Bug Bounty Secrets

  Рет қаралды 13,476

NahamSec

NahamSec

Жыл бұрын

📚 Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training
💵 Support the Channel:
You can support the channel by becoming a member and get access exclusive content, behind the scenes, live hacking session and more!
☕️ Buy Me Coffee:
www.buymeacoffee.com/nahamsec
JOIN DISCORD:
discordapp.com/invite/ucCz7uh
🆓 🆓 🆓 $200 DigitalOcean Credit:
m.do.co/c/3236319b9d0b
💬 Social Media
- / nahamsec
- / nahamsec
- twitch.com/nahamsec
- / nahamsec1
#bugbounty #ethicalhacking #infosec #cybersecurity #redteam #webapp

Пікірлер: 74
@joseph_thacker
@joseph_thacker Жыл бұрын
first
@NahamSec
@NahamSec Жыл бұрын
💥💥💥
@MFoster392
@MFoster392 Жыл бұрын
U da man Ben, I started out 6 months ago knowing nothing and i've learned so much from your videos. Thank You :-)
@NahamSec
@NahamSec Жыл бұрын
You rock!
@MFoster392
@MFoster392 Жыл бұрын
@@NahamSec Thanks man
@sagarshah5846
@sagarshah5846 11 ай бұрын
I have the same opinion of him.
@SplitUnknown
@SplitUnknown Жыл бұрын
Always ready for part2❤🙂
@Andrei-ds8qv
@Andrei-ds8qv Жыл бұрын
Something that I noticed is that it takes so much mental energy to try out, in the wild a new type of attack. I learn about it, I test it locally but it's like I am afraid to test it in the wild, what if something go wrong. So I usually test it on a few hosts, them more, and then go full scale. But yeah, that is something that I feel is slowing me down by some days for each attack I am learning. Is this happening to you also? If you got over it, how did you do?
@6060fishy
@6060fishy Жыл бұрын
Definitely a part 2 please! ❤
@rohitlondhe4441
@rohitlondhe4441 Жыл бұрын
Your posting a great content but please increase the volume or speak loudly, it is very difficult to heard you in noisy conditions... ❤
@rahmat_qurishi
@rahmat_qurishi Жыл бұрын
Great as always Waiting for part 2
@chaospixxie
@chaospixxie Жыл бұрын
One of the things I love about the industry is the continuous learning, but how do you manage burnout with the demand of keeping up to date?
@juliusrowe9374
@juliusrowe9374 Жыл бұрын
Ben, please do a part 2!
@nandeeyr
@nandeeyr Жыл бұрын
This is surely not a clickbait video Naham.
@prabakarj4797
@prabakarj4797 Жыл бұрын
Thanks for always motivating us ❤Is there any platform to practice real world vulnerabilities
@vsulli
@vsulli Жыл бұрын
@NahamSec, In regards to mindset, if you understand a cross-site scripting report can you read the report and turn it into layman terms. Like when I talk to ppl about network IP addresses, I'll say that it's an Address like sending a letter at Christmas if that host is offline or that family moved, you Christmas card will be "return to sender recipient does not live here anymore."
@vsulli
@vsulli Жыл бұрын
It's kind of silly thinking about that way but people understand the concept of trying to send a Christmas card to someone but they don't live there anymore. They know that the address is important and they know that if there's a problem the US postal Service will return their Christmas card with some sort of a message.
@vsulli
@vsulli Жыл бұрын
I also do that when thinking about interoperability issues when setting things up in IT. Sometimes Cisco products do not work with Apple iOS. So when I'm troubleshooting something like this interoperability issue. I imagine a couple in an argument and they are experiencing miscommunication issues. One person is expecting the other to behave in a certain way and that's not happening.
@NahamSec
@NahamSec Жыл бұрын
I gotta think about how to do this. This seems like a cool/interesting idea!
@gramas19
@gramas19 11 ай бұрын
Could you make a video of how you create your own custom lists for finding subdomains? I saw that you used a custom list when hacking redbull a few weeks ago :)
@bugs-lk3jf
@bugs-lk3jf Жыл бұрын
Great Content
@glen8552
@glen8552 Жыл бұрын
My memory is my biggest problem, always having to refer back to books or notes. Working full time and only having limited time to learn i don't build enough muscle memory 😥😥
@yousefnaderi1935
@yousefnaderi1935 11 ай бұрын
plz speak more about defensive careers
@long2330
@long2330 Жыл бұрын
I'm struggling with missing bugs or standard methodology/checklist to ensure the application is secure
@nightfox9007
@nightfox9007 Жыл бұрын
Woohoo!
@klkiley2922
@klkiley2922 11 ай бұрын
Where do I get started with hacking? I am a very structured person, so I feel I would need the fundamentals. Any recommendations would be appreciated.
@saqibuzair7670
@saqibuzair7670 Жыл бұрын
This video is helpful for me < thank you :)
@NahamSec
@NahamSec Жыл бұрын
You're welcome 😊
@nafizimtiaz9367
@nafizimtiaz9367 Жыл бұрын
we want Part two
@user-ey8wm3hg7m
@user-ey8wm3hg7m Жыл бұрын
First man!
@Jilien
@Jilien Жыл бұрын
I’m struggling to sit down and learn/practice. Stupid video games are always more important and it is so frustrating, deep down I know what I have to do but it always gets in the way… Any tips on how to flip that switch? 😁
@TywinLannister0
@TywinLannister0 Жыл бұрын
part 2, please.
@c0gamer
@c0gamer Жыл бұрын
Hello sir, I want to learn API Testing but don't know where to start, please can you give some guidence.
@NahamSec
@NahamSec Жыл бұрын
Check out the videos on the 5 books to read. One of them is on API hacking!
@epithet
@epithet Жыл бұрын
I dropped out of college last month, only for what I love the most. Hacking.
@Abdoulaye-cg7np
@Abdoulaye-cg7np Жыл бұрын
Welcome bro. I have also dropped high school.
@Rocks_roxks9
@Rocks_roxks9 Жыл бұрын
Hey Nahamsec Sir 🤩🤩🤩
@NahamSec
@NahamSec Жыл бұрын
hiiii
@Boolap1337
@Boolap1337 Жыл бұрын
Im at the point where I wanna try out bug bounty but I still have much to learn in AppSec. Should I focus learning more, efficiently at etc portswigger or should I just go into bug bounty and learn there?
@ritikkarayat4647
@ritikkarayat4647 Жыл бұрын
Go in bug bounty. I'm in a similar position but doing it for real will be much beneficial than labs
@CB-gi7kd
@CB-gi7kd 11 ай бұрын
Do the labs or some training first. If you already have knowledge then try bug bounty but in moderation. You want to continue to build up your skills with more courses, certifications, and research. I've been in AppSec for 2.5 years and working on preparing for Burp Suite Exam and INE courses/certifications. Then most likely continue to build skills in programming and secure coding to eventually get OSWE. If you want to stay in application layer testing don't worry much about Active Directory or related for now. At some point I want the OSCP but right now it's not worth pursing unless you want to do general pentesting or red teaming.
@CB-gi7kd
@CB-gi7kd 11 ай бұрын
What I remember hearing is there's always a sh#t ton to learn. But focus on what's going to help you with your job or where yiu want to go first.
@mr.ayyanirfan7081
@mr.ayyanirfan7081 Жыл бұрын
we want videos on xss pleaseeeeee
@anonysm
@anonysm Жыл бұрын
1st view❤
@rdx8122
@rdx8122 Жыл бұрын
01:20, sir is Javascript really needed to be a good bug bounty hunter as really i have came so far giving a lot of time to javascript in the past few months
@pubgfantasy9010
@pubgfantasy9010 10 ай бұрын
@alpeshrprajapati5159
@alpeshrprajapati5159 Жыл бұрын
Salam valekum
@cehdinh5132
@cehdinh5132 Жыл бұрын
@0xbara
@0xbara Жыл бұрын
how long it took you to find your first bug?
@NahamSec
@NahamSec Жыл бұрын
2-3 months!
@Frawkesish
@Frawkesish Жыл бұрын
Part 2
@msohaib6181
@msohaib6181 Жыл бұрын
please make a video how much code learning is required to be able to find bugs nobody talk about it.
@NahamSec
@NahamSec Жыл бұрын
I've already made this video. It's on my channel!
@s.nikolic497
@s.nikolic497 Жыл бұрын
👍🏻
@Thiago1337
@Thiago1337 Жыл бұрын
are you happy, Naham?
@someshtiwari8268
@someshtiwari8268 Жыл бұрын
PLZZZ MAKE A VIDEO ON BUG BOUNTY REPORT WRITING
@NahamSec
@NahamSec Жыл бұрын
💥💥💥💥
@twguy69
@twguy69 Жыл бұрын
I've been trying for months, but I just can't find anything 😑
@74himanshukumar
@74himanshukumar Жыл бұрын
same problem bro
@captainnoobie331
@captainnoobie331 Жыл бұрын
I found a critical but duplicate few hours late 😭
@Aditya_khedekar
@Aditya_khedekar Жыл бұрын
daddy ben any pentester lab give away :)
@user-ey8wm3hg7m
@user-ey8wm3hg7m Жыл бұрын
Pzl! make 3 videos a week.
@netwons
@netwons Жыл бұрын
Hello, Behrooz. Your speech is good, but it is a slogan. It is better to cover this in practice so that we can understand it better
@KaafUzair
@KaafUzair Жыл бұрын
I'm struggling to finding my 4th valid bug last 2 months 😐
@amoh96
@amoh96 Жыл бұрын
what advice u give me i know baisc js and some web ? should i go to real world start learning xss or what
@KaafUzair
@KaafUzair Жыл бұрын
@@amoh96 ofcourse yes 👍🏻
@amoh96
@amoh96 11 ай бұрын
@@KaafUzair ?
@someshtiwari8268
@someshtiwari8268 Жыл бұрын
PAYLOADS VIDEO HOW TO USE IT
@NahamSec
@NahamSec Жыл бұрын
Absolutely!
@TesterGuy-dh9df
@TesterGuy-dh9df Жыл бұрын
I'm struggling with missing bugs, I remember finding one bug but due to lack of knowledge (at that time) I missed it now I don't even remember where did I saw it because as a beginner I jumped too many programs. I'm losing passion because I couldn't find a single bug in months. lastly I would like to know how to hack patiently and how other hackers find xss or other bugs in less than 1hr or 3hrs some says found 10 bugs in last 24hrs.
@arjunn7683
@arjunn7683 Жыл бұрын
MY THREAD MODEL IS EASY - HIT THEM WHERE IT HURTS . EXAMPLE TAKE PAYPAL REST YOU KNOW 😈 !!!!
@rxtechandtrading
@rxtechandtrading 11 ай бұрын
so i did some automated api endpoint enumeration testing (via feroxbuster) and managed to get into the /etc/passwd file on my friends web server he allowed me to hack-BUT - this was the contents of the file: root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin bin:x:2:2:bin:/bin:/usr/sbin/nologin sys:x:3:3:sys:/dev:/usr/sbin/nologin sync:x:4:65534:sync:/bin:/bin/sync games:x:5:60:games:/usr/games:/usr/sbin/nologin man:x:6:12:man:/var/cache/man:/usr/sbin/nologin lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin mail:x:8:8:mail:/var/mail:/usr/sbin/nologin news:x:9:9:news:/var/spool/news:/usr/sbin/nologin uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin does anybody know how i can ACTUALLY get a hold of the password hashes for each user here in the second field after the first : ????????
@moh5entuky940
@moh5entuky940 Жыл бұрын
Are you from iran? @NahamSec
@akshay_6944
@akshay_6944 Жыл бұрын
Part 2
WHY YOU SUCK AT HACKING // How To Bug Bounty
10:05
NahamSec
Рет қаралды 21 М.
Bug Bounty Changed My Life!
11:53
NahamSec
Рет қаралды 24 М.
Super gymnastics 😍🫣
00:15
Lexa_Merin
Рет қаралды 105 МЛН
Stupid Barry Find Mellstroy in Escape From Prison Challenge
00:29
Garri Creative
Рет қаралды 20 МЛН
Why You Should Always Help Others ❤️
00:40
Alan Chikin Chow
Рет қаралды 134 МЛН
Android App Bug Bounty Secrets
20:14
LiveOverflow
Рет қаралды 95 М.
Bug Bounty Hunting Full Time
11:20
NahamSec
Рет қаралды 29 М.
How to Look For Virtual Hosts // How To Bug Bounty
12:53
NahamSec
Рет қаралды 13 М.
Bug Bounty Target Deep Dive
10:52
NahamSec
Рет қаралды 13 М.
$780,000 in 3 months Bug Bounty!
23:55
Tadi
Рет қаралды 12 М.
How to Bug Bounty in 2023
13:15
NahamSec
Рет қаралды 71 М.
How to Write Great Bug Bounty Reports
11:48
The Cyber Mentor
Рет қаралды 15 М.
What Should You Do After Recon?!
14:47
NahamSec
Рет қаралды 26 М.
Super gymnastics 😍🫣
00:15
Lexa_Merin
Рет қаралды 105 МЛН