Revealing Secrets with Information Disclosure Bugs

  Рет қаралды 7,249

InsiderPhD

InsiderPhD

Күн бұрын

Information disclosure is really broad, ranging from technical things like finding API keys or code review, to that webpage is displaying my address publicly! So they can be great bugs particularly if you don't have access to a regular computer or you're not familiar with
This series couldn't happen without the support of our sponsor Bugcrowd, Bugcrowd is the best place to start hacking with a wide range of public and private programs from APIs to Desktop Applications and everything in between. Not ready to jump into a public program yet? Fill out your platform CV and sign up for a waitlisted program. Tell Bugcrowd a bit about your skills, previous certifications or experience and they’ll match you up with the right program using their industry-leading CrowdMatch technology. Whatever your level, there’s a place for you in the crowd. You can sign up with my link here: bugcrowd.com/user/sign_up.
- Social Media -
Discord: insiderphd.dev/discord
Patreon: / insiderphd
Twitter: / insiderphd

Пікірлер: 20
@mostafaomer1513
@mostafaomer1513 Жыл бұрын
I've been waiting for this for a long time❤❤ I decided to get started with information disclosure
@ariel1l
@ariel1l Жыл бұрын
Thank you very much! I would love to hear next month on the "Authorize" burp add one with practical example, thank you again I love you content !
@taiwomiracleveecthor2617
@taiwomiracleveecthor2617 Жыл бұрын
Thank you so much for aspiring us more
@alexandersoltesz8103
@alexandersoltesz8103 Жыл бұрын
Great content as always, thanks so much!
@SolitaryElite
@SolitaryElite Жыл бұрын
omg, i was literally going to comment asking if you were going to make a vid about info disclosure bugs today💀💀
@elbivio
@elbivio Жыл бұрын
Thanks!
@ridowansikder6374
@ridowansikder6374 Жыл бұрын
Great contents , loving it so far Would you please considering also share the slides with these videos ? That will be really helpful
@mostafaomer1513
@mostafaomer1513 Жыл бұрын
🎉❤ I hope to find first bug information disclosure
@aqwerzerd
@aqwerzerd Жыл бұрын
HEYYYY professor Missed you really
@mr.researcher1525
@mr.researcher1525 Жыл бұрын
Welcome..back..🎉🎉
@camelotenglishtuition6394
@camelotenglishtuition6394 Жыл бұрын
Great job! I also had a random q? I'm testing a parameter on a site and I'm getting a 500 with the ' so it seems vulnerable to sqli. It also seems to allow me to add to an sql statement but everything I try just gives me a 200 status. Shall I just walk away? lol or perhaps you have a little advice?
@InsiderPhD
@InsiderPhD Жыл бұрын
Blind SQL injection, see if it takes a lil longer to load!
@camelotenglishtuition6394
@camelotenglishtuition6394 Жыл бұрын
@@InsiderPhD yeah I tried a timing attack with sleep (10) but still nothing, frustrating as it's clearly vuln but I can't get anything out of it. Fantastic of your to come back so fast, thank you. Any other ideas or just walk away? lol
@badxcode
@badxcode Жыл бұрын
@@camelotenglishtuition6394 super late but did your try out-of-band techniques? :)
@greentorm5467
@greentorm5467 Жыл бұрын
Could someone change GCSE grades? I'm well out of school, just a curious question?
@Nightfire6565
@Nightfire6565 Жыл бұрын
First
@onisakura9
@onisakura9 8 ай бұрын
So if someone were able to an start editing people's names, phone numbers, location on those peoples accounts when they aren't supposed to be--is that a security vulnerability? Edit: whoops... never mind--if I'm using their cookies to change their info then that would be intended behavior--sorry 😅
@InsiderPhD
@InsiderPhD 8 ай бұрын
Sorry to disappoint:( yeah you need to do it without the victims cookie it’s just a way to simulate logging into accounts easily
@onisakura9
@onisakura9 8 ай бұрын
Bummer... Back to the drawing board 😅
@rb-py5cv
@rb-py5cv Жыл бұрын
Hello ma'am thank you for the videos but in the videos there is missing methodology and approach of it to find bug and i need the methodology and right techniques to find bug 🪲 please ma'am can you see through this and thanks for everything❤
"Easiest" Beginner Bugs? Access Control and IDORs
31:46
InsiderPhD
Рет қаралды 19 М.
Hacking when all the bugs have been found?
18:53
InsiderPhD
Рет қаралды 5 М.
Этот Пёс Кое-Что Наделал 😳
00:31
Глеб Рандалайнен
Рет қаралды 3,5 МЛН
ТАМАЕВ УНИЧТОЖИЛ CLS ВЕНГАЛБИ! Конфликт с Ахмедом?!
25:37
Smart Sigma Kid #funny #sigma #comedy
00:25
CRAZY GREAPA
Рет қаралды 26 МЛН
Why Your IDORs Get NA’d, Cookies Explained
20:09
InsiderPhD
Рет қаралды 16 М.
HOW-I-APPROACH Bug-Bounty-Target FOR-BEGINNERS
28:50
hacksys
Рет қаралды 13 М.
Approaching Large Scope Targets Without Feeling Overwhelmed
20:13
My Hacking Setup and How to Use It (Firefox/Burp Community)
28:28
Finding Your First Bug: Finding Bugs Using APIs
43:35
InsiderPhD
Рет қаралды 106 М.
Giving Yourself the Best Opportunity to Find a Bug
36:45
InsiderPhD
Рет қаралды 6 М.
Finding Your First API Bug (NahamCon 2023)
22:10
InsiderPhD
Рет қаралды 10 М.
Bug Bounty on Steroids
1:03:19
BSides Ahmedabad
Рет қаралды 19 М.
How I Found My First Bug (and earned $1k!) - Business Logic Tips
19:41
Этот Пёс Кое-Что Наделал 😳
00:31
Глеб Рандалайнен
Рет қаралды 3,5 МЛН