No video

Finding Your First Bug: Finding Bugs Using APIs

  Рет қаралды 108,433

InsiderPhD

InsiderPhD

Күн бұрын

Пікірлер: 131
@tayfun6378
@tayfun6378 4 жыл бұрын
you've improved the sound quality
@InsiderPhD
@InsiderPhD 4 жыл бұрын
I finally figured it out!
@digitaldina
@digitaldina 4 жыл бұрын
Your videos are a gold mine! Thank you so much for making them free accessible and so understandable ❤️
@InsiderPhD
@InsiderPhD 4 жыл бұрын
You are so welcome!
@charvi444
@charvi444 4 жыл бұрын
Nobody: InsiderPhD: "Howevaaaaaaar...."
@reo4680
@reo4680 3 жыл бұрын
Bri ish
@forrest8304
@forrest8304 2 жыл бұрын
@@reo4680 in'it
@mrtk-ph5sy
@mrtk-ph5sy 3 жыл бұрын
Really love your series 💖 I found my 1 st paid bb this week after completing your series love you 😘
@gamlielhernandez974
@gamlielhernandez974 3 жыл бұрын
I stumbled with your videos while searching for how to start with API hacking, I found you and all I can say your videos are GOLD!!! Thank you so much for sharing your time and knowledge with the Community.
@MH-tw1qi
@MH-tw1qi 4 жыл бұрын
I spent all my day with this video it's really great I tried hunting all day I didn't hunt :) anything but I'm happy because I collect a lot of knowledge thanks for your tips
@medhasni6432
@medhasni6432 3 жыл бұрын
Did you got some now?
@ICTSecurity
@ICTSecurity Жыл бұрын
You are an outstanding educator, please keep doing it! I just wanted to learn about enumeration for a project but now I'll binge the whole channel.
@jalapenohiway
@jalapenohiway 2 жыл бұрын
Ok this was.....BY FAR the BEST video I've seen on YT, for "Introduction to APIs", "API Basics", & "API Recon & Pentesting"! It was extremely useful & clear/concise information that thoroughly explained all subject matter at hand. TY soo much!!!! I'm super happy I found your channel!
@InsiderPhD
@InsiderPhD 2 жыл бұрын
Wow, thank you so much
@karim3741
@karim3741 Жыл бұрын
a great teacher, amazing and detailed explanation, thank you for your efforts ❤️🔥
@nirchoubey2011
@nirchoubey2011 4 жыл бұрын
Wanted to point out a small mistake. At 5:02 you said name is menu and value is curly braces. Actually value for that menu is an object starting with a curly braces. Thanks for all your effort. You are doing great.
@InsiderPhD
@InsiderPhD 4 жыл бұрын
You're absolutely correct, thank you for pointing out my mistake, I will issue a correction in the description
@NanoCyberSec
@NanoCyberSec 4 жыл бұрын
I am OSCP/OSWE.. and i am starting to learn from you thanks @InsiderPhD keep the greater work up
@ploutosroman4206
@ploutosroman4206 4 жыл бұрын
Nice thank you! Been looking for a detailed api bug video.
@cyberwolf7385
@cyberwolf7385 4 жыл бұрын
You are an amazing teacher Katie!! One can just watch your videos and start a career in Bug bounty hunting. Keep posting more videos. I love your content. You have helped me a lot. Thanks for everything.
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Aww thank you for being a supporter of my work
@Naha-ir9mi
@Naha-ir9mi Жыл бұрын
This is still a well made presentation after 2 years.
@shivanshusahu6121
@shivanshusahu6121 3 жыл бұрын
the way you explain things is just awesome.
@TheMortemGaming
@TheMortemGaming 4 жыл бұрын
Been bouncing around the channels not in order XD but I have to say i love this video and the way you taught it, they keep gettin better and better from what ive seen and super nice to take notes and follow along! Thanks again for the free knowledge !
@Shogunxd3-vp9jv
@Shogunxd3-vp9jv 4 жыл бұрын
This is what I was going to learn about today too! This is amazing! Thank you so much!
@satyaprakasha9356
@satyaprakasha9356 3 жыл бұрын
Your voice gives me a motivation, thank you so much❤❤❤❤
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Hell yeah! Good luck on your hacking journey I’m glad I could inspire you
@lifeofsq5653
@lifeofsq5653 10 ай бұрын
Hello Katie Its wonderful explanation can't wait to test APIs. Thankyou for sharing valuable information :))
@sumitkhadka5123
@sumitkhadka5123 3 жыл бұрын
was looking for information and what u are doing for the community and for all is very helpful thank u for ur beautiful content
@allan_bomb
@allan_bomb 3 жыл бұрын
thank you, thank you and thank you! Keep up the great work! Looking forward seeing more of your videos.
@jacobpetrov4041
@jacobpetrov4041 4 жыл бұрын
Great video, this series is really helping me out. Looking forward to the next one!
@mashin4777
@mashin4777 Жыл бұрын
Thank u, it's really feels like, you have a talent of teaching people
@kandarpmishra6009
@kandarpmishra6009 3 жыл бұрын
can you please elaborate what is "endpoint" at 33:52?
@RinkuVaghela
@RinkuVaghela 4 жыл бұрын
I really apricated your hard work behind your videos .. I love all the videos and learn lots of things thanks a lot
@AdnanDhinojwala
@AdnanDhinojwala 4 жыл бұрын
Was really waiting for something like this, Thank you so much
@kavishgour3267
@kavishgour3267 4 жыл бұрын
My favourite youtuber at the moment :)
@InsiderPhD
@InsiderPhD 4 жыл бұрын
:O I’m so honoured!
@ramsekargnanasekar9384
@ramsekargnanasekar9384 4 жыл бұрын
Really informative video, thanks!!!!!! I have a doubt when I saw zomato api , it showed a list of many GET method , like GET restaurant name, GET location name etc , so should I type the resto name and city name and try to capture the request using burp and run the response. Is this the method like what you are trying to explain?????
@thecast9864
@thecast9864 2 жыл бұрын
love the comments on your notes "seems sus come back"
@felipeolea8810
@felipeolea8810 2 жыл бұрын
Fantastic video, where shoould we look if we cant acces any ways to the apis becauser we dont have the crfs token or auth?
@goldengreengrass
@goldengreengrass Жыл бұрын
Thank you Katie for this wonderful lesson...😄😄
@shekharwagh4982
@shekharwagh4982 3 жыл бұрын
Xcellent Video for Developers trying to start Hacking
@helalsadat2077
@helalsadat2077 Ай бұрын
Starting TOday Lets rock and roll :))
@omnnnooy3267
@omnnnooy3267 2 жыл бұрын
I am so happy I find your channel 🤩
@selimeneskaraduman6935
@selimeneskaraduman6935 4 жыл бұрын
How do you find xss in API? API responses are json content type is xss possible?
@InsiderPhD
@InsiderPhD 4 жыл бұрын
The primary attack is using it to bypass any client-side WAF filters, but you should have a look at XSS write ups with APIs, I added one in the description but there are many others
@rohullahafzali1587
@rohullahafzali1587 Жыл бұрын
Thanks for your great contents.
@renganathanofficial
@renganathanofficial 3 жыл бұрын
you used mouse to write, that's awesome xD
@shift3y
@shift3y 3 жыл бұрын
This is brilliant, thank you! Any suggestions on where I can find CTFs to practice these techniques?
@TalsonHacks
@TalsonHacks 3 жыл бұрын
PortSwigger’s Web Security Academy, PentesterLab
@WaheedIqbal-gb3yt
@WaheedIqbal-gb3yt Жыл бұрын
Hey You made a great job , Thanks a lot
@meispi9457
@meispi9457 4 жыл бұрын
If you could provide those slides, that would be very helpful. thanks, great video!!
@InsiderPhD
@InsiderPhD 4 жыл бұрын
I don't provide my slides simply because I am not comfortable with other people presenting my work, I will see what I can in maybe sorting out some written notes in the future.
@meispi9457
@meispi9457 4 жыл бұрын
@@InsiderPhD Valid point.
@InsiderPhD
@InsiderPhD 4 жыл бұрын
@rl1k Doe It's less because I don't want people to take credit for my work, but because I want to make sure that if my name is attached to something that it's presented correctly with all the facts!
@optional6719
@optional6719 2 жыл бұрын
can websites restrict you to use burpsuit to intercept the requests. I am dealing with a website which is restricting me to use it there and its making it really hard to enumerate the good stuff. any help?
@cyber__hawk5555
@cyber__hawk5555 2 жыл бұрын
Awesome 👍
@ariyankhan2847
@ariyankhan2847 3 жыл бұрын
you should add link of your video in I button or in this description when you are talking about you some other videos
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Excellent idea, thank you I will do this!
@buricobain23
@buricobain23 4 жыл бұрын
Hello is it possible that you can make some video about APIs and perform security tests on PostMan and script? Excellent work I've learned a lot from you.
@InsiderPhD
@InsiderPhD 4 жыл бұрын
This is coming soon :) I’m going to do a video on more API testing tools!
@nicholasxyz8880
@nicholasxyz8880 4 жыл бұрын
The reports you use in your examples, in the future could you give us the url for them so we can look them up? Thanks!
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Now in the description - Information Disclosure: User Information Disclosure via the REST API - /?_method=GET - hackerone.com/reports/384782 - Authorisation Issues: Wordpress.com REST API oauth bypass via Cross Site Flashing - hackerone.com/reports/176308 - Business Logic Errors: Items bought for free due to lacks of quantity controls - hackerone.com/reports/357929 - IDORs: IDOR and statistics leakage in Orders - hackerone.com/reports/544329 - XSS: Stored XSS in blog comments through Shopify API - hackerone.com/reports/192210
@Socversity
@Socversity 4 жыл бұрын
It’s really Great, thank you for changing your mic 😁😁😁
@JohnCiprian
@JohnCiprian 4 жыл бұрын
Great content. Keep it coming!
@pankajprasad9179
@pankajprasad9179 4 жыл бұрын
Really help full thank you
@sayturestorver4334
@sayturestorver4334 Жыл бұрын
Thank you so much !!
@eed5278
@eed5278 4 жыл бұрын
Wow! Good work, very clear.
@2012mrmoh
@2012mrmoh Жыл бұрын
Great, however, how can I concentrate with an ad every minute. Thank you for your hard work .
@InsiderPhD
@InsiderPhD Жыл бұрын
I’m really sorry I actually have midrolls turned off completely but KZfaq will actually add them back into the videos anyway! Feel free to use an adblocker it’s very annoying
@starkeduplatform2320
@starkeduplatform2320 4 жыл бұрын
Thanks for this...really useful for me
@dipakpardesi4661
@dipakpardesi4661 Жыл бұрын
thanks for the video 👍
@wingwing2683
@wingwing2683 2 жыл бұрын
Thanks so much!
@aksharpatel1097
@aksharpatel1097 4 жыл бұрын
Is there something i should know about before starting to learn this?? As i find this quite difficult in some parts
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Try to watch my finding your first bug series in order, but you do need to know a little about how the internet works first! Let me know what you’re struggling with specifically and I’ll try to make more videos on it
@aksharpatel1097
@aksharpatel1097 4 жыл бұрын
@@InsiderPhD thanks!
@neoXXquick
@neoXXquick 4 жыл бұрын
Amazing video.. thx for contribution...
@IteLuis
@IteLuis 4 жыл бұрын
Awesome talk, thank you very much!!
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Glad you liked it! More API videos coming really soon!
@hardwork3196
@hardwork3196 3 жыл бұрын
thanks a lot for awesome information.
@kabirsuda
@kabirsuda 3 жыл бұрын
Really helpful video keep it up!
@noblesix6525
@noblesix6525 4 жыл бұрын
Thank you so much!! Very useful
@digitalcynicism
@digitalcynicism 9 ай бұрын
Microwave Oven, doo Doo Doo Doo Doo doo
@champagnepete3386
@champagnepete3386 4 жыл бұрын
Awesome resource!
@TheHammertownhead
@TheHammertownhead 4 жыл бұрын
I would love to see a sample of your spreadsheet. Would you be willing to share or post link below your video? Great video!! Great content! Thanks for taking the time! A final slide would be great at the end of the video while you are doing final comments as the screen going black, which is a little freaky.
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Link to the spreadsheet :) docs.google.com/spreadsheets/d/1IJvTH6QpTlxWdy4Ss6I0G_f4csCYwBdgE88ya7XijnI/edit?usp=sharing will take your feedback into account for next time!
@TheHammertownhead
@TheHammertownhead 4 жыл бұрын
@@InsiderPhD keep up the great work on these great videos!!! Very informative!! Its greatly appreciated!
@JuanBotes
@JuanBotes 2 жыл бұрын
great training video, thanks for content \o/
@shiftlock452
@shiftlock452 Жыл бұрын
lovely voice🤩
@vishalpatidar2737
@vishalpatidar2737 4 жыл бұрын
Great video, please make a video on CSRF
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Coming next week :)
@hasnainabidkhanzada3754
@hasnainabidkhanzada3754 3 жыл бұрын
Enumeration is a part of a larger recon process. Right?
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Yup but sometimes not! API recon is often discovering endpoints while larger recon is usually exploring a scope in depth
@hasnainabidkhanzada3754
@hasnainabidkhanzada3754 3 жыл бұрын
@@InsiderPhD Exploring a scope could be finding the hidden endpoints. Isn't this also enumeration?
@h4kster182
@h4kster182 4 жыл бұрын
really Great, thank you
@cyrilbeyo8731
@cyrilbeyo8731 4 жыл бұрын
Thank you This was helpful
@xx2125
@xx2125 4 жыл бұрын
Hi Katie, thanks for this superb video. Do you have somewhere the presentation for download?
@InsiderPhD
@InsiderPhD 4 жыл бұрын
No, sorry, unless it's mentioned specifically in the video descriptions I don't make slides freely available, usually I do for conference talks!
@xx2125
@xx2125 4 жыл бұрын
​@@InsiderPhD Ok, so I will take notes from your videos. :)
@albonycal
@albonycal 3 жыл бұрын
I'm little bit confused @ 30:29 that means if we remove the cookies and the api accepts it... Does this bypasses Authorization... I'm confused
@InsiderPhD
@InsiderPhD 3 жыл бұрын
By removing cookies we are basically “logged out” which is why it works, there are many different type of IDORs but it’s a quick litmus test to check!
@shrirangkahale
@shrirangkahale 3 жыл бұрын
Got it..
@hannanjamil1060
@hannanjamil1060 4 жыл бұрын
Can you please share slides? BTW thank you so much. ❤🌹
@emreru5687
@emreru5687 4 жыл бұрын
Thank you so much
@yogteacherdilipmotkar8801
@yogteacherdilipmotkar8801 4 жыл бұрын
Plz tell which lecture are coming at what time means future schedule plz
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Next up: Q and A - midweek next week RCE bug in focus - 18th Jan CSRF finding your first bug - 25th Jan I often post in the channel community tab or on twitter when I know what my next video will be!
@nishikanttayade7446
@nishikanttayade7446 3 жыл бұрын
For Web Developers start at 14:30
@isfk
@isfk 3 жыл бұрын
Reusing code by creating a web API is not being lazy, its being smart.
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Of course! It’s just a joke :)! Using an API can also reduce development time when you’re managing a desktop, web and mobile app for example
@yethu7682
@yethu7682 4 жыл бұрын
can you share the slide of this video?
@RahulYadav-qg9ms
@RahulYadav-qg9ms 4 жыл бұрын
please bring some practical beside theory
@thehackerish
@thehackerish 4 жыл бұрын
1337 video! Is it just a chance or I am the 3337th person to view the video? :D
@henryasubonteng695
@henryasubonteng695 4 жыл бұрын
Thank
@MrTiger-eg1gr
@MrTiger-eg1gr 3 жыл бұрын
This was great. But, if you don't mind, can you please slow down a lil bit while talking?
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Of course! Thank you for your feedback! I will definitely try to talk slower and pace myself better!
@bugsbunny6286
@bugsbunny6286 4 жыл бұрын
Can you make a good video on XSS explaining all of them briefly and ways to find it out easily
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Great idea I will make this video!
@yassindaboussi2570
@yassindaboussi2570 4 жыл бұрын
thank You
@goooooo9197
@goooooo9197 4 жыл бұрын
How to find that api plz tell that
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Keep an eye out for web apps which have mobile app counterparts, often they both use the same API, another option is to take a look at mobile apps (video coming soon!), but in the meantime, you can check out Spaceraccoon's recent iOS blog spaceraccoon.dev/low-hanging-apples-hunting-credentials-and-secrets-in-ios-apps or using Genymotion to set up an Android emulator
@ishansaha8652
@ishansaha8652 Жыл бұрын
can i get your PPT?
@probeing9418
@probeing9418 4 жыл бұрын
it will be gud if u give reports link is description
@InsiderPhD
@InsiderPhD 4 жыл бұрын
Now in the description - Information Disclosure: User Information Disclosure via the REST API - /?_method=GET - hackerone.com/reports/384782 - Authorisation Issues: Wordpress.com REST API oauth bypass via Cross Site Flashing - hackerone.com/reports/176308 - Business Logic Errors: Items bought for free due to lacks of quantity controls - hackerone.com/reports/357929 - IDORs: IDOR and statistics leakage in Orders - hackerone.com/reports/544329 - XSS: Stored XSS in blog comments through Shopify API - hackerone.com/reports/192210
@hanko1
@hanko1 3 жыл бұрын
i have watched 'All' of your videos but never fined a bug
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Keep an eye out I’m posting a video just for you soon!
@hanko1
@hanko1 3 жыл бұрын
@@InsiderPhD I would be so happy
@SumitSingh-xu4qs
@SumitSingh-xu4qs 3 жыл бұрын
mam your voice is very beautiful
@beamedbyflimzy5463
@beamedbyflimzy5463 3 жыл бұрын
huh
@beamedbyflimzy5463
@beamedbyflimzy5463 3 жыл бұрын
sorry for bad comment
@funkiimonke6129
@funkiimonke6129 3 жыл бұрын
You british?
@InsiderPhD
@InsiderPhD 3 жыл бұрын
Yup! From Surrey live in Manchester
Finding Your First Bug: Getting Started on a Target (Part 1)
48:47
How To Do Recon: API Enumeration
56:12
InsiderPhD
Рет қаралды 59 М.
Schoolboy Runaway в реальной жизни🤣@onLI_gAmeS
00:31
МишАня
Рет қаралды 3,7 МЛН
The Joker saves Harley Quinn from drowning!#joker  #shorts
00:34
Untitled Joker
Рет қаралды 72 МЛН
Кадр сыртындағы қызықтар | Келінжан
00:16
My Cheetos🍕PIZZA #cooking #shorts
00:43
BANKII
Рет қаралды 28 МЛН
Hacking when all the bugs have been found?
18:53
InsiderPhD
Рет қаралды 5 М.
Why Your IDORs Get NA’d, Cookies Explained
20:09
InsiderPhD
Рет қаралды 16 М.
How I made 1k in a day with IDORs! (10 Tips!)
23:09
InsiderPhD
Рет қаралды 51 М.
Finding Your First Bug: Manual IDOR Hunting
33:28
InsiderPhD
Рет қаралды 76 М.
API Testing Using Postman | Crash Course
3:27:51
Mukesh otwani
Рет қаралды 90 М.
Top 10 API Bugs (and Where to Find Them)
30:04
InsiderPhD
Рет қаралды 24 М.
How To Hack APIs with Python
22:55
John Hammond
Рет қаралды 86 М.
Finding Your First Bug: Goal Setting and Motivation
29:48
InsiderPhD
Рет қаралды 22 М.
everyone should test their code this way
8:34
Low Level Learning
Рет қаралды 80 М.
Real Bugs - API Information Disclosure
17:32
The Cyber Mentor
Рет қаралды 33 М.
Schoolboy Runaway в реальной жизни🤣@onLI_gAmeS
00:31
МишАня
Рет қаралды 3,7 МЛН