Complete Ethical Hacking Course 2025 - Top 90 Interesting Bugs - Ethical Hacking & Bug Bounty

Complete Ethical Hacking Course 2025 - Top 90 Interesting Bugs - Ethical Hacking & Bug Bounty

🎙 Arman Sedana 👥 13K 📅 September 15, 2025 ⏱ 141 min 👁 443 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

XSSprivilege escalationIDORreconAPI keysbroken access controlCSRFdirectory traversalS3 bucketgit config

Summary

This video is a tutorial on ethical hacking and bug bounty hunting, presented by Arman Sedana, co-founder of Nexus Security. It is part of a series covering ‘Top 100 Interesting Bugs’, with this installment focusing on bugs 1-17. The presenter emphasizes that he is not the original discoverer of these bugs but is breaking down the technical aspects for educational purposes. The video covers a range of vulnerabilities including stored XSS leading to privilege escalation, using recon to find exposed database credentials, broken access control (BAC) via API endpoint manipulation, HTML injection leading to PII disclosure, IDOR in ChatGPT’s remix feature, exposed AWS API keys in JS files, chaining self-XSS with CSRF for account takeover, path guessing to access dashboards, bypassing 403 with HTTP method changes, a logical flaw in discount application, plaintext site ID leading to third-party account takeover, and multiple vulnerabilities found in a single program. The presenter also mentions using tools like Axiom for automated recon. The video ends with a bug involving unprotected S3 directories and a git config exposure. The content is presented in a conversational style with practical examples, but lacks in-depth technical explanations and verifiable sources.

193 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides practical insights into bug bounty hunting, emphasizing the importance of recon, chaining vulnerabilities, and thinking creatively. The presenter shares real-world examples that illustrate common vulnerabilities and exploitation techniques. However, the argumentation is largely anecdotal and lacks rigorous technical depth. The presenter does not provide detailed payloads, request/response examples, or remediation advice, which limits the educational value for advanced practitioners. The value lies in the breadth of vulnerability types covered and the mindset encouraged, but the lack of verifiable details and sources weakens the overall argumentation.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is low: the presenter explicitly states he does not own the reports and they may not be true, and he does not provide any links to the original bug reports or technical write-ups. The only sources cited are promotional links to his own website and social media, which are not scientific references. The title is misleading as it promises a complete course covering 90 bugs, but the video only covers about 17 bugs and is more of an overview. The content is not peer-reviewed and lacks citations, making it unreliable for academic or professional use. The presenter’s credentials are not verified, and the video appears to be a promotional tool for his training platform.

220 words

Title / Content Match

The title promises a comprehensive ethical hacking course covering 90 bugs, but the video only covers about 17 bugs and is more of an overview than a complete course.

Quality & Reliability

5/10

The video is a tutorial that presents a curated list of bug bounty findings, but it lacks verifiable sources, technical depth, and rigorous methodology. The presenter explicitly disclaims ownership and verification of the reports, and the content is largely anecdotal with minimal technical detail.

Key Moments

Cited Sources

  • AllGoodTutorials — Promotional website for the presenter's training platform.
  • AllGoodTutorials Newsletter — Newsletter signup page.
  • AllGoodTutorials Supporters — Support page for the platform.
  • AllGoodTutorials Pricing — Pricing page for premium access.
  • AllGoodTutorials Videos — Video courses page.
  • AllGoodTutorials Telegram — Telegram channel.
  • AllGoodTutorials LinkedIn — LinkedIn company page.

Concurring Sources

  • OWASP Top 10 — Lists common web vulnerabilities such as broken access control and injection, which align with the bugs discussed.
  • PortSwigger Web Security Academy — Provides labs and tutorials on vulnerabilities like XSS, CSRF, and access control, which are covered in the video.

Dissenting Sources

  • No specific discordant sources found — The video does not cite any sources that contradict its claims, but the lack of verifiable sources makes it difficult to assess concordance.

Contribution & Novelties

The video offers a curated list of real-world bug bounty findings, which can be valuable for beginners to understand common vulnerability classes and exploitation techniques. It emphasizes the importance of recon, chaining vulnerabilities, and thinking outside the box. However, the content is not original research and lacks technical depth. The presenter’s approach of breaking down bugs conceptually is useful for mindset development, but the lack of detailed technical explanations and verifiable sources limits its novelty.

Pour aller plus loin :

  • OWASP Top 10 — The standard awareness document for web application security, covering many of the vulnerability classes mentioned.
  • PortSwigger Web Security Academy — Free labs and tutorials on web vulnerabilities, including XSS, CSRF, and access control.
  • Bugcrowd University — Educational resources for bug bounty hunters.
  • HackerOne Hacktivity — Public disclosure of real bug bounty reports, useful for learning.
  • Nuclei — A tool for fast and customizable vulnerability scanning, mentioned in the video.

153 words

Radar Profile

The radar profile shows moderate scores across all dimensions, with slightly higher in quantity of information and technical level, but lower in reliability. This indicates a tutorial that provides a broad overview of vulnerabilities but lacks depth and verifiable sources, making it suitable for beginners but not for advanced practitioners seeking rigorous technical details.

Reliability 3/10

💬 No comments were provided for analysis.