If I Started Bug Bounty Hunting in 2024, I'd Do this

Поделиться
HTML-код
  • Опубликовано: 4 ноя 2024

Комментарии • 120

  • @NahamSec
    @NahamSec  9 месяцев назад +21

    📚 Purchase my course and learn about bug bounty hunting 👉🏼 app.hackinghub.io/hubs/nahamsec-bug-bounty-course

    • @GilligansTravels
      @GilligansTravels 9 месяцев назад

      done

    • @Whatisthis_1
      @Whatisthis_1 9 месяцев назад +1

      Hey Naham! How long it takes for a beginner to be really good that you start making some bucks? I'm not talking about millions of dollars here but maybe some hundred dollars?

    • @mdowais6447
      @mdowais6447 9 месяцев назад

      3 years
      @@Whatisthis_1

    • @CriticSimon
      @CriticSimon 6 месяцев назад

      @@mdowais6447 Whaat? 3 years to make a $100? Are you joking? or you meant $100,000

    • @AliAli-lh5ku
      @AliAli-lh5ku 4 месяца назад

      Can you post new coupon, please?

  • @edrickreyes-melendez4215
    @edrickreyes-melendez4215 9 месяцев назад +18

    I was really needing phase 2. I don't think I've head a content creator mention to get to know yourself and what type of hacker you are. Love that

  • @GohansTips72
    @GohansTips72 9 месяцев назад +74

    Your live recon videos have helped me learn a lot, and they actually led me to find a $1000 bug. So, thank you for that! I'm referring to the old recon videos like Yahoo and some interviews where you conducted recon.

    • @NahamSec
      @NahamSec  9 месяцев назад +9

      Nice!! So happy to hear that!

    • @GreenMohawk1987
      @GreenMohawk1987 9 месяцев назад +3

      That's awesome! Congrats!

    • @milankomatinovic6614
      @milankomatinovic6614 9 месяцев назад +1

      How much time you needed for that?

    • @GohansTips72
      @GohansTips72 9 месяцев назад

      @@milankomatinovic6614 started on September 8th got a bug on next year July 8th

    • @aleksjagger9770
      @aleksjagger9770 8 месяцев назад +1

      What kind of bug was it?

  • @askholia
    @askholia 9 месяцев назад +91

    One thing I can't get good clarification on: a lot of bounty programs say something along the lines of 'no automated tools' but most bug bounty educational videos seem to tout the overall important and use of automated tools. It is not a sexy topic, but something I would love to see a bit about. No worries if it is something you don't want to cover!

    • @KhalifaYakub
      @KhalifaYakub 9 месяцев назад +30

      I believe by automated tools they mean is tools like nikto that does vulnerability assessment. There’s no need since they can use those tools too.

    • @askholia
      @askholia 9 месяцев назад +7

      Thank you!!@@KhalifaYakub

    • @effsixteenblock50
      @effsixteenblock50 9 месяцев назад +26

      Like someone else said - they don't want you to run vuln assessment tools that have likely already been used. The main thing is a lot of these tools spam massive amounts of requests and make a lot of "noise", which make it tougher on SOC teams to be able to differentiate BB hunters traffic from actual threat traffic.

    • @askholia
      @askholia 9 месяцев назад

      Great explanation! This community rocks.@@effsixteenblock50

    • @abdullahjaved2371
      @abdullahjaved2371 6 месяцев назад +1

      @@effsixteenblock50 so tools like subdomain enumeration ones or directory enums are okay?

  • @neiltsakatsa
    @neiltsakatsa 9 месяцев назад +17

    Your Critical Thinking Bug Bounty Podcast was 🔥🔥🔥🔥

    • @NahamSec
      @NahamSec  9 месяцев назад +3

      Thank you!!

  • @awakenerd1101
    @awakenerd1101 5 месяцев назад +1

    Well I get lost watching your videos, that's why I never start hunting. Man you are a very unique person. Thank you for your great work and energy.

  • @rhidayahh
    @rhidayahh 9 месяцев назад +2

    good video, your video changed the way I look at web apps, starting from methodology and others, and now I always do manual tests even though it takes a long time, that's what makes me like BB

  • @edwardadonis6825
    @edwardadonis6825 Месяц назад

    Thank you so much for sharing. Now I got a very clear roadmap to follow😀

  • @brunom12111
    @brunom12111 9 месяцев назад +9

    looking forward for the automation video too!

  • @0x2e2e2f
    @0x2e2e2f 9 месяцев назад +1

    You forgot Stock, he’s a good guy and he’s vibe is totally different from any other hacker at the community

  • @bobanmilisavljevic7857
    @bobanmilisavljevic7857 9 месяцев назад +2

    Thank you all bug bounty hunters!

  • @sveneFX
    @sveneFX 9 месяцев назад +3

    Thanks! Looks like I'm in level 2 right now 😊

    • @NahamSec
      @NahamSec  9 месяцев назад +2

      Nice! Keep up the great work. You'll get to level 4 in no time!

    • @sveneFX
      @sveneFX 9 месяцев назад

      @@NahamSec Thanks my man, you're really an inspiration for me ✌️

  • @ra.njan_kr
    @ra.njan_kr 9 месяцев назад +1

    Nice video ❤🎉,Thanks for the video

  • @moshoodkamorudeen5947
    @moshoodkamorudeen5947 9 месяцев назад

    thanks for giving back to the community

  • @MarkFoudy
    @MarkFoudy 9 месяцев назад +3

    love this! thanks

    • @NahamSec
      @NahamSec  9 месяцев назад

      Glad you enjoyed it!

  • @Ynerson9003
    @Ynerson9003 9 месяцев назад +3

    Great video, love your content. As a complete beginner with a tremendous amount of motivation to get into big bounties and ethical hacking. Would you have any advice or words of encouragement how to get into this field. I just purchased your udemy course! Thanks for the great videos

    • @atanaspeev4960
      @atanaspeev4960 8 месяцев назад +3

      Just stop thinking how to get started. Pick some websites, play around and understand how they work, look at login flaw, try to find open redirects as a beginner. My first bug was open redirect and then XSS.
      Just start hacking while learning.

    • @dixelinho
      @dixelinho 5 месяцев назад

      I heard the advice from someone like: not to learn how to hack, HACK to LEARN how to hack.

  • @janekmachnicki2593
    @janekmachnicki2593 9 месяцев назад

    Thanks mate for being with us .Thanks for hoke me up with bb . Iam not just doing for money doing to challenge myself and get satisfaction of my hobby .Thanks and Happy new Year

  • @zacharyjohnston70
    @zacharyjohnston70 9 месяцев назад

    Im snagging this course for sure!

  • @kaxin8980
    @kaxin8980 9 месяцев назад +5

    i started bug bounty because of motivation which you gave me

    • @frankmugabe4325
      @frankmugabe4325 9 месяцев назад

      When did you started and how is it now?

    • @NahamSec
      @NahamSec  9 месяцев назад

      ♥️

  • @AnonymousVv3
    @AnonymousVv3 6 месяцев назад

    The number 1 cause it information technology problems is black hats

  • @ВодолейСтупин
    @ВодолейСтупин 9 месяцев назад

    Hi, i started bug bounty at 1 year ago , i need a peoples who work in this industry for their exp (sry for my bad eng , without translate)Thx for the videos

  • @fathyart
    @fathyart 26 дней назад

    I can edit your videos with more graphics .
    I'm ready for that

  • @geniusesml3700
    @geniusesml3700 9 месяцев назад +2

    Thank you Nahmsec im in Level 1.5 I start 8 month ago found 8 bugs (vdp) :)

    • @NahamSec
      @NahamSec  9 месяцев назад +1

      That is amazing!! Congratulations and keep up the good work!

  • @mrhack3950
    @mrhack3950 9 месяцев назад +2

    Bro i don't have good budget to buy a pc or laptop. Can i start with ryzen 3 3200g? Can we install virtual machine on it? Will it work?

    • @atanaspeev4960
      @atanaspeev4960 8 месяцев назад +1

      You don't really need a supercomputer for this. That processor is enough, you need at least 8 GB ram, 16 GB and up is recommended.
      For web application hacking you don't need a virtual machine, you could install Linux alongside with your windows.

    • @mrhack3950
      @mrhack3950 7 месяцев назад

      @@atanaspeev4960 can I use i3?

    • @animelove3553
      @animelove3553 6 месяцев назад

      Juz go for PC around 30000 price, there are plenty

    • @deadlyspud7399
      @deadlyspud7399 3 месяца назад

      You don't need such a good pc when starting out. Get something cheap like a lenovo thinkpad t480. Anything that has an i5, 8 or 16gb ram, and at least 256gb ssd will do the trick. Once you start earning money in bug bounties, you can eventually save up for better components, or a better laptop in that case.

  • @tallst1
    @tallst1 9 месяцев назад

    Yes please update the Course @Nahamsec.

  • @jxkz7
    @jxkz7 9 месяцев назад

    sir , can you suggest programs have large web application with ton of functionality for manual hunting

  • @Mike-cp1tj
    @Mike-cp1tj 9 месяцев назад

    I saw you recommended "black hat python" as 1 of 5 books, but in chapter 2 it's already too hard

    • @anonyghost7422
      @anonyghost7422 9 месяцев назад +1

      So keep learning! This isn’t suppose to be easy.

    • @effsixteenblock50
      @effsixteenblock50 9 месяцев назад +1

      Did you bother to learn Python first?

  • @bhag47
    @bhag47 9 месяцев назад

    hey ben my plan is looking for idor only in every application i approach do you think it's a good idea ? and i thinking learn more about authorization issue's and file upload vulnerability what's your comment

    • @NahamSec
      @NahamSec  9 месяцев назад +3

      That is not a bad idea but make sure it makes sense. That means the application has an API/GraphQL backend or makes AJAX calls to retrieve PII or sensitive information.

    • @bhag47
      @bhag47 9 месяцев назад

      @@NahamSec k thanks

  • @GoliTech
    @GoliTech 9 месяцев назад

    thanks Ben

  • @junpinox1574
    @junpinox1574 7 месяцев назад

    I have my audio maxed out, I think your video/voice is quiet, a bit hard to hear.

  • @mysteriousministar2481
    @mysteriousministar2481 9 месяцев назад

    عالی هستی بهروز جان،این کورس برای مید لول هاست؟

    • @NahamSec
      @NahamSec  9 месяцев назад +1

      Beginners for now

    • @mysteriousministar2481
      @mysteriousministar2481 9 месяцев назад

      @@NahamSec تشکر،راستی لایو ریکان یا لایو هانت دیگه انجام نمیدین توییچ؟

  • @zTech300
    @zTech300 9 месяцев назад

    Thanks man

  • @phch54
    @phch54 9 месяцев назад

    which platforms for bug bounty?

  • @955aravinthk7
    @955aravinthk7 9 месяцев назад

    Where can learn ios bug bounty?

  • @FactoMastic
    @FactoMastic 8 месяцев назад

    I have done the first three resources...

  • @hadiuzzaman9027
    @hadiuzzaman9027 9 месяцев назад

    ThankYou Sir

  • @AnonymousVv3
    @AnonymousVv3 6 месяцев назад

    I'm a white hat. I hate Black hats

  • @akashbhosle6276
    @akashbhosle6276 9 месяцев назад

    Thanks

  • @showupshowout
    @showupshowout 2 месяца назад

    Fire

  • @xxjblexx
    @xxjblexx 9 месяцев назад

    Ambiguous Information … With Sprinkles of Advertising. Always repeating the same info

  • @shreerammallick5434
    @shreerammallick5434 9 месяцев назад

    Make a video on technology stack based testing

  • @monikasharma4403
    @monikasharma4403 9 месяцев назад +1

    Love from India

  • @ourlifeinportugal
    @ourlifeinportugal 3 месяца назад

    Your to close to your mic

  • @johnp5761
    @johnp5761 9 месяцев назад +2

    Ez, just start with Call of Duty 😂

    • @NahamSec
      @NahamSec  9 месяцев назад

      Where are we dropping?

  • @muhammadharis2212
    @muhammadharis2212 9 месяцев назад +1

    Can you share coupon code for udemy cources

    • @NahamSec
      @NahamSec  9 месяцев назад

      It's in the description of the video

    • @NahamSec
      @NahamSec  9 месяцев назад

      www.udemy.com/course/intro-to-bug-bounty-by-nahamsec/?couponCode=RUclips

    • @muhammadharis2212
      @muhammadharis2212 9 месяцев назад

      Thanks I am also very interested in bug bounty and doing an internship

  • @SushantChauhan-jp3sb
    @SushantChauhan-jp3sb 9 месяцев назад

    ❤❤❤❤❤❤❤

  • @kalendra.ethicalhacker
    @kalendra.ethicalhacker 9 месяцев назад

    I always getting duplicates

    • @atanaspeev4960
      @atanaspeev4960 8 месяцев назад

      No worry for this, everyone started at this point, you probably reporting some informative reports that are reported a long time ago before you. Always make sure your reports are valid and have impact, if so ask a mediation for help, I get a lot of duplicates by mistake of lazy triagers...

  • @KushanHettiarachchi-g1w
    @KushanHettiarachchi-g1w 8 месяцев назад

    step 1 is learn web development

  • @aliuzun8885
    @aliuzun8885 9 месяцев назад

    Eyv knk

  • @orbitxyz7867
    @orbitxyz7867 9 месяцев назад +1

    Wasted 2/3 years in bug bounty nothing happen😢

    • @KaTal-6
      @KaTal-6 9 месяцев назад

      really ? how

    • @orbitxyz7867
      @orbitxyz7867 9 месяцев назад +1

      @@KaTal-6 learned bug bounty cant find any bugs

    • @vz7742
      @vz7742 9 месяцев назад +2

      Haha this is sad reality for most of you who wants to get into bbh..😅

    • @serialkiller8783
      @serialkiller8783 9 месяцев назад

      you cant destroy what you cant build! and not all developers are hackers.

    • @vz7742
      @vz7742 9 месяцев назад +1

      @@serialkiller8783 come at me bro!

  • @__CJ.__
    @__CJ.__ 9 месяцев назад

    😢❤

  • @ham_eed578
    @ham_eed578 9 месяцев назад

    First ❤

  • @SleepyAizawa69
    @SleepyAizawa69 2 месяца назад

    Noice

  • @hoodietramp
    @hoodietramp 9 месяцев назад

    og