Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

Hunting for IDORs with Katie Paxton-Fear

Автор: OWASP DevSlop

Загружено: 2021-05-02

Просмотров: 14226

Описание:

▬▬▬▬▬▬ TIMESTAMPS ⏰ ▬▬▬▬▬▬
00:03:24 Katie's presentation starts

▬▬▬▬▬▬ Abstract & Bio 📝 ▬▬▬▬▬▬
Anyone who's watched Katie before knows that IDORs (Insecure Direct Object References) are some of her favourite bugs. Often caused by a single missing if statements, these lil bugs can have devastating impacts, and even worse they are everywhere!

In this talk, she'll go through the what, where, how, and fixes of these tricky bugs. Giving you the ultimate IDOR / BOLA (Broken Object Level Authorisation) / BFLA (Broken Function Level Authorisation) methodology, how this can be automated and how it can't be automated, the fixes for some of these vulnerabilities and why even with all of this they're still some of the most common bugs to find, and why they're worth looking for.

OUR GUEST: Katie Paxton-Fear

Katie is an Application Security Engineer at Bugcrowd, a Lecturer and Manchester Metropolitan University and Ph.D. Student, but she's far more well known for her hobbies. On evenings and weekends, she hunts bugs!

A self-described occasional bug bounty hunter, she loves the thrill of hunting down real vulnerabilities in software, but her passion is education. Through her YouTube channel, she creates weekly videos on how to get into bug bounty hunting, web application security, tooling and goes in-depth on a range of bugs and targets.

Since starting as a mentee in 2019 at a HackerOne live event she's found 30+ bugs in real software, handed in her Ph.D. thesis, created 50+ videos on her YouTube channel and grown an audience of over 20,000 subscribers.

A former developer and data scientist, she finds her success is directly related to being able to see through a website into the code/infrastructure, and she loves any opportunity to turn developers into hackers.

▬▬▬▬▬▬ Useful Links from Katie Paxton-Fear 🛠 ▬▬▬▬▬▬
https://github.com/InsiderPhD/Generic...
https://hub.docker.com/r/busk3r/gener...
▬▬▬▬▬▬ Other Links 🛠 ▬▬▬▬▬▬
CyberChef: https://gchq.github.io/CyberChef/
▬▬▬▬▬▬ Hosts 🎙️ ▬▬▬▬▬▬
Nancy Gariché ►   / nancygariche  
▬▬▬▬▬▬ Hosts 🎙️ ▬▬▬▬▬▬
Nikki Becher ►   / thedeadrobots​  
Stefania Chaplin ►   / devstefops​  
▬▬▬▬▬▬ Connect with Us 👋 ▬▬▬▬▬▬
YOUTUBE ►    / owaspdevslop  
DEV ► https://dev.to/devslop​
INSTAGRAM ►   / ​  
TWITTER ►   / owasp_devslop​  
LINKEDIN ►   / owasp-devslop  

Hunting for IDORs with Katie Paxton-Fear

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

Finding bugs with Nuclei with PinkDraconian (Robbe Van Roey)

Finding bugs with Nuclei with PinkDraconian (Robbe Van Roey)

Still not found your first bug? Try IDORs

Still not found your first bug? Try IDORs

May Lightning Event Featuring Katie Paxton-Fear

May Lightning Event Featuring Katie Paxton-Fear

Mind blowing 🤯 $20 million USD bounties! (Zero to Hero Money Hacking Roadmap)

Mind blowing 🤯 $20 million USD bounties! (Zero to Hero Money Hacking Roadmap)

[Part I] Bug Bounty Hunting for IDORs and Access Control Violations

[Part I] Bug Bounty Hunting for IDORs and Access Control Violations

How I made 1k in a day with IDORs! (10 Tips!)

How I made 1k in a day with IDORs! (10 Tips!)

Workshop: Scaling your AppSec Program with Semgrep

Workshop: Scaling your AppSec Program with Semgrep

Software Security Education with the OWASP Secure Coding Dojo

Software Security Education with the OWASP Secure Coding Dojo

[Part III] Bug Bounty Hunting for IDORs & Access Controls

[Part III] Bug Bounty Hunting for IDORs & Access Controls

Сколько денег я заработал за первый год участия в программе «Bug Bounty»? Видеоблог о программе «...

Сколько денег я заработал за первый год участия в программе «Bug Bounty»? Видеоблог о программе «...

Let’s Write Security Unit Tests! with Eric Johnson

Let’s Write Security Unit Tests! with Eric Johnson

Why Your IDORs Get NA’d, Cookies Explained

Why Your IDORs Get NA’d, Cookies Explained

Как я нашел своего первого жука (теперь и вы сможете)

Как я нашел своего первого жука (теперь и вы сможете)

APISEC CON  Where the Wild APIs Are, Katie Paxton Fear

APISEC CON Where the Wild APIs Are, Katie Paxton Fear

3 реальных ошибки API, за которые я получил награду

3 реальных ошибки API, за которые я получил награду

Insecure Direct Object Reference  / IDOR Explained  // How to Bug Bounty

Insecure Direct Object Reference / IDOR Explained // How to Bug Bounty

Задайте себе эти четыре вопроса, когда будете искать IDOR-ы в рамках программы Bug Bounty

Задайте себе эти четыре вопроса, когда будете искать IDOR-ы в рамках программы Bug Bounty

Think Ahead: 4 Ways Copilot Changes Teamwork Forever

Think Ahead: 4 Ways Copilot Changes Teamwork Forever

Глава Neuralink: чип в мозге заменит вам телефон

Глава Neuralink: чип в мозге заменит вам телефон

Bug Bounty bootcamp // Get paid to hack websites like Uber, PayPal, TikTok and more

Bug Bounty bootcamp // Get paid to hack websites like Uber, PayPal, TikTok and more

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]