Это видео недоступно.
Сожалеем об этом.

OpenRedirect vulnerability Mass Hunting | Bug bounty poc

Поделиться
HTML-код
  • Опубликовано: 7 мар 2024
  • in this video i am going to show you how to mass hunt for openredirect vulnerability and report to bounty program to earn bounties.
    Disclaimer: This video is for strictly educational and informational purpose only. I own all equipment used for this demonstration. Hacking without permission is illegal so always ensure you have proper authorization before using security tools in any network environment. thanks.

Комментарии • 207

  • @gauravkesharwani5557
    @gauravkesharwani5557 5 месяцев назад +14

    Excellent work bro. I never thought this way

  • @Ajay_Yadav_Smart
    @Ajay_Yadav_Smart 5 месяцев назад +4

    I was waiting for your videos..❤❤

    • @lostsecc
      @lostsecc  5 месяцев назад

      my pleasure bro ❤️😇

  • @harshh25.02
    @harshh25.02 5 месяцев назад +2

    Amazing!!!!🔥Really need tutorials or videos on bug hunting from you!

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      sure all comming soon ❤️

    • @PhvexSeven
      @PhvexSeven 5 месяцев назад

      did u gonna tell us all the stratigys for bug bounty and exploits finding ?
      im having fun see u do that , thats so cool @@lostsecc

    • @REDCULT-is-Live
      @REDCULT-is-Live 5 месяцев назад

      Good job bro. ❤ Appreciate ​@@lostsecc

  • @user-ez3yg9ob6e
    @user-ez3yg9ob6e 5 месяцев назад +2

    super content bro i like your stratagie
    can you plz telme the whole learning path to learn fully like you

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      join telegram i will share all @lostsec

  • @Erbis13
    @Erbis13 5 месяцев назад +2

    love your content bro, hope to be like you someday

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      my pleasure bro ❤️😇

  • @BeBold_05
    @BeBold_05 5 месяцев назад +6

    OP Bro...

  • @deanervinsebial9942
    @deanervinsebial9942 5 месяцев назад +2

    I like your contents. Straight to the point. Where can I get that tool you used to automatically give google dork payloads.

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      thnq so much bro ❤️ join my telegram i will post all tools and payloads @lostsec

  • @d4nm4c
    @d4nm4c 5 месяцев назад +2

    Awesome content bro! With open redirects I’m assuming you can find ways to escalate to a bigger vuln?

    • @lostsecc
      @lostsecc  5 месяцев назад +4

      yes you can perform xss and ssrf

  • @aashishsubedi9144
    @aashishsubedi9144 5 месяцев назад +1

    I see you are using Windows 10 and also opening multiple tabs on terminal..what terminal is that? i guess cmd does not have that feature in windows 10

    • @lostsecc
      @lostsecc  5 месяцев назад

      its window terminal you will found in microsoft store

  • @Mohammed_TURKI66
    @Mohammed_TURKI66 Месяц назад

    keep going

  • @eyezikandexploits
    @eyezikandexploits 5 месяцев назад +1

    Id throw all those in something like dalfox too, maybe even ppmap. I bet those all were made poorly to begin with

    • @lostsecc
      @lostsecc  5 месяцев назад

      dont become independent on tools do manual hunt most of times tool give false postive

  • @eliotsec
    @eliotsec 5 месяцев назад +12

    Which tools and extension do you use?

    • @lostsecc
      @lostsecc  5 месяцев назад +16

      its LinkGopher & OpenRedirex

    • @eliotsec
      @eliotsec 5 месяцев назад

      @@lostsecc thanks sir

    • @Nochymusic
      @Nochymusic 5 месяцев назад +1

      @@lostsecchey how do i connect to you

    • @lostsecc
      @lostsecc  5 месяцев назад +3

      @@Nochymusic telegram @lostsec

    • @Nochymusic
      @Nochymusic 5 месяцев назад

      @@lostsecc cool i just joined your telegram channel👳🏼‍♀️

  • @ahmedelsaedy7426
    @ahmedelsaedy7426 5 месяцев назад

    You deserve a lot of likes ❤❤✔✔

    • @lostsecc
      @lostsecc  5 месяцев назад

      its means lot for me🥰❤️

  • @yungxxilax9194
    @yungxxilax9194 5 месяцев назад

    lostsec, what you do if you dont find any vulns in a bbp? do you keep going or do you change?

    • @lostsecc
      @lostsecc  5 месяцев назад +3

      dont stat too much in one site do your best whatever you learn try them..and just moveon to different target dont wsste much time there are thousands of subdomains so just keep going...

    • @user-cl8gr1sy8i
      @user-cl8gr1sy8i 5 месяцев назад

      @@lostsecc That might be true for this kind of vulnerability findings. But if you want to get paid on hackerone for example you need to spend loads of time trying different kinds of stuff.

  • @AEGIS-RED-MEGA-VIEWS
    @AEGIS-RED-MEGA-VIEWS 5 месяцев назад

    aww the song was so cool, i wonder if i learn haking, will this cool songs pop up on my playlist..

    • @lostsecc
      @lostsecc  5 месяцев назад

      join my telegram @lostsec

  • @suryakiran2632
    @suryakiran2632 5 месяцев назад +1

    Bruh what is that terminal in windows ? Wsl ? Powershell ?

    • @lostsecc
      @lostsecc  5 месяцев назад

      wsl2

    • @suryakiran2632
      @suryakiran2632 5 месяцев назад

      Available at Microsoft Store ? Does it allow root privilege?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      nope

  • @korea7moda
    @korea7moda 5 месяцев назад +1

    good luck bro 😊

  • @NGodgod
    @NGodgod 5 месяцев назад +1

    Broo you are my inspiration ❤😎

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      and you guys are my motivation also ❤️😇

  • @miteshvalvi1170
    @miteshvalvi1170 5 месяцев назад +1

    which extension is used to extract

    • @lostsecc
      @lostsecc  5 месяцев назад

      link gopher

  • @khalidelgazzar4601
    @khalidelgazzar4601 2 месяца назад

    Name of the extension getting all urls ?

    • @lostsecc
      @lostsecc  2 месяца назад +1

      linkGopher

  • @olafcio
    @olafcio 4 месяца назад

    cool videos, but why don't you use keyboard shortcuts? ctrl+c, ctrl+v, ctrl+a

    • @lostsecc
      @lostsecc  4 месяца назад

      i use but sometime not bcz of my placement of sitting and i light off most time so keyboard not show that time

  • @sukremez1870
    @sukremez1870 5 месяцев назад

    how do you find if a website or program has bugs, like i know you had to test it, but do you just go to random and test it one by one by yourself, or you use automation like scrapiing and auto find bugs on website/program?

    • @lostsecc
      @lostsecc  5 месяцев назад

      there are many thing including automation and manual depend on bug ...but first you need to find all subdomains and then filter live host and then extract links and then do automation and also pick one target juicy one and do manual all testing...

    • @sukremez1870
      @sukremez1870 5 месяцев назад

      @@lostsecc how do i find subdomains? do i have to brute force and match it one by one?
      if yes are there any good tools for it?
      or are there optimized technique?

    • @lostsecc
      @lostsecc  5 месяцев назад

      subfinder and amass is best for this or you can use online website also like nmapper or sudomain finder..dont worry all content from staring and ending comming..just stay with me bro ..

    • @sukremez1870
      @sukremez1870 5 месяцев назад

      @@lostsecc yes ofcurse bro, you are one of my reason im starting to like cyber security and it gave me richer knowledge especially cause im in backend area, so you gave me knowledge to make me build more secure software, it looks fun when i watch your videos especially penetrating in web/url area, keep it up, hope the best for you

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️😇my pleasure to hear this from you ...

  • @Naxyzzncs
    @Naxyzzncs Месяц назад

    no way, are you ethersec?, because i am too :)

  • @NinjaLives-rg8vl
    @NinjaLives-rg8vl 5 месяцев назад +1

    Thank you sir !

    • @NinjaLives-rg8vl
      @NinjaLives-rg8vl 5 месяцев назад

      You can click on the mouse wheel if you want to open the link on a new tabs it's more easier and faster

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      oh nicee man i did'nt notice it thank you so much brother ❤️🫂

  • @tanakim
    @tanakim 5 месяцев назад

    What song is this? Wat version of kerosene is this?

    • @lostsecc
      @lostsecc  5 месяцев назад

      rain version

  • @mr-dark
    @mr-dark 5 месяцев назад

    What terminal do I use on Windows in the video?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      search window terminal in microsoft store and install wsl2 in it with kali linux with ohmyposh themes

  • @imreplicanthunter
    @imreplicanthunter 5 месяцев назад

    your google is a little different. you can go to next page or page 1, 2, 3 which i can't. I dont have that option here.

  • @user-fp7fs9xl2t
    @user-fp7fs9xl2t 5 месяцев назад

    Great Content ... Lostsec ...

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️😇Thnq brother

  • @nobad4122
    @nobad4122 5 месяцев назад

    hello bro, im french and I wanted to know if there is a tool to write reports more easily or even automatically ? thx ;)

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      just use chatgpt it will make best report for you ❤️try once

  • @itzxdark
    @itzxdark 5 месяцев назад +1

    Tutorial video plz

  • @thereisnotomorrow0
    @thereisnotomorrow0 5 месяцев назад

    Bro, which extension did you use to view all domains?

    • @lostsecc
      @lostsecc  5 месяцев назад

      link gopher

  • @mr-dark
    @mr-dark 5 месяцев назад

    Well done, brother🎉

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq brother❤️😇

  • @kaqeli
    @kaqeli 5 месяцев назад

    Where do you get bug bounty offers like this?

    • @lostsecc
      @lostsecc  5 месяцев назад

      join my telegram you will no @lostsec

    • @kaqeli
      @kaqeli 5 месяцев назад

      @@lostsecc I already joined

  • @nonidentified89
    @nonidentified89 5 месяцев назад +1

    Bro which extension and tool you used in recon ?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      link gopher & openredirex

    • @nonidentified89
      @nonidentified89 5 месяцев назад +1

      @@lostsecc author or source of openredirex tool bro ?

    • @we__do
      @we__do 5 месяцев назад

      google it@@nonidentified89

  • @yappingchannel20
    @yappingchannel20 4 месяца назад

    where do you get this software bro?

    • @lostsecc
      @lostsecc  4 месяца назад

      dm me.in telegram i will share @lostsec

  • @greggarcia4943
    @greggarcia4943 5 месяцев назад

    Like to learn more on how to bug hunts

    • @lostsecc
      @lostsecc  5 месяцев назад

      join telegram it would be help you t.me/lostsec

  • @techytech2781
    @techytech2781 5 месяцев назад

    bro which google dork were u using?

    • @lostsecc
      @lostsecc  5 месяцев назад

      site:abc.com and redirect= url= etc

  • @TheTrueTrinity888
    @TheTrueTrinity888 5 месяцев назад

    All answers lead to more questions

  • @Dan-km7il
    @Dan-km7il 4 месяца назад

    Can u upload shells using this vulnerability?

    • @lostsecc
      @lostsecc  4 месяца назад

      nope you can try xss ssrf

  • @tranquilla-videos
    @tranquilla-videos 5 месяцев назад

    is this is how bug bounty performed?

  • @devakabari
    @devakabari 5 месяцев назад

    bro witch plugin you use for converting google search to links?

    • @lostsecc
      @lostsecc  5 месяцев назад

      link gopher

  • @ardabruh9086
    @ardabruh9086 4 месяца назад

    How do you make it seem so easy? epic stuff

    • @lostsecc
      @lostsecc  4 месяца назад

      part 2 tcomming soon with whitelist filter bypass 😉

  • @darkmix4192
    @darkmix4192 5 месяцев назад

    Hi bro recently watched your videos, i like this your bounty but, i recently started bug bount. Can you help me?
    How to select website and normal of bugs names tell me bro....main question how to select domains

    • @lostsecc
      @lostsecc  5 месяцев назад +5

      just pick your fav one program.and find all.subdomains and eztract urls and then find all bugs in all parameters i will.make soon playlist for this from start recon to end just wait sometime..

    • @Mustafa-wq6ew
      @Mustafa-wq6ew 4 месяца назад

      @@lostsecc We are looking forward to it bro

  • @Shapeshiftshow
    @Shapeshiftshow 5 месяцев назад

    Nice one brother

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq brother ❤️

  • @ciceroeduardo2859
    @ciceroeduardo2859 5 месяцев назад +1

    awesome, i love you

    • @lostsecc
      @lostsecc  5 месяцев назад

      love you three❤️

  • @xskotaka_
    @xskotaka_ 5 месяцев назад

    bro, where you learning this?

    • @lostsecc
      @lostsecc  5 месяцев назад

      self i just explore things in my own style..

    • @xskotaka_
      @xskotaka_ 5 месяцев назад

      holy nice bro@@lostsecc

  • @monikasharma2931
    @monikasharma2931 5 месяцев назад

    Amazing video ❤😍

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️😇

  • @kushgautam2987
    @kushgautam2987 5 месяцев назад

    Great video bro❤❤

    • @lostsecc
      @lostsecc  5 месяцев назад

      😇❤️thnq bro

  • @keyon_renner
    @keyon_renner 5 месяцев назад

    Yo lostsec do you have a github acc where you share these tools because I can't find them in your tg channel

    • @lostsecc
      @lostsecc  5 месяцев назад

      just msg me.in telegram through bot i will share you all tools or i will share in channel soon..

    • @keyon_renner
      @keyon_renner 5 месяцев назад

      @@lostsecc i did but idk if it worked

    • @lostsecc
      @lostsecc  5 месяцев назад

      @@keyon_renner what not work

    • @keyon_renner
      @keyon_renner 5 месяцев назад

      @@lostsecc i messaged you on telegram i think its not working

  • @SohelPratap
    @SohelPratap 5 месяцев назад

    wow bro since when are you hunting

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      6 month. before i done ceh chfi redhat ccnp and ctf player

  • @sea8367
    @sea8367 5 месяцев назад

    did u using vpn or proxy while hacking?

  • @H4cker_Nafeed
    @H4cker_Nafeed 5 месяцев назад

    Which website you are hunting on ?

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      Russia domains

    • @H4cker_Nafeed
      @H4cker_Nafeed 5 месяцев назад +1

      @@lostsecc i was waiting fir u r video

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      😇❤️Ahhhh my pleasure

  • @HawkPubg48
    @HawkPubg48 4 месяца назад

    wha is tool & extensions

    • @lostsecc
      @lostsecc  4 месяца назад

      link gopher & openredirex

  • @Fury.Editz.54
    @Fury.Editz.54 5 месяцев назад

    Bro which terminal you use?

  • @user-il8yq4po1o
    @user-il8yq4po1o 5 месяцев назад

    keep up m bro

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnq bro 😇❤️

  • @ace-veen35
    @ace-veen35 5 месяцев назад

    First of all, thank you my friend, but what harm can this do?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      you can redirect victim to malicious site and also perform ssrf and xss and many thing...

    • @ace-veen35
      @ace-veen35 5 месяцев назад

      @@lostsecc thanks for your reply you have discord or telegram?

  • @qadeerhussain1430
    @qadeerhussain1430 5 месяцев назад

    Can you please share your google dock search terms thanks

    • @lostsecc
      @lostsecc  5 месяцев назад

      dm me in telegram i will share there all things @lostsec

  • @patfire785
    @patfire785 5 месяцев назад

    Gold bro! thanks

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️☺️

  • @user-pe1og1vs5x
    @user-pe1og1vs5x 3 месяца назад

    share a big bounty recon ?

    • @lostsecc
      @lostsecc  3 месяца назад

      github.com/Viralmaniar/BigBountyRecon

  • @Krjganov
    @Krjganov 5 месяцев назад

    where do you report such websites to get money?

    • @lostsecc
      @lostsecc  5 месяцев назад

      there are some bounty platform in that you can submit but for live website other then bounty program you can report it to there company email

  • @vivaanvivaan3920
    @vivaanvivaan3920 5 месяцев назад

    xss ke mass hunting ke video sir leke ao

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      sure ❤️

  • @bountyvitcim
    @bountyvitcim 3 месяца назад

    tools name (extension, etc)

    • @lostsecc
      @lostsecc  3 месяца назад

      shared in my tg channel t.me/lostsec

  • @user-mr6ok9vs2g
    @user-mr6ok9vs2g 5 месяцев назад

    Can you teach us that how can we also find bug like you?? plz reply if you can
    You videos always motivate me to do so
    keep going bro you doing great🧡🧡

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      sure why not i am uploading soon bug hunting seriess in very essy stepss..you can find bug..

    • @user-mr6ok9vs2g
      @user-mr6ok9vs2g 5 месяцев назад

      thanks bro and can't wait for you series@@lostsecc

    • @ArtOfExploitation
      @ArtOfExploitation 5 месяцев назад

      @@lostsecc thanks brother have voice also THANK YOU

  • @emiltoys8563
    @emiltoys8563 5 месяцев назад

    Not matter u get bug or not the point is the site target is on the list of bug bounty or not if not on the list well that waste time 😅

    • @lostsecc
      @lostsecc  5 месяцев назад

      due to privacy of bug bounty program i cannot show that so but.hope you have idea on live site.

  • @Black_Ghost69
    @Black_Ghost69 3 месяца назад

    song name??

    • @lostsecc
      @lostsecc  3 месяца назад

      kerosene rain edition

  • @RORO-xz4gm
    @RORO-xz4gm 5 месяцев назад

    nice mann

    • @lostsecc
      @lostsecc  5 месяцев назад

      thnks man ❤️

  • @tejaschitkara1531
    @tejaschitkara1531 5 месяцев назад

    Bro but mostly websites with domains like ru and tk don't give bounties

    • @lostsecc
      @lostsecc  5 месяцев назад

      yes its just example so you have idea how to find in real target just add there name in site:ab.com

  • @user-yy7dh9pw3c
    @user-yy7dh9pw3c 5 месяцев назад

    Bruuhhh,
    can i get that framework ?

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      there is person name in twitter just pull put from there

  • @4everforgotten
    @4everforgotten 5 месяцев назад

    ngl i have no idea what’s going on 😅

    • @lostsecc
      @lostsecc  5 месяцев назад

      just search on google what is openredirect vulnerability

    • @4everforgotten
      @4everforgotten 5 месяцев назад

      @@lostsecc okay I appreciate it thanks 🙏🏽
      update: I understand what this means now

  • @didi-sx5cn
    @didi-sx5cn 5 месяцев назад

    Amo tu trabajo amorsito ❤ I Love U ❤

    • @AxthonySS
      @AxthonySS 5 месяцев назад

      he said "sweetheart" to lostsec... asf lol

    • @lostsecc
      @lostsecc  5 месяцев назад

      i love you three ❤️☺️

    • @lostsecc
      @lostsecc  5 месяцев назад

      🌝

    • @didi-sx5cn
      @didi-sx5cn 5 месяцев назад

      ​@@lostseccI love you too much baby, keep up your work 💕

    • @lostsecc
      @lostsecc  5 месяцев назад

      ❤️☺️

  • @DBVLOGS1510
    @DBVLOGS1510 5 месяцев назад

    Extension name bro

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      link gopher

  • @mirozo
    @mirozo 5 месяцев назад

    i dont even understand what was the vul here XDDDD

    • @lostsecc
      @lostsecc  5 месяцев назад

      i give reply to somone just read it

    • @mirozo
      @mirozo 5 месяцев назад

      @@lostseccok thanks i found it

  • @radicc
    @radicc 5 месяцев назад

    Can someone please explain what is going on? ❤😊

    • @lostsecc
      @lostsecc  5 месяцев назад +2

      open Redirect is security vulnerability in this attacker can change the website url redirection by this they can transfer victim to there own phising or milicious site or they can do xsss and steal there cookie and login to there account aka ATO account takeover & they can spread malware by this when victim visit the link there will be malicious file download on there system that will compromise and damage more thing...

    • @radicc
      @radicc 5 месяцев назад

      @@lostsecc ooh makes alot of sense, thank you for the answear man

  • @SU-bsam
    @SU-bsam 5 месяцев назад

    app name or link ??

    • @lostsecc
      @lostsecc  5 месяцев назад

      just search on google opentedirex github

    • @lostsecc
      @lostsecc  5 месяцев назад

      or join channel @lostsec in telegram

  • @itsm3dud39
    @itsm3dud39 5 месяцев назад

    did you get bounty?

    • @lostsecc
      @lostsecc  5 месяцев назад

      its live site not bounty program

    • @itsm3dud39
      @itsm3dud39 5 месяцев назад

      ok@@lostsecc

  • @Aksh.....
    @Aksh..... 5 месяцев назад

    bro you got bounty??

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      its live hunting broo i also done in bounty program

  • @ewvcweddfg
    @ewvcweddfg 5 месяцев назад

    But who cares about open redirects there are so many why report them there useless anyway

    • @lostsecc
      @lostsecc  5 месяцев назад

      that video will help you in real bounty program there you can earn bounty..

  • @lostsecc
    @lostsecc  5 месяцев назад

    join telegram @lostsec

  • @aatankbadboy3941
    @aatankbadboy3941 3 месяца назад +1

    Bro how you report this?? Got 500$ Make video for that..🎉

  • @LostAdmin
    @LostAdmin 5 месяцев назад

    Hello lostsecc

  • @funny_videos31
    @funny_videos31 5 месяцев назад

    bro i need your instagram your telegram your facebook anything bro i want to be your friend to teach me bro big respect

    • @lostsecc
      @lostsecc  5 месяцев назад +1

      just dm in telegram @lostsec nice to meet you bro ❤️