🌟 Premium LIVE Blockchain Bootcamp(8 Weeks)🌟
https://www.codeeater.in/
🔍 Dive into the world of bug hunting with our comprehensive tutorial! 🐞 Whether you're a seasoned developer, a curious beginner, or simply intrigued by the intricate world of software, this video will equip you with essential skills to uncover and squash bugs like a pro.
Course Contents -
➡️ (00:00:00) Introduction
➡️ (00:01:32) Prerequisites
➡️ (00:01:55) Important Instructions
➡️ (00:03:24) Contents
➡️ (00:04:51) What is Bug hunting?
➡️ (00:06:52) What is penetration testing?
➡️ (00:08:22) Penetration testing vs bug hunting
➡️ (00:12:57) Website Fundamentals
➡️ (00:20:02) Vulnerabilities
➡️ (00:21:32) Information Disclosure
➡️ (00:22:38) Ways of Attacks for Information Disclosure
➡️ (00:24:20) Instruction for labs
➡️ (00:26:05) PortSwigger
➡️ (00:27:44) Lab - Source code disclosure via backup files
➡️ (00:34:31) Lab - Information disclosure on debug page
➡️ (00:49:35) Lab - Information disclosure in version control history
➡️ (01:03:58) Lab - Information disclosure in error messages
➡️ (01:08:38) Information Disclosure Attacks Summary
➡️ (01:09:42) Broken Access control
➡️ (01:12:00) Ways of attack for broken access control
➡️ (01:13:16) Burp Suite Installation
➡️ (01:24:46) Lab - User role controlled by request parameter
➡️ (01:32:39) Lab - User role controlled by request parameter with unpredictable user IDs
➡️ (01:35:52) IDOR - Insecure Direct Object Reference
➡️ (01:38:38) Lab - Insecure direct object references
➡️ (01:45:28) Lab - The user role can be modified in a user profile
➡️ (01:52:32) What is Trace?
➡️ (01:55:26) Lab - Authentication bypass via information disclosure
➡️ (02:06:18) What is Path Traversal?
➡️ (02:08:47) Lab - File path traversal, traversal sequences blocked with absolute path bypass
➡️ (02:13:32) Lab - File path traversal, simple case
➡️ (02:17:34) Lab - File path traversal, validation of file extension with null byte bypass
➡️ (02:23:15) Broken AccessControl Summary
➡️ (02:24:13) What is Client Side Forgery (CSRF)?
➡️ (02:25:27) Lab - CSRF where the token is not tied to the user session
➡️ (02:32:33) What is OAuth 2.0?
➡️ (02:38:45) Lab - Authentication bypass via OAuth implicit flow
➡️ (02:47:54) End Note
Other Links -
SecLists - https://github.com/danielmiessler/Sec...
Feroxbuster - https://www.kali.org/tools/feroxbuster/
https://0a7600270479466c80c5854600080...
Burpsuite - https://www.kali.org/tools/burpsuite/
🟡 Labs 🟡
1) Source code disclosure via backup files - https://portswigger.net/web-security/...
2) Information disclosure on debug page - https://portswigger.net/web-security/...
3) Information disclosure in version control history - https://portswigger.net/web-security/...
4) Information disclosure in error messages - https://portswigger.net/web-security/...
5) User role controlled by request parameter (1st) - https://portswigger.net/web-security/...
6) User role controlled by request parameter with unpredictable user IDs - https://portswigger.net/web-security/...
7) Insecure direct object references - https://portswigger.net/web-security/...
8) User role can be modified in user profile - https://portswigger.net/web-security/...
9) Authentication bypass via information disclosure - https://portswigger.net/web-security/...
10) File path traversal, traversal sequences blocked with absolute path bypass - https://portswigger.net/web-security/...
11) File path traversal, simple case - https://portswigger.net/web-security/...
12) File path traversal, validation of file extension with null byte bypass - https://portswigger.net/web-security/...
13) Authentication bypass via OAuth implicit flow - https://portswigger.net/web-security/...
14) CSRF where the token is not tied to the user session - https://portswigger.net/web-security/...
📧 Business Email - [email protected]
LinkedIn - / kshitijweb3
Thank you for watching !
Cheers,
Code Eater
#codeeater #developer