    this is some GOD-LEVEL recon !!! We want more sessions from Tom. Thanks nahamsec for bringing this to the community and thanks Tom for sparing your time for this!!!

    • @alexander_adnan
      @alexander_adnan Год назад +4

      Lol .. 😂…GOD level would leave you speechless

    • @godspeed2124
      @godspeed2124 Год назад

      @@alexander_adnan what god level according to you?

    • @65hammad
      @65hammad 11 месяцев назад

      @@alexander_adnanyou don't have a clue then. For mass recon, this is GOD-tier automation. These guys can even automate the entire process if they wanted.

    • @alexander_adnan
      @alexander_adnan 6 месяцев назад

      @@godspeed2124 looks like you will find out before others.
      Not a good idea to do reverse psychology, with strangers.
      I would be rational though, there’s no recipe for recon, it depends on your target while Technics matters less than the potential.

  • @cr4zy_0o
    @cr4zy_0o 2 года назад +12

    The calmness that Tom have is really unique, great and fancy.
    + The way he do his things is really epic
    Really a great guy

  • @franco2179
    @franco2179 3 года назад +46

    It's funny because I can tell from Nahamsec's faces that he just loves Tomnomnom. At the same time it makes him laugh that he is so calm when explaining things.

    • @NahamSec
      @NahamSec  3 года назад +27

      Haha! Tom is one of the most genuine and nicest people I have had on the show.

    • @chasejensen88
      @chasejensen88 3 года назад +5

      I think he's also realizing the greatness he's capturing at the moment, he isn't fully comprehending it yet but he knows it.

  • @HenryLawrenceHMBL
    @HenryLawrenceHMBL 2 года назад +11

    I would love to be a Shopify developer watching this unfold

  • @netoeli
    @netoeli 3 года назад +14

    fantastic video , Tom really knows his stuff

  • @IBDLFSEragon
    @IBDLFSEragon 2 месяца назад

    Mind blowing. Thank you so much for giving back to community.

  • @shuvamadhikari2662
    @shuvamadhikari2662 2 года назад +2

    Every week i rewatch your videos; I am learning new things 💙.

  • @vonniehudson
    @vonniehudson 3 года назад +3

    “ass, is that a new tool to compete with meg? I don’t know” had me rolling lololz

  • @hayben7046
    @hayben7046 2 года назад +4

    Thank you both for this great content.
    We want more videos with @TomNomNom.

  • @BnayaProgramming
    @BnayaProgramming 3 года назад +5

    Start at 5:59

  • @rajanrawal6396
    @rajanrawal6396 2 года назад +1

    amazing, this could be probably one of the biggest information that i have ever been given. we need such playlist more and more in upcoming days. i hope i made you understand the things that i wanted to make you understand.. again, we need such playlist more and more in upcoming days.

  • @piusgabula
    @piusgabula 2 года назад

    This is byfar the most incredible live recon i have watched on youtube

  • @mateuszwasielewski7193
    @mateuszwasielewski7193 8 месяцев назад +3

    I started watching this with hope of learning something. Ended with depression and one conclusion - I should stop learning this stuff if I'm gonna need to compete with maaany, maaany people as Tom. And as he said - it was his first attempt since like two years ago. I would need like a week to check all the things that he checked. Now I get it why entry-level positions needs few years of experience but in the same time I don't see a way to get this experience

    • @purplethunder778
      @purplethunder778 6 месяцев назад +1

      If you think that the competitors out there are all as skillful as tom . You are very wrong

  • @ca7986
    @ca7986 3 года назад +4

    Tom is really really good! He knows what he is doing! Amazing! Thanks Nahamsec for this video.

  • @bertrandfossung1216
    @bertrandfossung1216 3 года назад +11

    This is epic!! I've have to watch this video over 10 times just to understand Tomnomnom's recon process. The guy is really really good at what he does. Thanks @nahamsec & @Tomnomnom🙏🏽🙏🏽🙏🏽

  • @jeffreynoose
    @jeffreynoose 2 года назад +1

    I can watch these 50 times daily I love nomnom

  • @joefawcett2191
    @joefawcett2191 Год назад

    these vim and bash skills are really something to behold

  • @samfisher8426
    @samfisher8426 Год назад +3

    maan seeing how tom is working makes me feel down, this dude is so good

  • @abdul-rahman7608
    @abdul-rahman7608 Год назад +1

    Tom is a genius I must confess 🖤💯

  • @ashleypursell9702
    @ashleypursell9702 3 года назад +4

    i was literaly looking for something just like anew to use in my automation since i run scans everday i want to add stuff to already existing txt files. i have seen people use it and idk why i only found out about it rn, great video thanks so much

  • @crusader_
    @crusader_ 3 года назад +7

    Could you please upload all the other recons

  • @xrfox1634
    @xrfox1634 3 года назад

    I love this man!

  • @gifbfbvhvhdhfhfjffjfnfhfb515
    @gifbfbvhvhdhfhfjffjfnfhfb515 Год назад

    best video ive seen in a long time

  • @danieltamang2289
    @danieltamang2289 2 года назад

    finally, the two underrated hunters!!

  • @theys6837
    @theys6837 3 года назад +2

    *TomNomNom* is a FKIN G 💯👏

  • @baolamminh1146
    @baolamminh1146 3 года назад

    I improve my bash skill much when watching this video. thanks Tomnomnom & Nahamsec

  • @soloapplications9466
    @soloapplications9466 3 года назад

    Awesome video, I loved you Tom

  • @affulsamuel728
    @affulsamuel728 7 месяцев назад

    That is why Hacking is time and patience game. i love the way he spend days to come on this i love this channel

  • @ggmaxx66
    @ggmaxx66 3 года назад +3

    "...previous versions can be a goldmine" wow!

  • @The1994mattj
    @The1994mattj 3 месяца назад

    Would be interesting to see how different the process/tools look 3 years on.

  • @thenarrowgate3063
    @thenarrowgate3063 4 месяца назад

    I wish I had vim mastered in this way, I use nano which has some of the same features but vim has way more flexibility it's a language all it's own and it's why hackers prefer it, I mean true command based hackers..windows has spoiled this generation..nothing wrong with a GUI but hacking is about control and putting that level of control in a GUI is a major resource hog..TOM you are a dying breed, my hats off to you..grey that is

  • @chiragagrawal7856
    @chiragagrawal7856 3 года назад +1

    Was it Recon Only ? Completely Mind Blowing stuff I saw today 🙌🙌🙌🙌🙌

  • @ar-uh1dj
    @ar-uh1dj 3 года назад

    He is truly a Genius!!!!!!!

  • @0xsunil
    @0xsunil 3 года назад +1

    Tom is best!

  • @Rashedulcss
    @Rashedulcss 3 года назад

    Thanks Tom!

  • @Stas1983ful
    @Stas1983ful 3 года назад

    Very nice and interesting video bro!

  • @mrrexder7910
    @mrrexder7910 Год назад

    #TOMNOMNOM FOR EVER!

  • @localmega5824
    @localmega5824 2 года назад

    Two masters at work

  • @otukencoffee7273
    @otukencoffee7273 3 года назад

    Tom is such a wizard

  • @remonsec1641
    @remonsec1641 Год назад

    insane 🔥

  • @ahmedahmedx9600
    @ahmedahmedx9600 3 года назад +1

    please which terminal theme tomnomnom used ?

  • @farhonahmed5081
    @farhonahmed5081 Год назад

    farhan ahmed was here at 10-31-22

  • @n0w0nd3r5
    @n0w0nd3r5 3 года назад +2

    It would be cool if you could list every command tomnomnom uses in this video in the description with a timestamp so people can go directly to that section to see what it does.. Or just watch the video.

    • @n0w0nd3r5
      @n0w0nd3r5 3 года назад

      @hackR That's Cool.

  • @thatguycrash2255
    @thatguycrash2255 3 года назад

    tomnomnom the goat

  • @bughunt2568
    @bughunt2568 2 года назад

    could you please share your recon methodology you applied on redbull as target.

  • @razmjumehdi9069
    @razmjumehdi9069 11 месяцев назад

    Hello Ben 😊. please make a video about "Finding origin IP behind AWS CDN", because i searched a lot, but i found only video about Cloudflair bypass 🙏

  • @saivenkatmaheshwaram9868
    @saivenkatmaheshwaram9868 3 года назад +1

    i didn't understand how he learn all this things and how he remember this all this commands and their particular options of a tools..

    • @parkour.11parkour58
      @parkour.11parkour58 2 года назад +2

      Probably because it's an hobby for him.
      When you're not forced to do something that you love, you usually become an expert at it.

  • @charonxxi5985
    @charonxxi5985 3 года назад

    💯

  • @sadraasadi
    @sadraasadi 2 года назад

    Nice :)

  • @naveensaradhi6923
    @naveensaradhi6923 3 года назад

    We want more live with tom #request

  • @lufom
    @lufom 2 года назад

    Is he previewing the `find` results? Does anyone know how to do that?

  • @faris9859
    @faris9859 2 года назад

    anew installation as mentioned in github not working for me. Anyone facing issues?

  • @user-jr3qf7cq5q
    @user-jr3qf7cq5q Месяц назад

    hey!!))) where i can find list configfiles ?))

  • @MrRaja
    @MrRaja 2 года назад

    Anyone got the list of all tomnomnom tools used in the video?

  • @shuvamadhikari2662
    @shuvamadhikari2662 2 года назад

    Still in a dilemma how to filter hosts on basis of response body from fff; since, every host is responding with 200 OK 😢.

    • @rajanrawal6396
      @rajanrawal6396 2 года назад

      they are not filtering hosts they are just checking those hosts which thet have got liittle bit doubt

  • @rushikeshchaudhari476
    @rushikeshchaudhari476 Год назад

    How I can start with lve website bug bounty hunting

  • @orxanovn5057
    @orxanovn5057 2 года назад

    naham bro this is gf and fff methodology or bug bounty methodology?))))

  • @imuser007
    @imuser007 3 года назад

    I like tom

  • @yaseenzubair8792
    @yaseenzubair8792 2 года назад

    Is tom operating himself on 1.5x?

  • @MrRaja
    @MrRaja 2 года назад

    I am not even sure what i am looking at. I know what he is looking at but i have no clue what to do with what he is looking at.

  • @baravind719
    @baravind719 3 года назад +1

    Huh man ...

  • @jayesh6290
    @jayesh6290 Год назад

    Here Kali Linux is used right ?

  • @ajaykumark107
    @ajaykumark107 2 года назад +2

    In the webpaste part the value he uses @1:06:26 are
    Code:
    [...document.querySelectorAll('div.g a:first-child')].map(n=>n.href)
    On Success:
    document.location=document.querySelectorAll('a#pnnext')[0].href;

  • @user-xd4sb5rq4o
    @user-xd4sb5rq4o 3 года назад

    🕵‍♀

  • @CyberSecForce
    @CyberSecForce 3 года назад

    Hi 👋

  • @SrTCOT
    @SrTCOT 3 года назад

    In this video I learned a lot of things thank you so much Nahamsec

  • @beelostlove
    @beelostlove Год назад

    Just gave up her cover

  • @learnwithpikes
    @learnwithpikes 3 года назад

    what's up behrouz ?? how are you ??

  • @beelostlove
    @beelostlove Год назад

    So what's this worth this bug

  • @beelostlove
    @beelostlove Год назад

    Hi did you miss me

  • @shrumplestiltskin7922
    @shrumplestiltskin7922 Год назад

    Where do we get the ass tool?

  • @Kas_Styles
    @Kas_Styles 2 года назад

    Just to point out that Auv5 is the Shopify security team member. Does anyone know if they have a twitter account?

    • @lilyrosestracke4591
      @lilyrosestracke4591 2 года назад

      ...And this, ladies and gentlemen, is how you know you have failed recon101! 😅😜😉

    • @Kas_Styles
      @Kas_Styles 2 года назад

      @@lilyrosestracke4591 don't know why my comments keep getting deleted but I'll try posting it again

    • @Kas_Styles
      @Kas_Styles 2 года назад +1

      @@lilyrosestracke4591 I'm actually really good at recon. I have a public playlist (all osint videos) with at the time of writing this comment it's has 407 videos in it so from that you can tell that I know a lot about the topic.

    • @Kas_Styles
      @Kas_Styles 2 года назад

      @@lilyrosestracke4591 also, I have checked Google with Google dorks and Twitter and I didn't find anything related to the username.

    • @Kas_Styles
      @Kas_Styles 2 года назад

      @@lilyrosestracke4591 and another thing, you shouldn't be rude to others in general. I asked because I already did some research and I couldn't find it so I was asking.
      It's OK to ask questions, if anything its good and its how humans learn.
      Also, it's a social engineering skill which is used a lot in infosec so please don't share the idea that asking questions (after doing research and not finding anything useful/related) is bad because it's 100% not bad.

  • @Kas_Styles
    @Kas_Styles 2 года назад

    Whoxy the website can get historical whois.

  • @haxwizard2035
    @haxwizard2035 3 года назад

    😁😀😁😁😁😁😁

  • @LetsGoTech
    @LetsGoTech 2 года назад

    Problem number one I'm on Windows

  • @Virdoex
    @Virdoex 3 года назад

    Hey @Nahamsec what you deal with 403 subdomains

    • @bobmarley8644
      @bobmarley8644 3 года назад +6

      Just keep bruteforcing for directories, maybe /login will return 200 or /api will return 400

    • @robinhood3841
      @robinhood3841 3 года назад +4

      i had a scenario where i have found a directory which returns 403 forbidden, so i kept brute forcing on that directory and eventually i got PhpMyAdmin mysql page and it was accessible for anyone and i was able to successfully login with a weak credentials :), thats why u shouldn't stop on a 403 they made it forbidden for a reason and simple miss configuration may give you a high result.

    • @Sakuraigi
      @Sakuraigi Месяц назад

      ​@@bobmarley8644and for 401?

  • @sandeepsingh87
    @sandeepsingh87 2 года назад +1

    Na bhai tune subtitles diye, na tune tools explain kre, aur apni accent mei tum log bol kya rhe ho ghanta samajh nhi aa rha ... Khud hi seekh le bhai, jab ye samajh aa jae ki "padhate kaise hai" tab video upload kr dena

    • @hellb0y794
      @hellb0y794 Год назад +1

      Ist: it's not his problem if you don't understand english
      first clear your basics then come here.
      they both are doing great work

    • @sandeepsingh87
      @sandeepsingh87 Год назад +1

      @@hellb0y794 Fucking Dimwit, atleast read what I've written before commenting. I wrote "accent".
      Simplifying it for you,
      What it means is that, I do know English however I am having difficulty understanding their accent (Google the meaning of accent for more information)
      Also if you've even seen the starting of the video, you'll notice they are not teaching the basics here, they are talking about approaching a target i.e., their methodology.
      So, your statement about basics don't even make sense.
      I mean I don't mind you standing up for the hackers you admire but at least make some logical statement.
      Even I know these hackers know a lot more than me, but they have little to no idea "how to teach". This could've been structured into a nice course.

  • @chiyoalice327
    @chiyoalice327 Год назад

    Tom is not someone to follow . No
    My brain cells 😪 😭😭😭😭😭

  • @aminumuhammed3114
    @aminumuhammed3114 3 года назад +1

    I think this is the most useful technical video that is related to recon / bug bounty
    thank you @nahamsec
    thank you @tomnomnom

  • @sushantr24
    @sushantr24 2 года назад

    Cat from-findomain | why i m unable to run the command

  • @snehadeepgolui3757
    @snehadeepgolui3757 5 месяцев назад

    github dork not working please help
    [...document.querySelectorAll('.codesearch-results a.v-align-middle')].map(n=>n.href) it is not working