Autoplay
Autocomplete
Previous Lesson
Complete and Continue
Ethical Hacking / Penetration Testing & Bug Bounty Hunting v2
Training Overview
Description of Training
Video Overview (3:28)
Section 1: Introduction
Disclaimer (1:02)
Section 2: Future Updates
Future Updates (1:32)
Section 3: Setting up Environment
Burp Suite Proxy Lab Setup (17:11)
Section 4: Subdomain Takeovers
What are Subdomains (3:52)
Subdomain Enum (5:12)
What is DNS (9:26)
Fastest Resolver (7:38)
What are DNS Records (7:56)
Sublister (6:00)
Findomain (3:02)
Subfinder (6:27)
Recursive Subdomain Enumeration (3:08)
Can I take over XYZ (6:54)
Can I take over ALL XYZ (6:37)
AWS Subdomain Takeover Live -1 (14:36)
AWS Subdomain Takeover Live -2 (7:14)
AWS Bugcrowd Report Breakdown (6:11)
Tumblr Subdomain Takeover (8:22)
Shopify Subdomain Takeover (11:55)
Cargo Subdomain Takeover (4:38)
Subzy Tool Automation for Subdomain Takeovers (5:47)
Subjack - Tool for Subdomain Takeovers (5:10)
Section 5: HTML Injection
What is HTML (5:41)
Understanding HTML (3:15)
HTML (3:59)
HTML Injection - Lab (5:06)
HTML Injection Live-1 (4:02)
Section 6: Click Jacking
Click Jacking Live-1 (3:31)
Click Jacking Live-2 (2:56)
Click Jacking Live-3 (3:35)
Click Jacking Live-4 (3:57)
Clickjacking Exploitation (7:40)
Clickjacking Live Target Exploitation (7:29)
Clickjacking Automation Live Target Exploitation (3:27)
Clickjacking - ClickBandit with Burpsuite (5:55)
Section 7: File Inclusion Exploitation
What is LFI (4:15)
LFI Exploitation on Lab (9:10)
LFI Exploitation Live -1 (4:49)
LFI Exploitation Live -2 (4:43)
LFI Exploitation LFi to RCE (11:52)
LFI vs RFI (3:26)
Section 8: Broken Link Hijacking
Introduction & Background Concept (5:39)
BLH Exploitation Practical (5:36)
BLH Exploitation Tool (6:17)
BLH Instagram Report Breakdown (2:01)
BLH Exploitation Practical Live (2:24)
BLH Hackerone Report Breakdown (3:00)
BLH Practical Tool Resource (3:30)
BLH Exploitation Practical Extension Tool (3:42)
BLH Command Injection (5:01)
BLH Exploitation Github Repo - Live (7:16)
SQL Injection
SQL Injection Background Concept (2:21)
SQL vs Spreadsheets (1:46)
SQL Database Importance (1:44)
XAMPP Installation & Setup (5:25)
SQL Practical Hands on - First Table (5:25)
SQL Practical Hands on - Queries (2:16)
SQL Practical Hands on - Second Table (5:47)
SQL Practical Hands on - Exercise (2:24)
Truth Table (1:51)
Truth Table Practical (6:11)
SQL Understanding the Logic (2:54)
SQL Query Breakdown (3:45)
SQL Injection Impact & Approach (5:43)
SQLi on Lab-1 (3:57)
SQL Query Breakdown payload-2 (3:49)
SQLi on Lab-2 (5:45)
Burp suite Web Academy (2:24)
SQLi Labs Data Retrieval Lab (4:37)
SQLi Labs Data Retrieval Live (2:01)
SQLi Login Bypass Lab (2:14)
SQLi Login Bypass Live 1 (2:57)
SQLMap Installation & Setup (3:14)
SQLMap Exploitation - Live 2 (11:58)
SQLMap Exploitation - Live 3 (9:40)
Shell Exploitation Techniques (2:26)
SQL : Shell Exploitation - Live 4 (5:16)
SSRF
SSRF Introduction & Principle (6:41)
SSRF Practical (10:06)
SSRF Bincatcher Listener (5:13)
SSRF against Server Itself (11:07)
SSRF against another Backend Server (10:08)
SSRF Bypass Protection Blacklist Filter (11:03)
SSRF Bypass Protection Whitelist Filter (8:07)
SSRF Chaining with Open Redirect and Bypass Filter (6:20)
SSRF Exploitation using MPEG - Live (6:58)
SSRF Exploitation JIRA chaining with XSS - Live (2:01)
SSRF Exploitation JIRA chaining with XSS - Live (4:01)
SSRF Exploitation JIRA Automation with Python (5:26)
SSRF Facebook Breakdown (14:42)
SSRF Microstrategy Live -1 (6:29)
SSRF PHP Filter Live (8:04)
SSRF PHP Filter Wordpress Config Live (5:38)
Remote Code Execution
Apache Unomi RCE Live (9:08)
How to start with Bug Bounty Platforms and Reporting
BugCrowd ROADMAP (17:41)
Hackerone ROADMAP (8:57)
Open Bug Bounty ROADMAP (8:00)
Synack ROADMAP (5:41)
Intigriti ROADMAP (10:43)
NCIIPC Govt of India ROADMAP (8:27)
RVDP All Websites ROADMAP (6:25)
Section 13: Bug Bounty / Penetration Testing Reporting Templates
Reporting Templates - We have your back!
Section 14: Snapshot
Snapshot of Subdomain Enumeration
Snapshot of Broken link Hijacking
Section 15: PortSwigger Labs
Solving Portswigger Lab SQL Injection -1
Section 16: Learning LFIscan
LFIscan
Section 17: Mastering Subdomain Enumeration in Penetration Testing
Basics and Common Mistakes to Avoid while doing Subdomain Enumeration
Subdomain Enumeration Strategies
Learning DOME - A subdomain enumeration tool
Section 18: Automating SQL Injection using Ghauri
Learning Ghauri
Hackerone ROADMAP
Lesson content locked
If you're already enrolled,
you'll need to login
.
Enroll in Course to Unlock