
Start Hacking at Hacker One - Learn Bug Hunting & Get Paid Legally
Keywords
Summary
182 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides practical, hands-on demonstrations of five specific vulnerability types, which is valuable for beginners seeking actionable techniques. The presenter’s argumentation is based on his claimed experience as a top HackerOne hacker, but he does not provide verifiable evidence or references to support his claims. The strategic advice on focusing on medium/high impact bugs and avoiding duplicates is sound, but the reasoning is not deeply elaborated. The demos are clear and step-by-step, making the content accessible, but the explanations of the vulnerabilities’ root causes are superficial. The video does not discuss mitigation strategies or broader security concepts, limiting its educational value beyond the specific bugs shown.
Scientific Rigor, Source Quality, Title Accuracy
The video does not cite any external sources or references. The presenter mentions HackerOne’s statistics (e.g., $20 million earned by 2017, expected $100 million by 2020) but does not provide sources. The title accurately reflects the content, which is a beginner’s tutorial on bug hunting. The video includes a disclaimer about ethical hacking, but the lack of citations and reliance on anecdotal evidence reduces its scientific rigor. The presenter’s credentials are not verified, and no peer-reviewed or authoritative sources are referenced.
203 words
Title / Content Match
The title accurately reflects the content: a beginner's guide to bug hunting on HackerOne, covering five specific bugs with demos.
Quality & Reliability
6/10
The video provides practical demonstrations of five specific vulnerability types, but lacks rigorous scientific sourcing and relies on anecdotal evidence. The presenter claims to be a top hacker on HackerOne, but no verifiable credentials are provided. The content is educational but not peer-reviewed.
Chapters
- Introduction
- HackerOne: Your Big Opportunity
- Getting Started with 5 Bugs
- Automatic Leakage of Password Reset Link – Overview
- Automatic Leakage of Password Reset Link – Demo
- How to Get Access to the Account of the Logged Out User – Overview
- How to Get Access to the Account of the Logged Out User – Demo
- Insecure Processing of Credit Card Data – Overview
- Insecure Processing of Credit Card Data – Demo
- Disclosure of Authentication Cookie – Overview
- Disclosure of Authentication Cookie – Demo
- User Enumeration: Overview
- User Enumeration: Demo
- Summary & Next Steps
Contribution & Novelties
The video offers a practical, demo-driven introduction to five specific bug bounty vulnerabilities, which is useful for beginners. The demos show how to use browser developer tools to identify these issues, providing a hands-on approach. However, the content is not novel; similar tutorials are widely available. The presenter’s claimed experience adds a personal touch but is not substantiated.
Pour aller plus loin :
- OWASP Top Ten — Relevant for understanding common web vulnerabilities, including those discussed.
- HackerOne’s official website — The platform itself, where viewers can practice and find programs.
- PortSwigger Web Security Academy — Offers free labs and tutorials on web vulnerabilities, including those covered in the video.
109 words
Radar Profile
The radar profile shows moderate scores across all dimensions, with quantity of information slightly higher than quality and reliability. This indicates a tutorial that provides a decent amount of practical content but lacks depth and authoritative sourcing.