#558: Top 4 Web hacking demos for aspiring hackers (with labs and CTF)
David Bombal16 Maalis

#558: Top 4 Web hacking demos for aspiring hackers (with labs and CTF)

Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Are you looking to get into bug bounty hunting but feel overwhelmed or worried the field is oversaturated? In this video, full-time bug bounty hunter Justin Gardner shares a realistic, actionable guide to web hacking for beginners. We dive straight into the practical side with five live demonstrations of common web vulnerabilities—all done using just your browser and DevTools. Justin explains how Insecure Direct Object Reference (IDOR), Broken Access Controls, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF) work in the real world, including stories of finding these exact bugs on major platforms like Google. After the demos, we tackle the biggest questions new hackers have: Is there still money to be made in 2026? How has AI changed the landscape? And what is the exact roadmap to landing your first bounty? Justin breaks down his "200-hour rule" for learning, why you need to get comfortable with failing, and the best resources (like HackerOne and PortSwigger) to help you launch your cybersecurity career today. // Labs and more here: // Labs: https://ztw.ctbb.show/ More labs: https://labs.cai.do/ And more labs: https://portswigger.net/web-security // Justin Gardner’s SOCIAL // YouTube: / @criticalthinkingpodcast LinkedIn: / rhynorater X: https://x.com/Rhynorater GitHub: https://rhynorater.github.io/aboutme/ / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:40 - Introduction 01:50 - Getting Started in Bug Bounty 03:11 - Can I Make Money in Bug Bounty? 04:11 - Demo 1 06:55 - Demo 2 08:47 - Lessons for Upcoming Hackers 10:09 - Demo 3 13:49 - Are There Demos on Justin’s Podcast? 14:20 - Demo 4 18:11 - Real-Life Date of Birth Vulnerability 19:13 - Advice on Becoming a Hacker Like Justin 20:20 - What & Where to Study to Become a Bug Bounty Hacker 21:49 - How Long Does It Take? 25:07 - Outro & Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #webhacking #bugbounty #hack

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(500)

#592: Why most enterprise AI fails (and how to succeed)

#592: Why most enterprise AI fails (and how to succeed)

Agentic AI is putting a 400x load on enterprise networks. Cisco and NTT Data experts reveal why only 13% of leaders successfully scale AI, the nightmare of quantum threats, and how to secure your infr...

15 Heinä 37min

#591:  Inside the Cisco Live 2026 NOC (exclusive tour)

#591: Inside the Cisco Live 2026 NOC (exclusive tour)

Big thanks to Cisco for sponsoring my trip to Cisco Live EMEA and for changing my life and the lives of many other people. // Joe Clarke SOCIAL // LinkedIn: / joeclarke2 // YouTube video REFER...

15 Heinä 26min

#590: CCNA 2.0: What did Cisco just remove from the exam?

#590: CCNA 2.0: What did Cisco just remove from the exam?

Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Vegas. Cisco has officially announced a major update to the CCNA, moving from version 1.1 to the new CCNA 2.0 bluepr...

2 Heinä 44min

#589: How to run an AI agent INSIDE your network CLI for 2026

#589: How to run an AI agent INSIDE your network CLI for 2026

Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Vegas 2026. Network engineers, are you ready for 2026? Learn how to deploy an AI agent directly into your CLI using...

30 Kesä 31min

#588: Which is Ethernet? What's the difference?

#588: Which is Ethernet? What's the difference?

Big thank you to DeleteMe for sponsoring this video. Use my link https://joindeleteme.com/Bombal to receive a 20% discount or use the QR Code in the video. Also, a Big thanks to Cisco for sponsoring...

30 Kesä 22min

#587: Agentic AI is attacking your network (how to defend it)

#587: Agentic AI is attacking your network (how to defend it)

Are your legacy network devices a ticking time bomb? In this deep dive, Cisco’s Head of Customer Experience reveals alarming statistics from the latest Talos report: 40% of top vulnerabilities directl...

24 Kesä 16min

#586: Stop zero days without a patch: You need to learn eBPF

#586: Stop zero days without a patch: You need to learn eBPF

How has AI changed cybersecurity and enterprise networks? In this interview, Michael (General Manager for Cisco's Campus Networking) joins David Bombal to discuss the real-world impact of agentic AI, ...

24 Kesä 21min

#585: Run Full WiFi Networks in your laptop 🤯

#585: Run Full WiFi Networks in your laptop 🤯

In this episode, David Bombal sits down with Joe and Dalton from Cisco to break down the biggest Cisco Modeling Labs (CML) 2.10 release yet. Joe demos the new open source MCP server (model context pro...

24 Kesä 19min