
Complete Ethical Hacking Course 2025 - Top 90 Interesting Bugs - Ethical Hacking & Bug Bounty
Keywords
Summary
193 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides practical insights into bug bounty hunting, emphasizing the importance of recon, chaining vulnerabilities, and thinking creatively. The presenter shares real-world examples that illustrate common vulnerabilities and exploitation techniques. However, the argumentation is largely anecdotal and lacks rigorous technical depth. The presenter does not provide detailed payloads, request/response examples, or remediation advice, which limits the educational value for advanced practitioners. The value lies in the breadth of vulnerability types covered and the mindset encouraged, but the lack of verifiable details and sources weakens the overall argumentation.
Scientific Rigor, Source Quality, Title Accuracy
The scientific rigor is low: the presenter explicitly states he does not own the reports and they may not be true, and he does not provide any links to the original bug reports or technical write-ups. The only sources cited are promotional links to his own website and social media, which are not scientific references. The title is misleading as it promises a complete course covering 90 bugs, but the video only covers about 17 bugs and is more of an overview. The content is not peer-reviewed and lacks citations, making it unreliable for academic or professional use. The presenter’s credentials are not verified, and the video appears to be a promotional tool for his training platform.
220 words
Title / Content Match
The title promises a comprehensive ethical hacking course covering 90 bugs, but the video only covers about 17 bugs and is more of an overview than a complete course.
Quality & Reliability
5/10
The video is a tutorial that presents a curated list of bug bounty findings, but it lacks verifiable sources, technical depth, and rigorous methodology. The presenter explicitly disclaims ownership and verification of the reports, and the content is largely anecdotal with minimal technical detail.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction and overview of the course, disclaimer about bug reports.
- Bug 1: Stored XSS to privilege escalation - chain of vulnerabilities leading to account takeover.
- Bug 2: Recon finding - exposed database credentials via subdomain and config file.
- Bug 3: Broken access control - API endpoint manipulation to access all user profiles.
- Bug 4: HTML injection leading to PII disclosure in source code.
- Bug 5: IDOR in ChatGPT remix feature - predicting media IDs.
- Bug 6: Exposed AWS API keys in JS files leading to arbitrary account creation.
- Bug 7: Chaining self-XSS with CSRF for account takeover (PortSwigger lab).
- Bug 8: Path guessing to access dashboards without authentication.
- Bug 9: Bypassing 403 with HTTP method change to access admin panel.
- Bug 10: Logical flaw in discount application leading to free items.
- Bug 11: Plaintext site ID leading to third-party account takeover (New Relic).
- Bug 12: Multiple vulnerabilities found in a single program (HTML injection, response manipulation, API.log, XSS, SQLi).
- Bug 13: Using Axiom for automated recon and vulnerability scanning.
- Bug 14: Unprotected S3 directory listing on Netflix subdomain.
- Bug 15: Git config exposure leading to source code and credentials.
- Bug 16: Support email leading to full wiki access via Atlassian instance.
- Bug 17: Bypassing 2FA by dropping OTP request.
Cited Sources
- AllGoodTutorials — Promotional website for the presenter's training platform.
- AllGoodTutorials Newsletter — Newsletter signup page.
- AllGoodTutorials Supporters — Support page for the platform.
- AllGoodTutorials Pricing — Pricing page for premium access.
- AllGoodTutorials Videos — Video courses page.
- AllGoodTutorials Telegram — Telegram channel.
- AllGoodTutorials LinkedIn — LinkedIn company page.
Concurring Sources
- OWASP Top 10 — Lists common web vulnerabilities such as broken access control and injection, which align with the bugs discussed.
- PortSwigger Web Security Academy — Provides labs and tutorials on vulnerabilities like XSS, CSRF, and access control, which are covered in the video.
Dissenting Sources
- No specific discordant sources found — The video does not cite any sources that contradict its claims, but the lack of verifiable sources makes it difficult to assess concordance.
Contribution & Novelties
The video offers a curated list of real-world bug bounty findings, which can be valuable for beginners to understand common vulnerability classes and exploitation techniques. It emphasizes the importance of recon, chaining vulnerabilities, and thinking outside the box. However, the content is not original research and lacks technical depth. The presenter’s approach of breaking down bugs conceptually is useful for mindset development, but the lack of detailed technical explanations and verifiable sources limits its novelty.
Pour aller plus loin :
- OWASP Top 10 — The standard awareness document for web application security, covering many of the vulnerability classes mentioned.
- PortSwigger Web Security Academy — Free labs and tutorials on web vulnerabilities, including XSS, CSRF, and access control.
- Bugcrowd University — Educational resources for bug bounty hunters.
- HackerOne Hacktivity — Public disclosure of real bug bounty reports, useful for learning.
- Nuclei — A tool for fast and customizable vulnerability scanning, mentioned in the video.
153 words
Radar Profile
The radar profile shows moderate scores across all dimensions, with slightly higher in quantity of information and technical level, but lower in reliability. This indicates a tutorial that provides a broad overview of vulnerabilities but lacks depth and verifiable sources, making it suitable for beginners but not for advanced practitioners seeking rigorous technical details.
💬 No comments were provided for analysis.