Bug Bounty bootcamp // Get paid to hack websites like Uber, PayPal, TikTok and more
How to get experience with no experience? Have a look at bug bounty programs. Vickie Li demos Insecure Direct Object References (IDOR) and tells us how to get into bug bounty. We also discuss why her book Bug Bounty Bootcamp is a fantastic book to buy if you want to get into bug bounty. Get real world experience today.
// MENU //
00:00 - In plain text!
00:24 - Introducing//Vickie Li
00:58 - Part 1//The Interview
01:01 - Origin//Bug Bounty Bootcamp
03:37 - What are Bug Bounty Programmes?
05:26 - Part Time Bug Hunting?
05:44 - Easy Way to Get Experience
07:45 - Which Bug Bounty Programmes for B…
Watch on YouTube ↗
(saves to browser)
Chapters (36)
In plain text!
0:24
Introducing//Vickie Li
0:58
Part 1//The Interview
1:01
Origin//Bug Bounty Bootcamp
3:37
What are Bug Bounty Programmes?
5:26
Part Time Bug Hunting?
5:44
Easy Way to Get Experience
7:45
Which Bug Bounty Programmes for Beginners?
10:51
Beginners//Don't Compete with Pros
13:15
Duplicates as Valid Experience
14:23
What You Need to Start
14:59
Linux//Do You Need It?
15:55
Automate!//Which Programming Language?
18:03
Beginner Friendly Vulnerabilities
21:17
Part 2//Exploiting IDOR Vulnerability Demo
21:24
What is IDOR?
22:51
PortSwigger IDOR Lab
24:05
Live Chat IDOR
24:48
View transcript
25:12
Burp Suite Intercept
26:05
What to Look For//IDs Aren't Always Obvious
26:56
Burp Suite//Looking Through Headers
27:56
Burp Suite//Repeater
28:30
Testing View Transcript Again
29:18
GET Request//Identifying Exploitable Endpoint
30:26
Modifying GET Request
31:35
Finding the right headers to modify
33:47
Why the first attempt didn't work
34:09
IRL//What You Would Do
34:23
Password in Live Chat Transcript
35:40
How to Prevent IDORs
36:01
IDORs//Worth Pursuing?
39:57
Bug Bounties//How to Start
41:21
Learn More!//Vickie's Blog
41:38
Follow Vickie's Twitter!
41:52
Thank You & Closing
Playlist
Uploads from David Bombal · David Bombal · 59 of 60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
▶
60
16 secs to break it! 😱 70% of real world WiFi networks owned!
David Bombal
Traceroute explained // Featuring Elon Musk // Demo with Windows, Linux, macOS
David Bombal
Bug Bounty 2022 Guide: Where to focus // How to make money // How to get started today
David Bombal
How Nmap really works // And how to catch it // Stealth scan vs TCP scan // Wireshark analysis
David Bombal
TLS Handshake Deep Dive and decryption with Wireshark
David Bombal
Real World Talks: pfsense firewalls for home and business? // Featuring Tom Lawrence
David Bombal
Bug Bounty: Get paid to hack PayPal and TikTok // Featuring Nahamsec
David Bombal
Troubleshooting slow networks with Wireshark // wireshark filters // Wireshark performance
David Bombal
Hacking Linux // Linux Privilege escalation // Featuring HackerSploit
David Bombal
Computer Science isn't programming! // How to become a Master Programmer // Featuring Dr Chuck
David Bombal
Hacking Power Plants and Industrial Control Systems (Scada)
David Bombal
Hacking networks with Python // Creating malicious packets and breaking TCP/IP rules
David Bombal
OSINT: You can't hide // Your privacy is dead // Best resources to get started
David Bombal
Website Hacking Demos using Cross-Site Scripting (XSS) - it's just too easy!
David Bombal
Hacking APIs and Cars: You need to learn this in 2023!
David Bombal
How TCP really works: MTU vs MSS
David Bombal
Hacking CCTV and IP cameras: Are you safe?
David Bombal
They said this doesn't work 🤣 Hacking networks with VLAN hopping and Python
David Bombal
WiFi has changed: Is UniFi better than Cisco?
David Bombal
You need to take control
David Bombal
My channel changes today
David Bombal
Synology NAS Quick Setup
David Bombal
Best Hacking Podcast in the world?
David Bombal
Hack like Mr Robot // WiFi, Bluetooth and Scada hacking
David Bombal
Do you realize that they are watching you? Protect your online privacy
David Bombal
Learn to hack in 60 seconds?
David Bombal
Hacking is not a crime. A real world story.
David Bombal
Get the Best Python Books for Free
David Bombal
She hacked me!
David Bombal
You are in a Cyber War. Don't be a dumb*** and try to ignore it
David Bombal
OSINT tools to track you down. You cannot hide.
David Bombal
Best Hacking Python Book?
David Bombal
SMS spoofing and Raspberry Pi Scada hacking
David Bombal
Hacker saves the world. Teaches you hacking.
David Bombal
Shodan demo vs hot cybersecurity trend?
David Bombal
The Internet just changed.
David Bombal
Hack Wifi from $1.80
David Bombal
The truth about AI and why you should learn it - Computerphile explains
David Bombal
Kali Linux NetHunter Android install in 5 minutes (rootless)
David Bombal
Is this the future of the Internet? UDP Deep Dive.
David Bombal
Warning! Python Remote Keylogger (this is really too easy!)
David Bombal
Free API Hacking course!
David Bombal
Kali Linux on all the things! (6 minute install)
David Bombal
#1 reason for data breaches! Free AppSec courses!
David Bombal
Warning! This is how cars are hacked. Just like in Mr Robot.
David Bombal
Uber, Rockstar fell for this attack. Will you?
David Bombal
Is Skynet watching you already?
David Bombal
Warning! Android phone remote control // Hackers can hack your phone
David Bombal
My YouTube channel being hacked // Lessons learned from hack
David Bombal
Hacker hunting with Wireshark (even if SSL encrypted!)
David Bombal
Best WiFi Hacking tools: Airgeddon, Kismet, Raspberry Pi and Kody's favourite wifi tools
David Bombal
Linux and Python on your phone for free in 2 minutes // iPhone or Android
David Bombal
OSINT social media: Are you crazy to share so much information online? 😱
David Bombal
Hacking cell phones like Mr Robot
David Bombal
Hacking WiFi with a Hak5 Pineapple
David Bombal
Did you know this about Virtual Machines (VMs)? Kali Linux, Ubuntu, Windows 11, macOS?
David Bombal
Rat hacks website in 5 minutes 😱
David Bombal
Is it possible to hack WiFi with a phone?
David Bombal
Bug Bounty bootcamp // Get paid to hack websites like Uber, PayPal, TikTok and more
David Bombal
OSINT: Have U been pwned?
David Bombal
DeepCamp AI