Finding Your First Bug: Finding Bugs Using APIs

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024

Комментарии • 131

  • @tayfun6378
    @tayfun6378 4 года назад +25

    you've improved the sound quality

    • @InsiderPhD
      @InsiderPhD  4 года назад +9

      I finally figured it out!

  • @digitaldina
    @digitaldina 4 года назад +18

    Your videos are a gold mine! Thank you so much for making them free accessible and so understandable ❤️

  • @charvi444
    @charvi444 4 года назад +48

    Nobody:
    InsiderPhD: "Howevaaaaaaar...."

  • @mrtk-ph5sy
    @mrtk-ph5sy 3 года назад +4

    Really love your series 💖
    I found my 1 st paid bb this week after completing your series love you 😘

  • @gamlielhernandez974
    @gamlielhernandez974 3 года назад +2

    I stumbled with your videos while searching for how to start with API hacking, I found you and all I can say your videos are GOLD!!!
    Thank you so much for sharing your time and knowledge with the Community.

  • @MH-tw1qi
    @MH-tw1qi 4 года назад +9

    I spent all my day with this video it's really great I tried hunting all day I didn't hunt :) anything but I'm happy because I collect a lot of knowledge thanks for your tips

  • @ICTSecurity
    @ICTSecurity Год назад +1

    You are an outstanding educator, please keep doing it! I just wanted to learn about enumeration for a project but now I'll binge the whole channel.

  • @nirchoubey2011
    @nirchoubey2011 4 года назад +2

    Wanted to point out a small mistake. At 5:02 you said name is menu and value is curly braces. Actually value for that menu is an object starting with a curly braces.
    Thanks for all your effort. You are doing great.

    • @InsiderPhD
      @InsiderPhD  4 года назад

      You're absolutely correct, thank you for pointing out my mistake, I will issue a correction in the description

  • @cyberwolf7385
    @cyberwolf7385 4 года назад +4

    You are an amazing teacher Katie!! One can just watch your videos and start a career in Bug bounty hunting. Keep posting more videos. I love your content. You have helped me a lot. Thanks for everything.

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      Aww thank you for being a supporter of my work

  • @jalapenohiway
    @jalapenohiway 2 года назад

    Ok this was.....BY FAR the BEST video I've seen on YT, for "Introduction to APIs", "API Basics", & "API Recon & Pentesting"! It was extremely useful & clear/concise information that thoroughly explained all subject matter at hand. TY soo much!!!! I'm super happy I found your channel!

    • @InsiderPhD
      @InsiderPhD  2 года назад +1

      Wow, thank you so much

  • @karim3741
    @karim3741 Год назад +5

    a great teacher, amazing and detailed explanation, thank you for your efforts ❤️🔥

  • @TheMortemGaming
    @TheMortemGaming 4 года назад +3

    Been bouncing around the channels not in order XD but I have to say i love this video and the way you taught it, they keep gettin better and better from what ive seen and super nice to take notes and follow along! Thanks again for the free knowledge !

  • @NanoCyberSec
    @NanoCyberSec 4 года назад +1

    I am OSCP/OSWE.. and i am starting to learn from you thanks @InsiderPhD keep the greater work up

  • @ploutosroman4206
    @ploutosroman4206 4 года назад +4

    Nice thank you! Been looking for a detailed api bug video.

  • @Shogunxd3-vp9jv
    @Shogunxd3-vp9jv 4 года назад +2

    This is what I was going to learn about today too! This is amazing! Thank you so much!

  • @shivanshusahu6121
    @shivanshusahu6121 3 года назад +1

    the way you explain things is just awesome.

  • @Naha-ir9mi
    @Naha-ir9mi Год назад +1

    This is still a well made presentation after 2 years.

  • @jacobpetrov4041
    @jacobpetrov4041 4 года назад +1

    Great video, this series is really helping me out. Looking forward to the next one!

  • @kavishgour3267
    @kavishgour3267 4 года назад +2

    My favourite youtuber at the moment :)

  • @allan_bomb
    @allan_bomb 3 года назад

    thank you, thank you and thank you! Keep up the great work! Looking forward seeing more of your videos.

  • @satyaprakasha9356
    @satyaprakasha9356 3 года назад +1

    Your voice gives me a motivation, thank you so much❤❤❤❤

    • @InsiderPhD
      @InsiderPhD  3 года назад +1

      Hell yeah! Good luck on your hacking journey I’m glad I could inspire you

  • @kandarpmishra6009
    @kandarpmishra6009 3 года назад +1

    can you please elaborate what is "endpoint" at 33:52?

  • @AdnanDhinojwala
    @AdnanDhinojwala 4 года назад +1

    Was really waiting for something like this, Thank you so much

  • @sumitkhadka5123
    @sumitkhadka5123 3 года назад

    was looking for information and what u are doing for the community and for all is very helpful thank u for ur beautiful content

  • @lifeofsq5653
    @lifeofsq5653 11 месяцев назад

    Hello Katie Its wonderful explanation can't wait to test APIs. Thankyou for sharing valuable information :))

  • @thecast9864
    @thecast9864 2 года назад

    love the comments on your notes "seems sus come back"

  • @ramsekargnanasekar9384
    @ramsekargnanasekar9384 4 года назад +1

    Really informative video, thanks!!!!!!
    I have a doubt when I saw zomato api , it showed a list of many GET method , like GET restaurant name, GET location name etc , so should I type the resto name and city name and try to capture the request using burp and run the response. Is this the method like what you are trying to explain?????

  • @felipeolea8810
    @felipeolea8810 2 года назад

    Fantastic video, where shoould we look if we cant acces any ways to the apis becauser we dont have the crfs token or auth?

  • @mashin4777
    @mashin4777 2 года назад

    Thank u, it's really feels like, you have a talent of teaching people

  • @selimeneskaraduman6935
    @selimeneskaraduman6935 4 года назад +3

    How do you find xss in API? API responses are json content type is xss possible?

    • @InsiderPhD
      @InsiderPhD  4 года назад +3

      The primary attack is using it to bypass any client-side WAF filters, but you should have a look at XSS write ups with APIs, I added one in the description but there are many others

  • @RinkuVaghela
    @RinkuVaghela 4 года назад

    I really apricated your hard work behind your videos .. I love all the videos and learn lots of things thanks a lot

  • @optional6719
    @optional6719 2 года назад

    can websites restrict you to use burpsuit to intercept the requests. I am dealing with a website which is restricting me to use it there and its making it really hard to enumerate the good stuff. any help?

  • @Socversity
    @Socversity 4 года назад

    It’s really Great, thank you for changing your mic 😁😁😁

  • @JohnCiprian
    @JohnCiprian 4 года назад +1

    Great content. Keep it coming!

  • @omnnnooy3267
    @omnnnooy3267 2 года назад

    I am so happy I find your channel 🤩

  • @renganathanofficial
    @renganathanofficial 3 года назад

    you used mouse to write, that's awesome xD

  • @cyber__hawk5555
    @cyber__hawk5555 2 года назад

    Awesome 👍

  • @goldengreengrass
    @goldengreengrass Год назад

    Thank you Katie for this wonderful lesson...😄😄

  • @shift3y
    @shift3y 3 года назад +1

    This is brilliant, thank you! Any suggestions on where I can find CTFs to practice these techniques?

    • @TalsonHacks
      @TalsonHacks 3 года назад

      PortSwigger’s Web Security Academy, PentesterLab

  • @shekharwagh4982
    @shekharwagh4982 3 года назад

    Xcellent Video for Developers trying to start Hacking

  • @helalsadat2077
    @helalsadat2077 2 месяца назад

    Starting TOday Lets rock and roll :))

  • @buricobain23
    @buricobain23 4 года назад +1

    Hello is it possible that you can make some video about APIs and perform security tests on PostMan and script? Excellent work I've learned a lot from you.

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      This is coming soon :) I’m going to do a video on more API testing tools!

  • @kabirsuda
    @kabirsuda 3 года назад

    Really helpful video keep it up!

  • @rohullahafzali1587
    @rohullahafzali1587 Год назад

    Thanks for your great contents.

  • @eed5278
    @eed5278 4 года назад

    Wow! Good work, very clear.

  • @aksharpatel1097
    @aksharpatel1097 4 года назад +1

    Is there something i should know about before starting to learn this?? As i find this quite difficult in some parts

    • @InsiderPhD
      @InsiderPhD  4 года назад +2

      Try to watch my finding your first bug series in order, but you do need to know a little about how the internet works first! Let me know what you’re struggling with specifically and I’ll try to make more videos on it

    • @aksharpatel1097
      @aksharpatel1097 4 года назад +1

      @@InsiderPhD thanks!

  • @pankajprasad9179
    @pankajprasad9179 4 года назад +1

    Really help full thank you

  • @digitalcynicism
    @digitalcynicism 10 месяцев назад +1

    Microwave Oven, doo Doo Doo Doo Doo doo

  • @WaheedIqbal-gb3yt
    @WaheedIqbal-gb3yt Год назад

    Hey You made a great job , Thanks a lot

  • @meispi9457
    @meispi9457 4 года назад +1

    If you could provide those slides, that would be very helpful.
    thanks, great video!!

    • @InsiderPhD
      @InsiderPhD  4 года назад +3

      I don't provide my slides simply because I am not comfortable with other people presenting my work, I will see what I can in maybe sorting out some written notes in the future.

    • @meispi9457
      @meispi9457 4 года назад

      @@InsiderPhD Valid point.

    • @InsiderPhD
      @InsiderPhD  4 года назад

      @rl1k Doe It's less because I don't want people to take credit for my work, but because I want to make sure that if my name is attached to something that it's presented correctly with all the facts!

  • @nicholasxyz8880
    @nicholasxyz8880 4 года назад

    The reports you use in your examples, in the future could you give us the url for them so we can look them up? Thanks!

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      Now in the description
      - Information Disclosure: User Information Disclosure via the REST API - /?_method=GET
      - hackerone.com/reports/384782
      - Authorisation Issues: Wordpress.com REST API oauth bypass via Cross Site Flashing - hackerone.com/reports/176308
      - Business Logic Errors: Items bought for free due to lacks of quantity controls - hackerone.com/reports/357929
      - IDORs: IDOR and statistics leakage in Orders - hackerone.com/reports/544329
      - XSS: Stored XSS in blog comments through Shopify API - hackerone.com/reports/192210

  • @champagnepete3386
    @champagnepete3386 4 года назад

    Awesome resource!

  • @TheHammertownhead
    @TheHammertownhead 4 года назад

    I would love to see a sample of your spreadsheet. Would you be willing to share or post link below your video? Great video!! Great content! Thanks for taking the time! A final slide would be great at the end of the video while you are doing final comments as the screen going black, which is a little freaky.

    • @InsiderPhD
      @InsiderPhD  4 года назад +4

      Link to the spreadsheet :) docs.google.com/spreadsheets/d/1IJvTH6QpTlxWdy4Ss6I0G_f4csCYwBdgE88ya7XijnI/edit?usp=sharing will take your feedback into account for next time!

    • @TheHammertownhead
      @TheHammertownhead 4 года назад

      @@InsiderPhD keep up the great work on these great videos!!! Very informative!! Its greatly appreciated!

  • @ariyankhan2847
    @ariyankhan2847 3 года назад

    you should add link of your video in I button or in this description when you are talking about you some other videos

    • @InsiderPhD
      @InsiderPhD  3 года назад

      Excellent idea, thank you I will do this!

  • @starkeduplatform2320
    @starkeduplatform2320 4 года назад

    Thanks for this...really useful for me

  • @neoXXquick
    @neoXXquick 4 года назад

    Amazing video.. thx for contribution...

  • @JuanBotes
    @JuanBotes 2 года назад

    great training video, thanks for content \o/

  • @sayturestorver4334
    @sayturestorver4334 Год назад

    Thank you so much !!

  • @noblesix6525
    @noblesix6525 4 года назад

    Thank you so much!! Very useful

  • @dipakpardesi4661
    @dipakpardesi4661 Год назад

    thanks for the video 👍

  • @hardwork3196
    @hardwork3196 3 года назад

    thanks a lot for awesome information.

  • @2012mrmoh
    @2012mrmoh Год назад

    Great, however, how can I concentrate with an ad every minute. Thank you for your hard work .

    • @InsiderPhD
      @InsiderPhD  Год назад

      I’m really sorry I actually have midrolls turned off completely but RUclips will actually add them back into the videos anyway! Feel free to use an adblocker it’s very annoying

  • @albonycal
    @albonycal 4 года назад

    I'm little bit confused @ 30:29 that means if we remove the cookies and the api accepts it... Does this bypasses Authorization... I'm confused

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      By removing cookies we are basically “logged out” which is why it works, there are many different type of IDORs but it’s a quick litmus test to check!

    • @shrirangkahale
      @shrirangkahale 4 года назад

      Got it..

  • @wingwing2683
    @wingwing2683 2 года назад

    Thanks so much!

  • @thehackerish
    @thehackerish 4 года назад +1

    1337 video! Is it just a chance or I am the 3337th person to view the video? :D

  • @IteLuis
    @IteLuis 4 года назад

    Awesome talk, thank you very much!!

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      Glad you liked it! More API videos coming really soon!

  • @shiftlock452
    @shiftlock452 Год назад

    lovely voice🤩

  • @hasnainabidkhanzada3754
    @hasnainabidkhanzada3754 3 года назад

    Enumeration is a part of a larger recon process. Right?

    • @InsiderPhD
      @InsiderPhD  3 года назад +1

      Yup but sometimes not! API recon is often discovering endpoints while larger recon is usually exploring a scope in depth

    • @hasnainabidkhanzada3754
      @hasnainabidkhanzada3754 3 года назад

      @@InsiderPhD Exploring a scope could be finding the hidden endpoints. Isn't this also enumeration?

  • @xx2125
    @xx2125 4 года назад

    Hi Katie, thanks for this superb video. Do you have somewhere the presentation for download?

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      No, sorry, unless it's mentioned specifically in the video descriptions I don't make slides freely available, usually I do for conference talks!

    • @xx2125
      @xx2125 4 года назад

      ​@@InsiderPhD Ok, so I will take notes from your videos. :)

  • @nishikanttayade7446
    @nishikanttayade7446 3 года назад

    For Web Developers start at 14:30

  • @h4kster182
    @h4kster182 4 года назад

    really Great, thank you

  • @cyrilbeyo8731
    @cyrilbeyo8731 4 года назад

    Thank you
    This was helpful

  • @yogteacherdilipmotkar8801
    @yogteacherdilipmotkar8801 4 года назад

    Plz tell which lecture are coming at what time means future schedule plz

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      Next up:
      Q and A - midweek next week
      RCE bug in focus - 18th Jan
      CSRF finding your first bug - 25th Jan
      I often post in the channel community tab or on twitter when I know what my next video will be!

  • @vishalpatidar2737
    @vishalpatidar2737 4 года назад

    Great video, please make a video on CSRF

  • @emreru5687
    @emreru5687 4 года назад

    Thank you so much

  • @yethu7682
    @yethu7682 4 года назад

    can you share the slide of this video?

  • @hannanjamil1060
    @hannanjamil1060 4 года назад

    Can you please share slides? BTW thank you so much. ❤🌹

  • @RahulYadav-qg9ms
    @RahulYadav-qg9ms 4 года назад

    please bring some practical beside theory

  • @MrTiger-eg1gr
    @MrTiger-eg1gr 4 года назад

    This was great. But, if you don't mind, can you please slow down a lil bit while talking?

    • @InsiderPhD
      @InsiderPhD  4 года назад

      Of course! Thank you for your feedback! I will definitely try to talk slower and pace myself better!

  • @yassindaboussi2570
    @yassindaboussi2570 4 года назад

    thank You

  • @isfk
    @isfk 3 года назад

    Reusing code by creating a web API is not being lazy, its being smart.

    • @InsiderPhD
      @InsiderPhD  3 года назад

      Of course! It’s just a joke :)! Using an API can also reduce development time when you’re managing a desktop, web and mobile app for example

  • @ishansaha8652
    @ishansaha8652 Год назад

    can i get your PPT?

  • @henryasubonteng695
    @henryasubonteng695 4 года назад

    Thank

  • @bugsbunny6286
    @bugsbunny6286 4 года назад

    Can you make a good video on XSS explaining all of them briefly and ways to find it out easily

    • @InsiderPhD
      @InsiderPhD  4 года назад

      Great idea I will make this video!

  • @goooooo9197
    @goooooo9197 4 года назад

    How to find that api plz tell that

    • @InsiderPhD
      @InsiderPhD  4 года назад

      Keep an eye out for web apps which have mobile app counterparts, often they both use the same API, another option is to take a look at mobile apps (video coming soon!), but in the meantime, you can check out Spaceraccoon's recent iOS blog spaceraccoon.dev/low-hanging-apples-hunting-credentials-and-secrets-in-ios-apps or using Genymotion to set up an Android emulator

  • @hanko1
    @hanko1 3 года назад

    i have watched 'All' of your videos but never fined a bug

    • @InsiderPhD
      @InsiderPhD  3 года назад +1

      Keep an eye out I’m posting a video just for you soon!

    • @hanko1
      @hanko1 3 года назад

      @@InsiderPhD I would be so happy

  • @probeing9418
    @probeing9418 4 года назад

    it will be gud if u give reports link is description

    • @InsiderPhD
      @InsiderPhD  4 года назад

      Now in the description
      - Information Disclosure: User Information Disclosure via the REST API - /?_method=GET
      - hackerone.com/reports/384782
      - Authorisation Issues: Wordpress.com REST API oauth bypass via Cross Site Flashing - hackerone.com/reports/176308
      - Business Logic Errors: Items bought for free due to lacks of quantity controls - hackerone.com/reports/357929
      - IDORs: IDOR and statistics leakage in Orders - hackerone.com/reports/544329
      - XSS: Stored XSS in blog comments through Shopify API - hackerone.com/reports/192210

  • @SumitSingh-xu4qs
    @SumitSingh-xu4qs 3 года назад

    mam your voice is very beautiful

  • @beamedbyflimzy5463
    @beamedbyflimzy5463 3 года назад

    huh

  • @beamedbyflimzy5463
    @beamedbyflimzy5463 3 года назад

    sorry for bad comment

  • @funkiimonke6129
    @funkiimonke6129 3 года назад

    You british?

    • @InsiderPhD
      @InsiderPhD  3 года назад

      Yup! From Surrey live in Manchester