Finding Your First Bug: Cross-Site Request Forgery (CSRF)

preview_player
Показать описание
In this video we're looking at Cross-Site Request Forgery, definitely on the more technical end of beginner bugs. This bug is all about abusing how web browsers keep people logged in to trick users into doing actions to their account. It sounds really complex but actually finding them is quite simple, all you need to do is find a single endpoint with a missing token, and bam, way in! This marks the penultimate episode in the Finding Your First Bug series. Fear not, when one door closes another opens, starting soon will be Finding Your Next Bug, all about building on what you've already learned in this series and taking your bug hunting to the next level.

Welcome to this video in the "Finding Your First Bug" in this series I'm going to go over some good first bugs: explain what they are, how to find them, show some examples of real bugs in the wild that paid out and finally do a practical example with Burp on a real target.

-- Case Studies --
Комментарии
Автор

Awesome content! They'll definitely have to renew my work contract when I hit em with this new knowledge 😈

cloudkungfu
Автор

Thank you very much sister! When I am seeing this video, got an approach to find the CSRF bug. The thing that I like in this video is - example reports that you shared. They helps a lot in understanding the bug and approach. Thanks again and Happy New Year🎁🎈🎊🎉😀

nadakuditigopikrishna
Автор

Anyway you can make you microphone a bit louder? I’m having trouble hearing sometimes. Your videos are awesome keep doing what your doing and your subscribers will sky rocket! Also, some more content discovery/enumeration videos would be awesome! Thank you for your hard work.

InfoSecIntel
Автор

Great Series Kate Learned a lot you So much love from community <3

onkarkoli
Автор

These are always Awesome-Sauce! Thank you!

Shogunxd-vpjv
Автор

thenk you so much for this and the whole series too :)))

pacman
Автор

I’m feeling a PTSD-like consequences of this channel (apologies for dark humor, I know it’s a serious illness but I needed this reference to make my point of how good all your vids are). Just found it and binge watched it fully (even saved this series on my gdrive and usb. Full access all the time). I’m not saying we need more girls in IT but damn I am saying now we definitely need much more girls in IT. I’m a wannabe bug bounty hunter but there’s much more bug bunny 🐰 than bounty in my hunting.
How come you’re not filthy rich by just making this amazing content.
I’ve watched so many bounty hunters’ vids I feel like I personally know most of them... all the courses the wide interweb (sic) has to offer... yet for the first time really understood the basics of this entire industry although I am trying hard (not so often though ... gotta do the stupid “work” stuff every weekday unfortunately;) on all the hackerone challenges and bounties (and much more definitely).
I do have a question though. If you could recommend one ☝️ course or (even better) certification to someone (besides your channel) what would it be? For working class, not students...
(Sorry for the rant but you caught me off guard with the quality and clarity of your videos)

docmalitt
Автор

I have a question ... I already have the knowledge on IDOR, CSRF vulnerabilities but I need to practice .. like chess ... I am happy there are softwares I can practice on relating to chess ... because I can test out ..reaarange..apply...try out anything I have learnt ... so saying that ..

are there any websites or softwares I can buy that has like 100's of IDOR vulnerabilities that I can use Burp on and practice all night?? Thanks.

brian_mckenzie
Автор

Great video as usual, I'm excited for the last one. Do you plan on making more content after this series is finished?

jacobpetrov
Автор

Holy shit just found your stuff. Amazing content!

adamschaefer
Автор

Ma'am i have a query regarding the privilege escalations ?

sharma
Автор

Madam thank you so much for this educational content, I really find it so motivational that a lady is explaining concepts in a practical and informative way. I am not sure what is happening to your DM but im still hoping you come back to discord. Thank you :)

johnphiri
Автор

great content. thank you so much. volume is very less though; pl look into it. thanks again.

kusharora
Автор

ma'am can you please make one video for XSSI and JSONP. one hacker found bug on paypal (User password leak) using XSSI. please include this vuln in your next series. :)

rockybhai-cnqw
Автор

Ma'am please start your discord channel .

ignitor
Автор

Your voice is very cute but....its very low...please increase the volume

tradingwithsomeonebetter
Автор

i CAN'T HEAR UR VOICEE, please increase the VOLUME VOICE IN NEXT VIDEO

adtiyamuhammadakbar
Автор

Too quiet, turn up your mic or something

mtop