Web Hacking Secrets: How to Hack Legally and Earn Thousands of Dollars at HackerOne

£840.00 ex VAT

HackerOne is your big opportunity. This is the platform where you can hack legally and at the same time you can make money. You can hack many different companies like Twitter, Yahoo, Uber, Coinbase, and a lot more. And you can get paid for your findings, for example $100, $1,000, or even $10,000 per one bug. It’s just amazing. All you need is Internet connection and knowledge. Yes, you need knowledge to go from zero to thousands of dollars at HackerOneand in this online training Dawid Czagan is going to share his knowledge with you.

This online training is composed of 6 hours of high-quality video courses and 4 hours of live online training.

The live part of this course will run online on the 20 April 2022, 9am−1pm (UK time).

Out of stock

SKU: 44CON-TRN-M22-WHS Category: Tags: , , , , , , , , ,

Part Recorded/Part Live Online Training

Presented By: Dawid Czagan

HackerOne is your big opportunity. This is the platform where you can hack legally and at the same time you can make money. You can hack many different companies like Twitter, Yahoo, Uber, Coinbase, and a lot more. And you can get paid for your findings, for example $100, $1,000, or even $10,000 per one bug. It’s just amazing. All you need is Internet connection and knowledge. Yes, you need knowledge to go from zero to thousands of dollars at HackerOneand in this online training Dawid Czagan is going to share his knowledge with you.

Dawid Czagan is one of the top hackers at HackerOne and he knows quite a lot about hacking and making money that way. In this online training he will present many award-winning bugs. The more you play with award-winning bugs the more knowledge you get and the more knowledge you have the more money you can make. He’ll also discuss a successful bug hunting strategy that he has been using in recent years. What’s more, he’ll present a lot of demos, because he wants you to see how all these things work in practice.

This online training is composed of:

  • 6 hours of high-quality video courses with lots of recorded demos (LIFETIME access; the courses are listed below)
  • 4 hours of live online training (demonstrating advanced attacks on modern web applications + training support for the video courses)

The live part of this course will take place online on the 20 April 2022, 9am−1pm (UK time).(Watching the video courses before the live online training is recommended, but not necessary).

The price is £840 (inc VAT/£700 ex VAT).

Read more

6 hours of high-quality video courses with lots of recorded demos

You will get lifetime access to these 6 video courses:

  1. Start Hacking and Making Money Today at HackerOne
  • HackerOne: Your Big Opportunity
  • Getting Started with 5 Bugs
  • Automatic Leakage of Password Reset Link  (FREE VIDEO)
  • How to Get Access to the Account of the Logged Out User
  • Insecure Processing of Credit Card Data
  • Disclosure of Authentication Cookie
  • User Enumeration
  1. Keep Hacking and Making Money at HackerOne
  • How to Impersonate a User via Insecure Log In  (FREE VIDEO)
  • Sensitive Information in Metadata
  • Disclosure of Credentials
  • Insecure Password Change
  • Dictionary Attack
  1. Case Studies of Award-Winning XSS Attacks: Part 1
  • XSS via Image
  • XSS via HTTP Response Splitting
  • XSS via Cookie  (FREE DEMO)
  • XSS via AngularJS Template Injection
  1. Case Studies of Award-Winning XSS Attacks: Part 2
  • XSS via XML  (FREE VIDEO)
  • XSS via location.href
  • XSS via vbscript:
  • From XSS to Remote Code Execution
  1. DOUBLE Your Web Hacking Rewards with Fuzzing
  • The Basics of Fuzzing
  • Fuzzing with Burp Suite Intruder – Overview
  • Fuzzing for SQL Injection – Demo  (FREE VIDEO)
  • Fuzzing for Path Traversal – Demo
  • Fuzzing with Burp Suite Intruder: Tips and Tricks
  1. How Web Hackers Make BIG MONEY: Remote Code Execution
  • From SQL Injection to Remote Code Execution   (FREE VIDEO)
  • From Disclosure of Software Version to Remote Code Execution
  • Remote Code Execution via File Upload
  • Remote Code Execution via Deserialization

Lifetime access to these 6 video courses will be granted before participating in the live online training session. More information can be found in the section ”What students will receive”.

4 hours of live online training

Part 1: Dawid will demonstrate advanced attacks on modern web applications:

  • Token hijacking via PDF file
  • Subdomain takeover
  • HTTP parameter pollution
  • Bypassing XSS protection
  • DB truncation attack
  • and more …

Part 2: Dawid will answer your questions about the attacks presented in the video courses and bug hunting at HackerOne (training support for the video courses).

What students should know

  • Basic hacking skills
  • Basic knowledge of web application security
  • Basic understanding of XSS attacks (cross-site scripting)

 What students will learn

  • Master web application security testing
  • Become a successful bug hunter
  • Go from zero to thousands of dollars at HackerOne
  • Double your web hacking rewards with fuzzing
  • Learn how hackers earn thousands of dollars per one bug
  • Discover how to find these bugs step-by-step in practice (recorded DEMOS)
  • Learn from one of the top hackers at HackerOne

What students will receive 

Students will receive lifetime access to 6 hours of high-quality video courses with lots of recorded demos (hosted on the 3rd party platform Grinfer; subject to terms of use and privacy policy). The access link will be sent after subscribing to Dawid’s newsletter and before participating in the live online training session (during the live online training session, there will be time to ask questions about the attacks presented in the video courses and bug hunting at HackerOne – training support for the video courses).

What students say about Dawid’s trainings 

References are attached to his LinkedIn profile. They can also be found here – training participants from companies such as Oracle, Adobe, ESET, ING, …

Read more

Instructor

Dawid Czagan (@dawidczagan) is an internationally recognised security researcher and trainer. He is listed among top hackers at HackerOne. Dawid has found security vulnerabilities in Google, Yahoo, Mozilla, Microsoft, Twitter and other companies. Due to the severity of many bugs, he received numerous awards for his findings.

Dawid shares his security bug hunting experience in his hands-on trainings “Hacking Web Applications – Case Studies of Award-Winning Bugs in Google, Yahoo, Mozilla and More” and “Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation”. He delivered security training courses at key industry conferences such as Hack In The Box (Amsterdam), CanSecWest (Vancouver), 44CON (London), Hack In Paris (Paris), DeepSec (Vienna), NorthSec (Montreal), HITB GSEC (Singapore), BruCON (Ghent) and for many corporate clients. His students include security specialists from Oracle, Adobe, ESET, ING, Red Hat, Trend Micro, Philips and government sector (recommendations).

Dawid is a founder and CEO at Silesia Security Lab – a company which delivers specialised security testing and training services. He is also an author of online security courses. To find out about the latest in Dawid’s work, you are invited to subscribe to his newsletter and follow him on Twitter (@dawidczagan) and LinkedIn.

Read more