Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

Finding Your First Bug: Manual IDOR Hunting

Автор: InsiderPhD

Загружено: 2019-11-29

Просмотров: 83992

Описание:

Hi everyone, welcome to the third video in the "Finding Your First Bug" in this series I'm going to go over some good first bugs: explain what they are, how to find them, show some examples of real bugs in the wild that paid out and finally do a practical example with Burp on a real target.

In this video, we'll be talking about IDORs (Insecure Direct Object Reference), which is a fancy term for 'the application didn't authenticate an endpoint correctly'. These are great first bugs, they don't require any technical knowledge and you can just use burp to find them.

0:00 - Theory: what is an IDOR and how to find them
8:21 - Case studies: 7 examples of IDORs which have paid out
27:28 - Practical Burp: Looking at the Hacker101 CTF level "postbook"

-- Case Studies --
Response program can create bounty table - $500: https://hackerone.com/reports/460920
[IDOR] Deleting other people's tasks - $300: https://hackerone.com/reports/293845
IDOR bug to See hidden slowvote of any user even when you dont have access right - $300: https://hackerone.com/reports/661978
Bypass of my three other reports #267636 + #255894 + #271861 - (IDOR) Ability to see full name associated with other New Relic accounts - $1,500: https://hackerone.com/reports/320173 and https://www.jonbottarini.com/2018/01/...
Replace other user files in Inbox messages - $1,000: https://hackerone.com/reports/322661
Low Privileged user able to add new Geographical settings to the Admin account. - $750: https://hackerone.com/reports/420130
Validation message in Bounty award endpoint can be used to determine program balances - $1,500: https://hackerone.com/reports/293299
IDOR to add secondary users in www.paypal.com/businessmanage/users/api/v1/users - $10,500: https://hackerone.com/reports/415081

-- You Should Also Watch --
Burp Suite tutorial: IDOR vulnerability automation using Autorize and AutoRepeater (bug bounty) - STÖK -    • Burp Suite tutorial: IDOR vulnerability au...  

-- Social Media --
Twitter:   / insiderphd  

Finding Your First Bug: Manual IDOR Hunting

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

How to Use Firefox Containers for Easy IDOR Hunting (With Demo!)

How to Use Firefox Containers for Easy IDOR Hunting (With Demo!)

Finding Your First Bug: Choosing Your Target

Finding Your First Bug: Choosing Your Target

Still not found your first bug? Try IDORs

Still not found your first bug? Try IDORs

На какие ошибки следует обращать внимание в API GraphQL? Пример программы Bug Bounty

На какие ошибки следует обращать внимание в API GraphQL? Пример программы Bug Bounty

Bug bounty tools that actually land bugs with Arthur Aires

Bug bounty tools that actually land bugs with Arthur Aires

Why Your IDORs Get NA’d, Cookies Explained

Why Your IDORs Get NA’d, Cookies Explained

Finding Your First Bug: Business Logic Errors

Finding Your First Bug: Business Logic Errors

Подробно о HTTP: как работает Интернет

Подробно о HTTP: как работает Интернет

How to Discover High-Paying IDOR Bugs in Real Apps?

How to Discover High-Paying IDOR Bugs in Real Apps?

Как хакеры взламывают Google 2FA

Как хакеры взламывают Google 2FA

Finding Your First Bug: Getting Started on a Target (Part 1)

Finding Your First Bug: Getting Started on a Target (Part 1)

Insecure Direct Object Reference  / IDOR Explained  // How to Bug Bounty

Insecure Direct Object Reference / IDOR Explained // How to Bug Bounty

Broken Access Control Explained: How to Discover It in 2025?

Broken Access Control Explained: How to Discover It in 2025?

How to Stop Learning and Start Hacking!

How to Stop Learning and Start Hacking!

Нахождение первой ошибки: поиск ошибок с помощью API

Нахождение первой ошибки: поиск ошибок с помощью API

Critical IDOR Leading to Full Account Takeover | $2,500 Bug Bounty PoC on SuryaElectronics.in

Critical IDOR Leading to Full Account Takeover | $2,500 Bug Bounty PoC on SuryaElectronics.in

"How to Get Started with Bug Bounty" - Resource Lists & Advice

Как я нашел своего первого жука (теперь и вы сможете)

Как я нашел своего первого жука (теперь и вы сможете)

[Part I] Bug Bounty Hunting for IDORs and Access Control Violations

[Part I] Bug Bounty Hunting for IDORs and Access Control Violations

Задайте себе эти четыре вопроса, когда будете искать IDOR-ы в рамках программы Bug Bounty

Задайте себе эти четыре вопроса, когда будете искать IDOR-ы в рамках программы Bug Bounty

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]