Live Bug Bounty Hunting | Client-Side Injection Testing on Starbucks Japan (Plus Q&A)

  Рет қаралды 14,276

rs0n_live

rs0n_live

Күн бұрын

This stream had a great mix of finding/testing Client-Side Injection Attack Vectors, general bug bounty hunting questions, and general enumeration to find hidden endpoints on authenticated routes.
Discord - / discord
Hire Me! - ars0nsecurity.com
Watch Live! - / rs0n_live
Free Tools! - github.com/R-s0n
Connect! - / harrison-richardson-ci...

Пікірлер: 35
@bradnaylor35
@bradnaylor35 5 ай бұрын
It's interesting to watch a bug bounty hunter's thought process when performing initial sitemapping/recon and then exploring common injection points. Thanks for the video!
@cacurazi
@cacurazi 5 ай бұрын
Yup… seeing someone taking notes before doing the “hacking” stuff I know they are knowledgeable and good things are going to happen. Subscribed!
@sw33d-jd1xm
@sw33d-jd1xm 5 ай бұрын
Awesome video! It's incredibly beneficial for beginners like us. Thanks a lot!
@walterwhite-du4rn
@walterwhite-du4rn 5 ай бұрын
You are gem for me..I learned a lot of burp suite using techniques from you.Thank you❤
@kittoh_
@kittoh_ 5 ай бұрын
Please don't stop doing this stuff! They're gold!
@Shivamhirwani
@Shivamhirwani 5 ай бұрын
Love this stream 😊
@user-oy6vv3go6d
@user-oy6vv3go6d 5 ай бұрын
Underrated stream
@z1ro_zb
@z1ro_zb 5 ай бұрын
Thanks for the content!
@HackAll-ue3sr
@HackAll-ue3sr 5 ай бұрын
I love you sir you are making our minds to open on a level of urs ❤❤❤
@user-zd5tz4sz5o
@user-zd5tz4sz5o 5 ай бұрын
how to choose the right subdomain after reconnaissance to start testing correctly? I often receive hundreds of subdomains and do visual reconnaissance, but often I don’t understand where to start. It would be very interesting to see a video on this topic, since many hunters miss this in their creativity on KZfaq
@bakeery
@bakeery 5 ай бұрын
Thank you for keeping your words :)
@steiner254
@steiner254 4 ай бұрын
Superb Cool
@user-jo4ko7si6s
@user-jo4ko7si6s 2 ай бұрын
great source Thanks
@b4arabe132
@b4arabe132 3 ай бұрын
love u man
@1a4s4l7
@1a4s4l7 5 ай бұрын
24:35 - 3 approaches 30:24 - insertion points
@aliuzun8885
@aliuzun8885 4 ай бұрын
Ty
@BEKTIPS
@BEKTIPS 5 ай бұрын
Make a video for a beginners like in which bug do we must focus on and your methodologies and show us the first bug you search for in a web app pls
@brs2379
@brs2379 5 ай бұрын
Any ideas on how to escalate CSS injection on a site where script tags and all event handlers are blocked by WAF?
@YettouYettou-uj9du
@YettouYettou-uj9du 5 ай бұрын
I see xss-protection:1 And amazon cloudfront How do you deal with thes ? Spesialy the second one because will block every single payload injectiin
@brendan8665
@brendan8665 5 ай бұрын
Do you pay for proton vpn premium? I wonder if I need that instead
@BugbountyPOCs41
@BugbountyPOCs41 5 ай бұрын
what are your laptop specs?
@Booom1444-_-
@Booom1444-_- 5 ай бұрын
Please create KZfaq video content for learning from beginners to advanced levels.
@HAzorTeam
@HAzorTeam 5 ай бұрын
Roadmap 2024 Bug Bounty Hunting and plataform earn money thanks
@eyephpmyadmin6988
@eyephpmyadmin6988 5 ай бұрын
No one wants the beginners videos theirs millions out their we need the most advanced of the advanced. Trust me youll bottleneck with all the beginner stuff. I rarely see any advanced stuff
@SumitYadav-lr5vy
@SumitYadav-lr5vy 4 ай бұрын
​@@HAzorTeamwhat do you mean?
@anurag.30302
@anurag.30302 5 ай бұрын
why the hell you don't use chrome that will help in language translation on that page itself
@master-manhood
@master-manhood 5 ай бұрын
Hi R-s0n, If you could provide the timestamp in your KZfaq video, it would be great, bcoz if often come back again and search for a particular piece. If you can would be much appreciated.
@user-oo4on5lg9m
@user-oo4on5lg9m 4 ай бұрын
Sorry how can I join your discord server 😞
@rabin2439
@rabin2439 17 күн бұрын
Bro come backkkkkkkkkkkkkkkkk
@theairsharma
@theairsharma 5 ай бұрын
2nd,runner up
@uttarkhandcooltech1237
@uttarkhandcooltech1237 5 ай бұрын
thanks sir
@orbitxyz7867
@orbitxyz7867 5 ай бұрын
2nd
@-Engineering01-
@-Engineering01- 5 ай бұрын
Seems being a security professional means using built-in software to find vulnerabilities. I didn't thought that way, i used to thought security professionals were so good at coding. But seems most of them are totally garbage at that(i don't mean you), so i left pursuing it and went to software engineering. I would rather to develop burp suite itself, rather than doing bug hunting using it.
@aashutoshlodhi1029
@aashutoshlodhi1029 5 ай бұрын
1st
@user-fb4pi6yf6o
@user-fb4pi6yf6o 5 ай бұрын
Thank you , I love you
Always be more smart #shorts
00:32
Jin and Hattie
Рет қаралды 29 МЛН
Универ. 13 лет спустя - ВСЕ СЕРИИ ПОДРЯД
9:07:11
Комедии 2023
Рет қаралды 6 МЛН
She ruined my dominos! 😭 Cool train tool helps me #gadget
00:40
Go Gizmo!
Рет қаралды 57 МЛН
How much money I made in my 1st year of bug bounty? Bounty vlog #4
17:02
Bug Bounty Reports Explained
Рет қаралды 138 М.
IDOR with EXIF Vulnerability | Bug Bounty POC
2:16
Jiiva hack
Рет қаралды 1,7 М.
From zero to 6-digit bug bounty earnings in 1 year - Johan Carlsson - BBRD podcast #3
1:08:37
How Microsoft Accidentally Backdoored 270 MILLION Users
14:45
Daniel Boctor
Рет қаралды 242 М.
Dominating Bug Bounties in 2024!
16:55
g0lden
Рет қаралды 7 М.
Install Nessus for Free and scan for Vulnerabilities (New Way)
14:56
🤖 iRobot | Live Bug Bounty Hunting 🕵️‍♂️
24:25