Watch me hack a bug bounty-like target from scratch.

Поделиться
HTML-код
  • Опубликовано: 29 сен 2024
  • In this video, I will demonstrate a bug bounty hunting methodology on a CTF website that mimics a bug bounty target. I will start from scratch and become admin on multiple web applications. Many techniques will be used: Subdomain enumeration, directory bruteforcing, using tools such as assetfinder, ffuf and Burp Suite Intruder.
    - Download your FREE Web hacking LAB: thehackerish.c...
    - Read more on the blog: thehackerish.c...
    - Support this work: thehackerish.c...
    - Facebook Page: / thehackerish
    - Follow us on Twitter: / thehackerish
    - Listen on Anchor: anchor.fm/theh... Listen on Spotify: open.spotify.c...
    - Listen on Google Podcasts: podcasts.googl...
    Thumbnail photo by Andrea Piacquadio from Pexels

Комментарии • 55

  • @bertrandfossung1216
    @bertrandfossung1216 3 года назад +12

    This video met me at the right time. Thank you very much. I'll definitely learn a lot from it.

    • @thehackerish
      @thehackerish  3 года назад

      Glad the timing was perfect for you ! Enjoy

  • @CristiVladZ
    @CristiVladZ 3 года назад +10

    Looking forward to reading it!

    • @goooooo9197
      @goooooo9197 3 года назад +4

      I think you don’t do ctf you do real thing called bug bounty

  • @TheWhaleon
    @TheWhaleon 2 года назад +7

    I've taken a few bounty Udemy courses and have watched a ton of video guides on youtube and other places. I wouldn't say I'm new to the content but I'm definitely not a professional when it comes to bug bounties. I'm not even 5 minutes into this video and have already dubbed this one of the best beginner videos I've seen so far. Why? Because the step-by-step example methodology and information is gold.. Not really found in other places as far as I've seen so far. Other typically explain their seemingly complex methodology that they have adopted, and beginner courses tend to focus on very beginner content. This has been middle ground information that is really useful! Looking forward to more!

    • @thehackerish
      @thehackerish  Год назад +3

      I am glad your found the content helpful! Thanks for sharing your feedback!

  • @itsalgore
    @itsalgore 4 месяца назад

    This is the most educative video so far, been going in circles

  • @zerobyte536
    @zerobyte536 Год назад

    Lol clicked video because it said you were going to hack an actual bugbounty target, then i see its a ctf. Was going to say how did het get to release this! Every bugbounty i have ever done has a non-disclosure. Lol any way good video for beginners

    • @thehackerish
      @thehackerish  Год назад

      I had permission from one developer to release a video doing bug bounty, well... web hacking, cuz I did it for free. Check it out, ruclips.net/video/aiOq-yOzgW0/видео.html

  • @chrismcnabb3134
    @chrismcnabb3134 3 года назад +2

    Great video! Thanks! Is the "A Bug Bounty Hunting Journey" book available yet?

    • @thehackerish
      @thehackerish  3 года назад

      It is available: www.amazon.com/dp/B08T81PP65/

  • @Arfat-Khan
    @Arfat-Khan Год назад

    I have exploit no rate limit, but now its been duplicate, what else i can do based on no rate limit. Further what can i exploit?

    • @thehackerish
      @thehackerish  Год назад +1

      bruteforce directories for interesting ones? passwod spraying using a custom wordlist?

    • @Arfat-Khan
      @Arfat-Khan Год назад

      @@thehackerish ok thanks

  • @karthik3913
    @karthik3913 Год назад

    Idk why iam always finding errors while running the tools I applied as same as u applied

  • @vihangadeshan2587
    @vihangadeshan2587 3 года назад +2

    Really Helpful. Where can I find the e-book (A bug bounty hunting journey...)

  • @user-tg6vk4ig3i
    @user-tg6vk4ig3i 3 года назад +2

    Awesome. Maybe you can show us more challenges from this website and how you solve them:) It was a great help for me understanding how an Bug Bounty researcher is thinking!

    • @thehackerish
      @thehackerish  3 года назад +1

      As much as I'd love to, this might spoil the fun for you and skew the leaderboard on the website. I will think about it though.

    • @user-tg6vk4ig3i
      @user-tg6vk4ig3i 3 года назад

      @@thehackerish Thank you so much!

  • @Xplo8E
    @Xplo8E 3 года назад +1

    Finally what I wanted I got🔥❤️👍

  • @jissjose1382
    @jissjose1382 3 года назад +2

    This was the one i searching for

    • @thehackerish
      @thehackerish  3 года назад

      I am glad you liked it :) Enjoy!

  • @naumanalam1
    @naumanalam1 3 года назад +1

    I just say woowwwww

  • @medjassertoubib4467
    @medjassertoubib4467 3 года назад +1

    those are the kind of video we want to see . great video dude wish you all the best

  • @jbrown8274
    @jbrown8274 3 года назад

    so do the flags coincide with vulnerabilities within the domain, if this was real life would those flags be something that could be abused and therefore reported in a BB report?

    • @thehackerish
      @thehackerish  3 года назад

      Some, not really. Others, definitely! It depends on the situation.

  • @avijitmazumder1762
    @avijitmazumder1762 2 года назад

    Just the video I wanted. Thanks.

  • @maheshkarunanithi2970
    @maheshkarunanithi2970 3 года назад

    alternative for burp collabrator

  • @darshanjogi5781
    @darshanjogi5781 3 года назад +1

    nice video

  • @position876
    @position876 3 года назад

    When did a CTF become a "bug bounty target"?

    • @thehackerish
      @thehackerish  3 года назад +4

      When we started watching new websites providing bug bounty-like challenges in the form of a CTF.

  • @xbparmar
    @xbparmar 3 года назад +1

    Awesome ❤️

  • @a.for.arun_
    @a.for.arun_ 2 года назад

    Great content 👍🏻

  • @Adam-wc5ol
    @Adam-wc5ol 3 года назад

    Nice video

  • @ahmedehab6899
    @ahmedehab6899 3 года назад

    great video i'm Looking forward to reading the book

  • @psychoSherlock
    @psychoSherlock 3 года назад +1

    You deserve more 👏👏👏

    • @thehackerish
      @thehackerish  3 года назад +1

      Appreciate your comment! Share the channel in your hacking surroundings buddies :)

    • @psychoSherlock
      @psychoSherlock 3 года назад

      @@thehackerish did already..... Ma discord buddies are on the way.... 😄

    • @thehackerish
      @thehackerish  3 года назад +1

      @@psychoSherlock You are the best!

    • @psychoSherlock
      @psychoSherlock 3 года назад

      @@thehackerish Nop, you are. I felt like you teach something in a way no other RUclipsrs does........ That's y I asked them....

  • @goodboy8833
    @goodboy8833 3 года назад

    Very Good Quality content.

  • @xrfox1634
    @xrfox1634 3 года назад

    Thanks for the video!

  • @asaad0x
    @asaad0x 2 года назад +1

    Wow That was so smooth makes it look very easy to be hacker 😁 keep going bro