My First Bounty Award

Поделиться
HTML-код
  • Опубликовано: 23 апр 2022
  • My first bounty award from a Code4rena audit contest. Solidity smart contract auditing.
    code4rena.com/
    cmichel.io/how-to-become-a-sm...

Комментарии • 50

  • @andyli
    @andyli  2 года назад +2

    1 month update ruclips.net/video/Gxg90os6Lvk/видео.html

  • @EnigmaticRapper
    @EnigmaticRapper 2 года назад +34

    Awesome video. I'm 60 now and just starting to learn about security and such to get into bug bounty hunting as an old retired man. I'm strickly going to teach myself using the internet "Google searching with Dorks" and RUclips videos. No need to get into security as a job, or get hired, at my age. But it will be something "other than watching TV all day" to pass my time a little more productively.

  • @gkags2848
    @gkags2848 2 года назад +7

    This is fantastic, thanks a lot for all the resources you are curating here, it is so welcome !

    • @andyli
      @andyli  2 года назад +1

      Glad you enjoy it!

  • @benbeale2727
    @benbeale2727 2 года назад +4

    I've been lurking in their Discord, and I think you've just convinced me to jump all the way in!

    • @andyli
      @andyli  2 года назад

      nice, good luck!

  • @frametrails
    @frametrails 2 года назад +6

    Hi Andy, good to watch your new video. It’s been a month I was waiting for another great video. Your content is great as usual. Keep it up buddy. 👍🏻

    • @andyli
      @andyli  2 года назад +1

      Hey, thanks!

    • @chitralima2208
      @chitralima2208 2 года назад

      @@andyli we want more videos like this Mr Li

  • @jaym4697
    @jaym4697 2 года назад +1

    Came for the osrs content. Stayed because your passion for all things you do.

  • @yufang173
    @yufang173 2 года назад +3

    Great video, informative, thank you, sir.👍

  • @devadevans700
    @devadevans700 2 года назад +2

    hey love you , u are an inspiration

  • @apostle5135
    @apostle5135 2 года назад +1

    awesome content dude :) looking for more videos on these !

    • @andyli
      @andyli  2 года назад

      Thanks! More content on this soon

    • @apostle5135
      @apostle5135 2 года назад

      @@andyli one more question , how long do they take to decide/award a bounty after reporting ?

    • @andyli
      @andyli  2 года назад

      @@apostle5135 at the moment around 20-40 days

  • @yourdailyblockchain
    @yourdailyblockchain Год назад

    Great video thanks

  • @jeffcui3660
    @jeffcui3660 2 года назад +1

    This is amazing. Do you recommend any way to learnt about solidity security?

    • @andyli
      @andyli  2 года назад

      Thanks. I talk about some of the learning resources in my videos. Secureum is a good place to start
      secureum.substack.com

  • @jxkz3
    @jxkz3 2 месяца назад

    Can you share some roadmap or anything for learning web3 bug hunting

  • @ka2edking507
    @ka2edking507 2 года назад +2

    Dude just question : can penetration tester keep all his work remotely for example like ur current role. Can u do the work done from home without going to office. "not bug bounty hunting" just real pentest like external/internal. Or this feature for programers only.

    • @andyli
      @andyli  2 года назад +1

      at the moment I am working pretty much entirely at home, definitely possible

  • @MufazaPT
    @MufazaPT 2 года назад +2

    Can I start on junior penetration tester job without experience with these 4 certificates ?
    Comptia A+
    Comptia Security+
    Comptia Network+
    Comptia Pentest+

    • @andyli
      @andyli  2 года назад +1

      Some IT experience and those certs would get you a job. Otherwise without experience I recommend the OSCP to show practical skills

  • @computerscience1008
    @computerscience1008 Год назад +1

    Hello dear, thank you for this wonderful video. I have a simple question
    what level of programming do I need to learn and after that I learn bug bounty ?
    And Thank you very much 🤗🤗

    • @andyli
      @andyli  Год назад

      Mostly you will be reading a lot of Solidity code. I recommend going through a few tutorials to understand the language.

    • @computerscience1008
      @computerscience1008 Год назад

      @@andyli
      Thank you

  • @ashhadali7592
    @ashhadali7592 2 года назад +1

    Will u create a video how to start auditing? smart contract bug bounty

    • @andyli
      @andyli  2 года назад +1

      yeah I made a video on that

  • @muratkurtulus151
    @muratkurtulus151 2 года назад

    Can you share the links of the discord channels related to the security you joined? thanks

    • @andyli
      @andyli  2 года назад

      Code4rena
      discord.gg/q3Ty5dEQes
      Secureum
      discord.gg/BxDEW6xRRF
      Smart Contract Developer
      discord.gg/r8VbC4HdGW
      Damn Vunerable Defi
      discord.gg/uKAqmvE9t5

  • @shockblockjohnson4599
    @shockblockjohnson4599 2 года назад +1

    Hello, can you please do a video regarding the legal risks involved in doung bug bounty? It's a critical issue that surprisingly doesnt get addressed. Thank you.

    • @andyli
      @andyli  2 года назад

      You just need to make sure to stay in scope when testing production systems. For code review type bounties there is no concern

    • @shockblockjohnson4599
      @shockblockjohnson4599 2 года назад

      Thank you so much for the reply! I do have one more question if you don't mind:
      Do I need to contact the company first before hunting? Or can I just start hunting right away as long as they have a public program on a platform like hackerone, and I stay within the scope as you mentioned?
      Thank you for your time!

    • @andyli
      @andyli  2 года назад

      for public programs you can just start

    • @shockblockjohnson4599
      @shockblockjohnson4599 2 года назад

      @@andyli Ok thank you very much!

  • @hell0kitje
    @hell0kitje 2 года назад +1

    wow there are 6 contents now live, if you find more bugs maybe some video analysis one of them?

    • @andyli
      @andyli  2 года назад +1

      Yeah crazy, I did submit some findings for them. Planning to do more videos on this

  • @44azeaze8
    @44azeaze8 Год назад

    what is the best thing to do when u burnout ?

    • @andyli
      @andyli  Год назад +2

      Don't be too hard on yourself if you burn out. Exercise, go to the gym helps too

  • @prosperdeogratius4888
    @prosperdeogratius4888 2 года назад

    I thought I clicked fast..but its 21 minutes late.fuck youtube algo

    • @andyli
      @andyli  2 года назад

      first comment! :)

    • @prosperdeogratius4888
      @prosperdeogratius4888 2 года назад

      @@andyli keep the good work up man..this inspiration is so much helpful..I decided to reduce some efforts in network penetration based CTFs and learn web app development well before I fully focus on web apps vulns,the idea of learning owasp top 10 without knowing how sql and how all those injections come about sounded like a shortcut to me...so just decided,I'll re-do all this in a year or more,wish me luck Li🤣🤣

  • @reikoobray2573
    @reikoobray2573 2 года назад +1

    😻 𝚙𝚛𝚘𝚖𝚘𝚜𝚖

    • @andyli
      @andyli  2 года назад

      👍🏻