2023 WebApp Pentesting/Hacking Roadmap // How To Bug Bounty

2024 ж. 25 Мам.
59 598 Рет қаралды

Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training
Does Cybersecurity Require Programming?
• Does Cybersecurity Req...
Buy Me Coffee:
www.buymeacoffee.com/nahamsec
Live Every Sunday on Twitch:
/ nahamsec
Free $100 DigitalOcean Credit:
m.do.co/c/3236319b9d0b
Follow me on social media:
/ nahamsec
/ nahamsec
twitch.com/nahamsec
hackerone.com/nahamsec
/ nahamsec1
Github:
github.com/nahamsec
Nahamsec's Discord:
discordapp.com/invite/ucCz7uh
Timestamps:
00:00 - Intro
00:45 - How the website works
01:56 - Curl / Linux basics
03:10 - Scripting
04:34 - Basics of Web application Hacking, Don't depend on Automation
07:49 - Learn JavaScript
#webhacking #redteam #bugbounty #offensivesecurity #hackerone #hackers #hacking #infosec #hackingtutorial #owasp #educational

Пікірлер
  • 00:00 = Intro 00:45 = How the website works 01:56 = Curl / Linux basics 03:10 = Scripting 04:34 = Basics of Web application Hacking, Don't depend on Automation 07:49 = Learn JavaScript For me personally this was not a roadmap, it was more like tips and tricks to upgrade my existing roadmap 😂😂, anyways, thank you very much Naham sir, following you further to learn a lot of stuff 🙏🙏💖💖 Love from India 🇮🇳 🇮🇳 🇮🇳

    @rdx8122@rdx8122 Жыл бұрын
    • Bro can you tell about where to practice web hacking

      @oviyanthelearner7656@oviyanthelearner7656 Жыл бұрын
    • @@oviyanthelearner7656 port swigger academy

      @nishantdalvi9470@nishantdalvi9470 Жыл бұрын
    • Added to the video. You the best!

      @NahamSec@NahamSec Жыл бұрын
    • @@oviyanthelearner7656 there are a lot them out there, explore them online, like tryhackme, hackthebox, especially portswigger and lot more !

      @rdx8122@rdx8122 Жыл бұрын
    • @@NahamSec thank you sir 🙏🙏❤️❤️

      @rdx8122@rdx8122 Жыл бұрын
  • Fuck. I just realized something while watching this. I’ve been into this for 2.5 years. Maybe 3. And I’m still finding myself watching these roadmap - how to become a bug bounty Hunter - videos. Damn. What can I do. Seriously.

    @superkool7@superkool78 ай бұрын
    • Disconnect for a while. Do something else. Then come back with a fresh mind

      @akhtarmohana2999@akhtarmohana29998 ай бұрын
  • Hi Ben, I am your huge fan i love your work immensely and your vlogs about live hacking events are as good as your other KZhead content . My question is that I’m currently in Canada and my studies will be over in next month like in Aug 2023 but I am lost in my path I don’t know what to do I am unable to find an internship or job so I needed your guidance and i also want to mention that I have successfully done your udemy course and i am currently preparing for PNPT by TCM security so If i could connect with you and talk about job search and other things then it would be really awesome.

    @romeoromeo7002@romeoromeo700210 ай бұрын
  • I've just started learning curl. Still trying to wrap my head around it. Baby steps 😊

    @chaospixxie@chaospixxie Жыл бұрын
    • You got this! curl is going to be very helpful especially when looking at APIs!

      @NahamSec@NahamSec Жыл бұрын
    • how's the learning my man?

      @firzainsanudzaky3763@firzainsanudzaky37634 ай бұрын
  • Great video as always mentor !

    @arijitdas9115@arijitdas9115 Жыл бұрын
  • You are legend sir , Always Appreciated.

    @shaifsec@shaifsec Жыл бұрын
  • Great as always🎉

    @rahmat_qurishi@rahmat_qurishi Жыл бұрын
    • Thank you so much 😀

      @NahamSec@NahamSec Жыл бұрын
  • came here from the live stream. and dropped a sub

    @bolivianPsyOp@bolivianPsyOp Жыл бұрын
  • How important do you think learning Python to an intermediate level is for a bug hunter? Awesome video!

    @axelieve@axelieve Жыл бұрын
  • Hey man, thanks for your content. Since you mentioned SSRF being network related, I come from a networking and netsec background with 10+ years experience. What hacking track do you recommend me to go where I can take of use my knowledge in networking?

    @denizyildirim116@denizyildirim11610 ай бұрын
  • like a Boss; Great Content Nahamsec ...

    @bugs-lk3jf@bugs-lk3jf10 ай бұрын
  • Thank you for this video, very good info

    @g1zmo85@g1zmo85 Жыл бұрын
  • Thanks! For the ADVICE!

    @night0x1@night0x1 Жыл бұрын
  • Thanks for the guidance!!

    @nadakuditigopikrishna6587@nadakuditigopikrishna658710 ай бұрын
  • Thanks for video ! Keep making more.

    @RivuDonTech@RivuDonTech Жыл бұрын
    • Thank you, I will

      @NahamSec@NahamSec Жыл бұрын
  • Knowledgeable Content

    @PS_Fantasy@PS_Fantasy Жыл бұрын
  • Just found your channel. You seem like a kool dude. Buying your BB Course for my barely 12 year old who lives on hack the box and is always on port swigger site. Hes actually trying to get me into it, but i think i like more actual network pentesting then web apps. That looks way too difficult for me.

    @Eric-ey7rm@Eric-ey7rm Жыл бұрын
    • Hey Eric. Thanks for the comment and thanks for supporting the course! That’s awesome that your son! If I can help him in anyway please let me know. Happy to even chat with the both of you on a zoom call if it helps motivate you guys to get into hacking. Feel free to email me! My emails on the about page of the channel. Go after whatever you’re passionate about. Whether it’s network, web, social engineering regardless of the difficulty. IMO that’ll drive you overcome the hurdles more than anything else. Best of luck!

      @NahamSec@NahamSec Жыл бұрын
  • Thanks for video .liked it

    @1DRS@1DRS Жыл бұрын
  • Please 🙏 keep it up more and more videos....

    @krishg767@krishg767 Жыл бұрын
  • Hey hey, nice video, thanks!

    @Andrei-ds8qv@Andrei-ds8qv Жыл бұрын
  • Actually I needed it. Thank you so much for making this video... ♥✌

    @nextbillionaire2513@nextbillionaire2513 Жыл бұрын
    • Welcome!!

      @NahamSec@NahamSec Жыл бұрын
  • thanks, greetings from turkey

    @lzxser6470@lzxser6470 Жыл бұрын
  • Thanks man ;-)

    @MFoster392@MFoster392 Жыл бұрын
  • And ctf to start with after learning these basics

    @mohammadalihanfi8237@mohammadalihanfi8237 Жыл бұрын
  • Came here from your live

    @m3nt0rz.haxx0r2@m3nt0rz.haxx0r2 Жыл бұрын
  • Hi, I came from your stream

    @user-vf8nm7xy1e@user-vf8nm7xy1e Жыл бұрын
  • So how in depth should you know about how websites work? Also do you have any prefered resources for learning these skills?

    @joeshmo546@joeshmo5465 ай бұрын
  • Any sources to learn this stuff from? Curl, JS for hacking, basics etc...

    @krishshah344@krishshah344 Жыл бұрын
  • For the first step Learning how the websites and internet works, what book should I choose to learn that how internet and websites works or do you have any resources plz tell me

    @kenkaneshki432@kenkaneshki43211 ай бұрын
  • thank you so much 😎

    @bugs-lk3jf@bugs-lk3jf10 ай бұрын
  • Very knowledgeable video ❤

    @uniskhan3815@uniskhan3815 Жыл бұрын
    • Thanks a lot 😊

      @NahamSec@NahamSec Жыл бұрын
    • @@NahamSec your welcome sir❤

      @uniskhan3815@uniskhan3815 Жыл бұрын
  • Love from Ethiopia❤

    @mametube6654@mametube6654 Жыл бұрын
    • @NahamSec@NahamSec Жыл бұрын
  • Thanks keep making more videos for beginners :)

    @amoh96@amoh96 Жыл бұрын
    • More to come!

      @NahamSec@NahamSec Жыл бұрын
  • as beginner it's really hard to me the part of recon ( DNS , ASN,DNS Records, Revers Ip,,,,,) This stuff about Network i only do basic recon gather subdomains & some google dorks :( is that ok for beginner im in 6 month in bug bounty ??

    @amoh96@amoh9610 ай бұрын
  • Do i need to study the a plus content or something like that to get into bug hunting

    @youssef-kz3yn@youssef-kz3yn11 ай бұрын
  • good content.

    @TonyAsh-rp6fp@TonyAsh-rp6fp Жыл бұрын
  • I suggest you use more visualization in your video, such as the terms, definitions.

    @Meenimie@Meenimie Жыл бұрын
  • Its a nice watch .... Which watch it is ? :)

    @DheerajMadhukar@DheerajMadhukar Жыл бұрын
  • After this what are books you recommend to read

    @mohammadalihanfi8237@mohammadalihanfi8237 Жыл бұрын
  • Great Video. I am looking for a good video on curl.

    @markfuentes3666@markfuentes3666 Жыл бұрын
    • Maybe I'll do it in my next project :)

      @NahamSec@NahamSec Жыл бұрын
    • easy: man curl

      @HelloThere-xs8ss@HelloThere-xs8ss Жыл бұрын
  • came from the livestream

    @HalfDeaff@HalfDeaff Жыл бұрын
  • awli bood❤❤

    @stabilizer7225@stabilizer7225 Жыл бұрын
  • Can u please make a video on hoelw to effectively map the web app and discover hidden functionalities

    @mereemail8352@mereemail8352 Жыл бұрын
    • Maybe :-)

      @NahamSec@NahamSec Жыл бұрын
  • How to find bugs from view-source? I want a video of this 😊

    @glostar_Rx@glostar_Rx Жыл бұрын
    • You mean finding bugs in JavaScript ? that's a great topic a video @NahamSec

      @rdx8122@rdx8122 Жыл бұрын
  • need resource to know more about DNS Configuration | DNS Records

    @shaifsec@shaifsec Жыл бұрын
  • ur the best dude

    @GoliTech@GoliTech Жыл бұрын
  • Thanks for the video. I purchase your course on udemy and I'm loving it. I have one request to ask, could you connect me to someone I can pair with and we can learn together? Thanks again

    @terrymac-tay5597@terrymac-tay5597 Жыл бұрын
    • Come join the discord!

      @NahamSec@NahamSec Жыл бұрын
  • Again I am first viewer 🥳

    @rahulacharya8159@rahulacharya8159 Жыл бұрын
    • nah i won this time 😆

      @shubham_srt@shubham_srt Жыл бұрын
    • you both win!

      @NahamSec@NahamSec Жыл бұрын
  • what are the different fields in ethical hacking

    @vedant.p.baghel8944@vedant.p.baghel8944 Жыл бұрын
  • best content

    @mehdi_sf7257@mehdi_sf7257 Жыл бұрын
  • Came here from LIVE

    @vineet1@vineet1 Жыл бұрын
  • Thanks

    @alagunoff@alagunoff Жыл бұрын
  • How much demand of Ethical Hackers is ?

    @codesaif8075@codesaif8075 Жыл бұрын
  • from the stream

    @iramdolal488@iramdolal488 Жыл бұрын
  • Please give the link to the video you said at the beginning.

    @MP-eq8fx@MP-eq8fx Жыл бұрын
    • In the description but here you go Does Cybersecurity Require Programming? kzhead.info/sun/irWamaekg5ashoE/bejne.html

      @NahamSec@NahamSec Жыл бұрын
    • @@NahamSec Thank you very much 💗

      @MP-eq8fx@MP-eq8fx Жыл бұрын
  • finelly :D

    @amoh96@amoh96 Жыл бұрын
  • ❤️

    @mereemail8352@mereemail8352 Жыл бұрын
  • i reported the vulnerabilities but they are all invalid

    @mikiminac251@mikiminac251 Жыл бұрын
  • Came here from the future

    @unexplicitist-oy3eh@unexplicitist-oy3eh6 ай бұрын
  • For scripting we should learn Python or Go?Which better? and how learn Scripting?

    @moh5entuky940@moh5entuky94011 ай бұрын
    • With Udemy…

      @a.g.4843@a.g.48434 ай бұрын
    • Witch course? @@a.g.4843

      @moh5entuky940@moh5entuky9404 ай бұрын
  • 🐝

    @securibee6016@securibee6016 Жыл бұрын
  • Why is everyone focusing on web bug bounty? Why not mobile and other platforms?

    @zerocool2765@zerocool2765 Жыл бұрын
    • money and because it's the first line of defense

      @epicotakugamer4930@epicotakugamer493010 ай бұрын
  • tnx but better if it was tear by tear and more step

    @Zillah_D@Zillah_D7 ай бұрын
  • احبك في الله 😅

    @voyageur1016@voyageur1016 Жыл бұрын
    • hhhhhhh

      @amoh96@amoh96 Жыл бұрын
  • Hello sir 👋 can you please make a Facebook cloning script for me ❤

    @satisfiedvideos1@satisfiedvideos111 ай бұрын
  • I want to know API hacking tips and tricks from you. 🙏🙏🙏🙏🙏

    @0XmsAhmed@0XmsAhmed Жыл бұрын
    • Soon!

      @NahamSec@NahamSec Жыл бұрын
    • @@NahamSec waiting dude

      @Adarsh.-.@Adarsh.-. Жыл бұрын
    • ​@@Adarsh.-.check out apisec University

      @lukeempty3386@lukeempty3386 Жыл бұрын
    • Need the API hacking too 🎉

      @tecksec@tecksec Жыл бұрын
    • @@tecksec TCM security just released an API course

      @lukeempty3386@lukeempty3386 Жыл бұрын
  • Hi i am from india. I want a great high paying career. On which skills i need to focus and get remote job while i stay in india. I am from non IT back ground. Thank you.

    @syedrafi3704@syedrafi3704 Жыл бұрын
  • Can you please make a video on writing PoC of Bugs

    @nareshrapthadu8262@nareshrapthadu8262 Жыл бұрын
  • 1st 🥵

    @shubham_srt@shubham_srt Жыл бұрын
  • Will penetration tester jobs be replaced by artificial intelligence?

    @cynerboy@cynerboy Жыл бұрын
    • Machine learning tools are already being used in security operation centers.

      @HelloThere-xs8ss@HelloThere-xs8ss Жыл бұрын
  • Api hacking roadmap guru ji

    @ByteHax_@ByteHax_ Жыл бұрын
  • Finally 😂😂

    @ralphandre4438@ralphandre4438 Жыл бұрын
  • still bug bounty is not a robust career!!! spending time on vuln machines and web apps is more important to know more about bugs. Bug hunting should be a part time and a just for fun game. No offense , but it is a matter of duplicates and reality.

    @harshsharma7505@harshsharma7505 Жыл бұрын
  • Where are the basics of networking ? 🙂

    @Sharif365@Sharif365 Жыл бұрын
  • Definitely not a roadmap lol but thanks for the tips.

    @uaebikers@uaebikers Жыл бұрын
    • Thanks! What should I do different next time so it's an actual roadmap? Should I specify where to learn them and what courses/sites to use?

      @NahamSec@NahamSec Жыл бұрын
    • Lmfao this guy wants latitude and longitude 🗺️🗾📍😂😂😂

      @cguzmanvisuals@cguzmanvisuals Жыл бұрын
    • @@NahamSec I recommend making a roadmap for a period of time like 6 months with detailed plan, goals and milestones. Maybe even make a playlist discussion each step of the roadmap.

      @uaebikers@uaebikers Жыл бұрын
    • Buddy wants spoon feeding.....

      @king09426@king09426 Жыл бұрын
    • @@king09426 I want things to be called as they are without click baiting! Go simp somewhere else!

      @uaebikers@uaebikers Жыл бұрын
  • Bir de Müslüman olsan süper olurdu naham dayı

    @vedaty.8259@vedaty.8259 Жыл бұрын
  • ایرانی هستی

    @user-oc6ge1lj9n@user-oc6ge1lj9n5 ай бұрын
  • For scripting we should learn Python or Go?Which better? and how learn Scripting? Thank You for your helps@NahamSec

    @moh5entuky940@moh5entuky94011 ай бұрын
  • thx for video

    @WasiLi0x1e@WasiLi0x1e Жыл бұрын
  • nahamsec . I am working as security in UAE. but I am from India. I fed up with my job because it is very boring. now I started learning about cybersecurity. can I change my job to bug bounty. I want a job that i can work from home. security job is not very interesting . cybersecurity seems to me very interesting

    @denildavis3561@denildavis3561 Жыл бұрын
  • Regexes

    @brs2379@brs2379 Жыл бұрын
  • i think review owasp better thing for start learn hunting

    @behrozarshiya@behrozarshiya7 ай бұрын
KZhead