BePractical – Telegram
BePractical
7.4K subscribers
232 photos
24 videos
6 files
395 links
If you have any doubts then email at faiyazahmad.online@gmail.com
Download Telegram
Bug Bounty Tip:

Found a subdomain of your target that looks like this api-prod.target.com?

Then try to use ffuf to discover additional subdomains with this same pattern using the command:

ffuf -u http://api-FUZZ.target.com/ -w wordlist.txt -mc all

This generally helps me to discover really interesting api apps that are usually hidden from the public
31👍4🔥2
Hi everyone! As promised, we will be conducting a free live webinar on server side request forgery on 29th June 2025 to celebrate 30k subscribers!!

This webinar will cover everything about ssrf from basics to advanced with practical demonstration & some PoCs as well

If you are interested then feel free to submit this form: https://forms.gle/2axTEKZpjTKcrVDa7

Once again, Thank you all for supporting the channel. Keep learning & Keep hacking!

- Faiyaz Ahmad
28🔥7😁1
Hi everyone! For the next video, I am thinking of creating one on how to get your first job in cyber security as a fresher in 2025. What do you guys think?
Anonymous Poll
75%
Sure, that'll be great
25%
Nah, make videos on bug bounty, vulnerabilities etc
7
This media is not supported in your browser
VIEW IN TELEGRAM
Really glad to have you all in the event! Hope you all liked it & got to learn something new
👍108🥰1
Hi everyone, Next video will be released tomorrow! This one's really interesting and will help you to discover vulnerabilities in modern applications.. I've recently used this method & found 5 critical vulnerabilities impacting their whole applications

Till then keep learning & keep hacking ❤️
20👍3🔥3👏2
Anyone at bsides bangalore now? If yes then let's catch up on the conference room!
Had a great day today at bsides bangalore!
9👍5
Hi people, is it really true that nahamsec recently created a new video which is very similar to our recent jwt exploit vulnerability?
🔥11👍5
Hi everyone, New video will be coming tomorrow at 6pm IST! Stay tuned ❤️
9👏1
My Take on AI in Cybersecurity

I believe that for a long time, AI will act more like a helpful assistant to cybersecurity professionals rather than replacing them completely. Here’s why:

1. AI Creates New Challenges Too
As the founder of Infosys once said, when machines start solving certain problems, humans begin working on more complex ones. A good example of this is how AI itself led to a new type of vulnerability known as *prompt injection*.

2. AI-Led Bug Hunting Isn’t Entirely New
Many people are talking about XBow AI, which recently ranked #1 on HackerOne’s VDP leaderboard. While that’s impressive, it’s important to remember that many top bug bounty hunters have been using their own powerful automation systems for years. These tools work at scale and follow unique methods, so this kind of automation isn’t new in the bug bounty world.

3. AI Struggles with Complex Vulnerabilities
While AI is good at finding common issues like simple XSS or IDOR, it still finds it hard to detect more advanced bugs—like business logic flaws, tricky XSS bypasses, or chaining multiple vulnerabilities together.

4. AI Can Make Mistakes (Hallucination)
Sometimes AI gives answers that sound correct but are completely wrong. This is called hallucination, and in cybersecurity, such mistakes can be risky and misleading.

Conclusion:
AI is definitely becoming a useful tool in cybersecurity, helping with automation, speed, and scale. But it’s not perfect and still needs human oversight, creativity, and deep understanding. Instead of seeing AI as a replacement, we should treat it as a partner that boosts our capabilities while we focus on solving the bigger, more complex problems
🔥174💯2
For example, Here's a little info on web development jobs. Many people were saying that these jobs will be replaced as AI is really good at doing it.However, just a Google search will show you that these jobs will get increased in the near future instead of decreasing.

Therefore, just chill, learn, treat ai as a tool and keep grinding!
💯14👀3
It always makes me so happy to see comments like these. I am really honored that my videos are helping you all in your bug bounty journey! Thanks for all your support & love
27🫡4🔥3
For the past few months, I've interviewed over 70+ candidates and while most of them had fancy certificates like OSCP etc..None were able to answer practical questions at all...

Remember: While it is important to have a certificate, The most important thing is to have the necessary skills for the role you're applying for!
🔥245
We have now 33K+ people supporting the youtube channel! ❤️
32🔥4👍2
Most beginners in cybersecurity skip recon.
But real progress begins when you start mastering it.

I just dropped a complete Udemy course: The Art of Web Reconnaissance.
It covers everything from basic to advanced recon techniques, and by the end, we find high/critical vulnerabilities on a real-world target—using only recon.

If you're into bug bounties or ethical hacking, this course will change the way you look at reconnaissance.

Grab it now with the maximum discount (valid only for the next 3 days):
https://www.udemy.com/course/the-art-of-web-reconnaissance-bug-bounty-ethical-hacking/?couponCode=D75401875F9E3CC55BB9
14
Stick to the roots 💪
🔥327👍2😍1
Hi everyone, New video will be releasing tomorrow at 11am IST! This one is really interesting and to be honest, it is one of the advanced stuffs that will be uploaded on our channel. Stay tuned❤️
🔥124