Finding Bugs in Mobile APIs

  Рет қаралды 20,131

InsiderPhD

InsiderPhD

Күн бұрын

Hey everyone! Welcome to another API video, well I promise more didn't I! This week we're going to use the setup from the previous videos on iOS and Android, and actually use it to FIND BUGS! Mobile apps have some AMAZING first bugs, that don't require complex technical skills, but instead perseverance!
Did you know this episode was sponsored by Intigriti? Sign up with my link go.intigriti.com/katie I'm so pleased with everyone's positive response to the Intigriti sponsorship and I'm so pleased you folks are finding bugs and even finding your first bugs! Thank you for being awesome!
- Resources -
A lot of people have told me that they struggle to find APIs to test, so I hope that this will help get you started! If you've only just joined us, here are the videos I recommend!
Top 10 API bugs: • Top 10 API Bugs (and W...
Enumerating APIs: • How To Do Recon: API E...
Finding Your First Bug: APIs: • Finding Your First Bug...
TomNomNom: • Who, What, Where, When...
FFUF: • How to use ffuf - Hack...
- Social Media -
Discord: / discord
Patreon: / insiderphd
Twitter: / insiderphd
- Patreon Shoutouts -
MechaInfoSec
Wardell Castles
rl1k
strongbeard
Lukáš Hájek
Gynvael
Ram
James Clee

Пікірлер: 36
@luckythandel
@luckythandel 3 жыл бұрын
You are doing such a good deed. Many of us are learning a lot from these videos. Thank you for doing it free.
@davicosta4931
@davicosta4931 3 жыл бұрын
Hey Katie, thanks for all your videos, in the last weekend, I found my first bug! A business logic error, thanks to your videos. Unfortunately, was a duplicate, but I'm very happy for this! Thanks again, love from Brazil!
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Nice work! a dupe is a bug, you just weren't quick enough this time! You CAN find bugs though, keep going and you'll get faster!
@nixsonblackstone7900
@nixsonblackstone7900 3 жыл бұрын
Thanks alot Katie and God bless 👍
@omarelfarsaoui5498
@omarelfarsaoui5498 3 жыл бұрын
great work !
@user-or9lh2bi6x
@user-or9lh2bi6x 3 жыл бұрын
Hi, top video! Just wanted to ask a question, both Genymotion and Android Studio, emulator does not support a lot of mobile apps because they have a different system architecture, do you guys have any suggestions? I mean cloud or something else?
@jeffm623
@jeffm623 3 жыл бұрын
Thank you :) For reference, something i still struggle with.. IDOR - Insecure direct object references
@learningwithtom4104
@learningwithtom4104 2 жыл бұрын
Hi Katie, You can directly edit from KZfaq video editor only & TRIM the final part. It's pretty easy & for a person like you, it should be damn easy. Look at some video if need any clarification. Thanks for this video. Keep up the good work.
@hydraking8768
@hydraking8768 3 жыл бұрын
Katie Nice Work 👍
@abhhibirdawade9657
@abhhibirdawade9657 3 жыл бұрын
katie your amazing!!!!!!!!!!!!!
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Aww thank you so much it means a lot to me!
@samudrasarma6555
@samudrasarma6555 3 жыл бұрын
Waiting for this video.
@InsiderPhD
@InsiderPhD 3 жыл бұрын
I hope it was worth the wait!
@user-wd3ng2pt3z
@user-wd3ng2pt3z 3 жыл бұрын
thanks for these videos you are great ^_^ , Can you make video about any tools or programs (VPNs) that secure myself after penetration web site hacking ? thanks again .
@ahmadgiftred2048
@ahmadgiftred2048 3 жыл бұрын
Nice!
@avilashnandy9886
@avilashnandy9886 3 жыл бұрын
Hi katie... I would like to thank you so so very much for introducing me to the ios bug bounty setup... I somehow managed to setup my "hacking environment" even though I don't have a mac...and had to browse through a lot of articles for understanding the linux way of settings things up (it took me like 3-4 days to set it up).. I was just curious..could you show some ios specific bugs that a beginner can look for, I read the "read ahead" articles given in the description of the that video..but was not able to understand it properly..and was wondering if you could help me out with it (by making a video or just by referring to any other resources that I could go through)..thanks in advance. much love from India
@InsiderPhD
@InsiderPhD 3 жыл бұрын
FRIDA and webview bugs are great places to start there’s a video I recommend by Dawn Isabel on Bugcrowds channel talking about iOS bug hunting, Spaceracoon also has an article on iOS bugs. But don’t worry we’ll be covering all of that in a later video :)
@avilashnandy9886
@avilashnandy9886 3 жыл бұрын
@@InsiderPhD thank you so much 😃
@dasuntheekshana7599
@dasuntheekshana7599 3 жыл бұрын
Great ❤
@babay-mp4bq
@babay-mp4bq 3 жыл бұрын
is it illegal using free genymotion for bug hunting ?
@AjayKumar-xl4jc
@AjayKumar-xl4jc 3 жыл бұрын
Wah super
@elsakaydb6271
@elsakaydb6271 3 жыл бұрын
Great
@AjayKumar-xl4jc
@AjayKumar-xl4jc 3 жыл бұрын
Thanks😃girl for this video
@ayushxowealth
@ayushxowealth 3 жыл бұрын
Nice
@amyqb117
@amyqb117 3 жыл бұрын
Omg greaaaat
@ca7986
@ca7986 3 жыл бұрын
❤️
@Stas1983ful
@Stas1983ful 3 жыл бұрын
Where is graphql link?
@mr.kn0w1t4ll2
@mr.kn0w1t4ll2 3 жыл бұрын
Yay Mobile !!
@rajatdutta8365
@rajatdutta8365 2 жыл бұрын
gr8 video
@realstar5979
@realstar5979 3 жыл бұрын
Good
@ganeshkhairkar30
@ganeshkhairkar30 3 жыл бұрын
𝗹𝗼𝘃𝗲❤ 𝗙𝗿𝗼𝗺 🇮🇳𝗜𝗻𝗱𝗶𝗮
@tangducbao7309
@tangducbao7309 3 жыл бұрын
Hello from fan, I have a few question - Do you need a rooted phone to perform a bug bounty? - Do bounty platform accept result from a emulation device like Genymotion? - How do you extract .apk from your real phone? with and without root.
@InsiderPhD
@InsiderPhD 3 жыл бұрын
- Yes, usually, because of something called certificate pinning - Yup - You can go on APK downloading sites
@tangducbao7309
@tangducbao7309 3 жыл бұрын
@@InsiderPhD thank you 👍
@321aayushsoni
@321aayushsoni 3 жыл бұрын
Hey Katie, Nice video but last 8 minutes or so are black screen, you must edit that out. after 31:20
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Thanks! I’m not a video editor so mistakes happen!
Hunting for bugs in GraphQL APIs (Demo)
50:41
InsiderPhD
Рет қаралды 15 М.
Live API Hacking Demo
48:11
InsiderPhD
Рет қаралды 40 М.
OMG😳 #tiktok #shorts #potapova_blog
00:58
Potapova_blog
Рет қаралды 3,9 МЛН
The joker's house has been invaded by a pseudo-human#joker #shorts
00:39
Untitled Joker
Рет қаралды 13 МЛН
I wish I could change THIS fast! 🤣
00:33
America's Got Talent
Рет қаралды 83 МЛН
Android App Penetration Testing 101
49:33
Wild West Hackin' Fest
Рет қаралды 48 М.
Giving Yourself the Best Opportunity to Find a Bug
36:45
InsiderPhD
Рет қаралды 6 М.
Android App Bug Bounty Secrets
20:14
LiveOverflow
Рет қаралды 95 М.
API Recon with Kiterunner - Hacker Toolbox
34:20
InsiderPhD
Рет қаралды 30 М.
Finding Your First Bug: Business Logic Errors
37:47
InsiderPhD
Рет қаралды 60 М.
Hacking when all the bugs have been found?
18:53
InsiderPhD
Рет қаралды 5 М.
API Testing Postman Tutorial Full Course 2023
2:43:38
Testers Talk
Рет қаралды 77 М.
How To Do Recon: API Enumeration
56:12
InsiderPhD
Рет қаралды 57 М.
тгк: Логово FRIENDS
0:23
АлексДан
Рет қаралды 8 МЛН
Пугает людей игрушкой аллигатора в воде
0:14
Короче, новости
Рет қаралды 3,2 МЛН
Он сильно об этом пожалел...
0:25
По ту сторону Гугла
Рет қаралды 7 МЛН
小路飞被臭死啦!#海贼王#路飞
0:27
路飞与唐舞桐
Рет қаралды 11 МЛН