This is my coolest bug bounty report (SSRF ➡ Phishing)

  Рет қаралды 8,309

Bug Bounty Reports Explained

Bug Bounty Reports Explained

Күн бұрын

Пікірлер: 24
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Hi! In a few days, the price of BBRE Premium goes up but if you subscribe, you will lock in the current price forever! Go to bbre.dev/premium
@francisdonald4298
@francisdonald4298 2 жыл бұрын
Hey bro can learn web development make someone a better hacker
@francisdonald4298
@francisdonald4298 2 жыл бұрын
???
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
yes
@axelvirtus2514
@axelvirtus2514 2 жыл бұрын
@@francisdonald4298 ye its more easy for developers to find bugs,have a friend working dev in java,he found great bugs in programs thats use java.
@francisdonald4298
@francisdonald4298 2 жыл бұрын
@@axelvirtus2514 i appreciate thanks bro
@J0R1AN
@J0R1AN 2 жыл бұрын
I think the reason cool and creative bugs often don't have a big impact, is that you found a way to do something weird on the site, but you're searching for a way to barely exploit it. That requires some really creative thinking to find a cool bug. When you just find a CVE with some big impact on a site, you're not thinking very creatively and just want to report it as soon as possible
@dhyeychoksi5178
@dhyeychoksi5178 2 жыл бұрын
Cool find!
@terabaap1719
@terabaap1719 2 жыл бұрын
love your content brother❤
@polonia66
@polonia66 2 жыл бұрын
Well done! Thanks for video
@sazukegu
@sazukegu 2 жыл бұрын
Cool find! You feel any difference in "difficulty" when comparing public an private programs? Also, im still waiting for the next 100 hour video!
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Well, counterintuitively, the bugs I am finding on this program are more complex and harder to exploit that bugs that I was finding on public ones. I am also waiting for the next 100 hour video from Elastic but I am starting to think that before I get the disclosure there, I will finish the 50 hours on this private program and since I won't have to wait for disclosures here, I may publish this bounty vlog earlier.
@aryzen2781
@aryzen2781 Жыл бұрын
how did you learn web app security.
@terabaap1719
@terabaap1719 2 жыл бұрын
❤❤❤
@farah13384
@farah13384 2 жыл бұрын
Hello, I need you and your help with my revenge plan, and I can explain to you why I want revenge and with the right evidence, can you help me?
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
No
@raihanhossain3423
@raihanhossain3423 2 жыл бұрын
How can we bypass the BBRE PREMIUM ? he he he
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
Actually, one guy did, accidentally, and he has the free subscription now
@raihanhossain3423
@raihanhossain3423 2 жыл бұрын
wow, that's great. I should try then 😀
@utensilapparatus8692
@utensilapparatus8692 2 жыл бұрын
3:30 : ! 7:47 : !*!
@CristiVladZ
@CristiVladZ 2 жыл бұрын
I think you're wasting away your genius thinking with these bug bounties. You can probably score much more in traditional pentesting with your skills, and way less friction.
@BugBountyReportsExplained
@BugBountyReportsExplained 2 жыл бұрын
I will consider this option but after a few years.
@SUMMedia
@SUMMedia 2 жыл бұрын
@Cristi Vlad I'm just curious to know more about that. What does the traditional pentesting mean? Is it like freelance pentesting service more like bug bounty hunting? Or, Is it joining a company as a pentester?
100 hours of bug bounty on a public Hackerone program. Bounty vlog #1 - Stripe
14:39
Bug Bounty Reports Explained
Рет қаралды 15 М.
How to get greater bounties for MEDIUM and LOW risk reports? Account takeover - Stripe
12:55
ROLLING DOWN
00:20
Natan por Aí
Рет қаралды 10 МЛН
ISSEI & yellow girl 💛
00:33
ISSEI / いっせい
Рет қаралды 22 МЛН
Get 10 Mega Boxes OR 60 Starr Drops!!
01:39
Brawl Stars
Рет қаралды 17 МЛН
Bony Just Wants To Take A Shower #animation
00:10
GREEN MAX
Рет қаралды 7 МЛН
Server-Side Request Forgery (SSRF) Explained
15:58
NahamSec
Рет қаралды 25 М.
How much money I made in my 1st year of bug bounty? Bounty vlog #4
17:02
Bug Bounty Reports Explained
Рет қаралды 149 М.
$2,500 Leaking parts of private Hackerone reports - timeless cross-site leaks
10:14
Bug Bounty Reports Explained
Рет қаралды 4,8 М.
Rat hacks website in 5 minutes 😱
53:49
David Bombal
Рет қаралды 279 М.
Finding Your First Bug
9:14
NahamSec
Рет қаралды 41 М.
Missing HTTP Security Headers - Bug Bounty Tips
15:48
LiveOverflow
Рет қаралды 139 М.
$16k Stealing secrets.yaml from GitLab using stored XSS - Hackerone bug bounty
9:48
Bug Bounty Reports Explained
Рет қаралды 6 М.
How to do account takeover? Case study of 146 bug bounty reports
30:23
Bug Bounty Reports Explained
Рет қаралды 10 М.
$28k IDOR that broke Apple Shortcuts - Apple bug bounty
8:04
Bug Bounty Reports Explained
Рет қаралды 6 М.
Networking For Hackers! (Common Network Protocols)
23:43
Hacker Joe
Рет қаралды 439 М.
Запрещенный Гаджет для Авто с aliexpress 2
0:50
Тимур Сидельников
Рет қаралды 2 МЛН
when foldable cellphones follow the trend#shorts
0:11
amazing populer
Рет қаралды 14 МЛН
Лучшая защита экрана
0:40
Newtonlabs
Рет қаралды 658 М.
Самый дорогой телефон 2000х
0:54
МАДНЕСС
Рет қаралды 2,1 МЛН