
Learn to use http debugger pro to intercept and analyze web traffic, install ssl certificates, inspect get and post requests and responses, and filter, edit, and resubmit http traffic.
Explore intercepting and editing requests with HTTP debugger Pro to analyze how app communications send and modify JSON payloads, including base64-encoded data and score parameters in a Telegram game scenario.
Learn to configure Burp Suite with Firefox proxy by installing Burp Suite, adding a Firefox proxy extension, configuring 127.0.0.1:8080, and enabling intercept.
Apply proxy settings to Burp Suite to reduce noise by filtering requests. Create 'does not match' rules for domains like Mozilla, Google, and Facebook to intercept only the target site.
Explore how to bypass email and phone otp by manipulating server responses with burp suite, intercepting requests, and testing sign-up flows for otp verification weaknesses.
Students explore an OTP bypass attack to take over accounts, examining OTP generation, bcrypt verification, and insecure forget-password flows, with notes on interception, request handling, and potential vulnerabilities.
Explore how an otp bypass can lead to account takeover by analyzing login flow, otp handling, and encryption interplay on a target website.
Explore automated form flooding with Burp Suite, focusing on the pitchfork attack using multiple payload sets and the intruder tool to test and submit form data.
Demonstrate a weak authentication bug where the OTP is exposed on the frontend, enabling an OTP bypass to sign up and log in.
demonstrates a simple two-factor authentication bypass by manipulating the login flow url to reach the dashboard without submitting a valid otp on misconfigured sites.
Explore the host header injection vulnerability through hands-on demos, learning how altering the http host header can redirect requests and bypass authentication using labs and x-forwarded-for techniques.
Learn how session hijacking occurs by stealing the victim's session ID from cookies and local storage to gain access to their account.
Explore insecure direct object reference (idor) by changing user ids to access other users' details, including billing and payments, using burp suite tools like intercept, repeater, and intruder.
Learn hands-on hacking of CCTV DVR systems, including online device discovery, credential testing, and using a GitHub tool workflow to access admin interfaces.
Explore hacking CCTV dashboards using Burp Suite, including proxy interception, response manipulation, and brute-force techniques to access admin portals and add users, with practical demonstrations.
Enable hypervisor on Windows 11, install VirtualBox, and download Kali Linux to set up a virtual machine. Then configure and run Kali Linux, test internet access, and explore Kali tools.
Learn Kali Linux basics by exploring the terminal, essential commands, and managing files and folders, including navigating directories, creating files and folders, viewing content, and managing users with sudo.
Learn to connect Kali Linux in VirtualBox to Wi-Fi with a USB wireless adapter, install drivers, attach the USB device, and verify networks using ifconfig and lsusb.
Explore sql injection with sqlmap in Kali Linux, identify vulnerabilities on a test site, and enumerate databases, tables, and login credentials, including MD5 hashed passwords.
Explore how account takeover arises from weak jwt token signatures, using brute-forcing to reveal the signature, and highlight tools such as burp suite and kali linux.
Control Android phone using Kali Linux, and learn to mirror and control Android via scrcpy, enabling USB debugging, wireless TCP/IP, audio forwarding, display mirroring, copy-paste, and webcam use.
Crack password protected PDF and ZIP files using a dictionary attack with John the Ripper on Kali Linux, leveraging a prebuilt word-list payload and hash extraction.
Identify hash types and crack hashed passwords using online tools and software like John the Ripper and Hashcat, with examples of sha1, md5, and ripemd-160.
Install metasploitable 2 in VirtualBox to practice ethical hacking by downloading the VMDK, attaching it to a new Linux 64-bit VM, and logging in as MSF admin.
Learn to use nmap to scan hosts and services, identify open ports and running services (ssh, ftp, http), and detect versions and operating system on Kali and Metasploitable.
Learn to use the Nmap scripting engine with Lua scripts to automate network tasks, enabling discovery, version detection, and exploitation of services like ssh, with custom wordlists.
Learn to brute force FTP services with Hydra, testing anonymous and user logins against vsftpd on the FTP port using password lists. Observe login outcomes and file transfers.
Explore brute forcing admin login using Burp Suite and Hydra in a controlled lab environment with DVWA and Metasploitable.
Develop understanding of command injection by demonstrating remote command execution on a vulnerable Dvwa page using Metasploitable and Kali Linux, and explore how security level settings affect exploit practicality.
Learn to set up a reverse shell using a command execution vulnerability, leveraging netcat to connect a metasploitable target to a Kali Linux listener, and execute remote commands.
TamperDev is a chrome extension to intercept and modify http requests
Explore negative quantity tampering in online shopping using burp suite, modifying cart requests to set quantity to -1 and reveal how final price can be reduced.
Explore how to bypass a four-digit OTP by brute forcing using burp suite, intercepting requests, and using repeater, intruder, and sniper payloads to identify the correct code.
Demonstrates a government site business logic bug by intercepting and modifying form data and post requests to tamper ticket price and total amount.
Are you ready to step into the world of ethical hacking and cybersecurity? Welcome to Blackhat Live: Hands-On Hacking, No Theory, the ultimate hands-on course designed for aspiring ethical hackers, bug bounty hunters, and cybersecurity enthusiasts who want to learn by doing, not just reading.
This course skips the boring theory and dives straight into live practicals, covering key topics such as penetration testing, Python scripting, malware analysis, bug bounty hunting, and more. Whether you’re a beginner or looking to enhance your hacking skills, this course will give you the real-world tools and techniques used by security professionals.
What You’ll Learn:
Ethical Hacking Basics: Understand the fundamentals of ethical hacking and how to identify security vulnerabilities.
Python Scripting for Cybersecurity: Automate your penetration testing and bug bounty tasks with Python.
Malware Analysis: Learn how to analyze malicious code, reverse-engineer malware, and secure systems.
Bug Bounty Hunting: Discover how to ethically find and report bugs and vulnerabilities for rewards.
Penetration Testing: Master the use of professional tools like Burp Suite, Silverbullet, and HTTP Debugger Pro.
Key Course Sections:
Burp Suite Live Practical: Learn how to use Burp Suite for basic penetration testing, OTP bypass, price tampering, and more.
Silverbullet Live Practical: Automate penetration testing and create custom configurations with Silverbullet.
HTTP Debugger Live Practical: Install, activate, and use HTTP Debugger Pro to analyze network traffic, inspect and modify HTTP requests and responses.
Real-World Projects: Hands-on labs and practical challenges to simulate live hacking environments.
Who Is This Course For?
This course is ideal for beginners in ethical hacking, Python programming, and cybersecurity who want to learn through practical, hands-on exercises. It’s also perfect for bug bounty hunters, security professionals, and tech enthusiasts eager to master tools and techniques without the fluff of traditional courses.
By the end of the course, you’ll have the skills to perform ethical hacking, conduct automated penetration testing, analyze malware, and successfully participate in bug bounty programs.