video thumbnail 9:55
Authorization vs. Authentication (Google Bug Bounty)

2021-12-02

[public] 8.83K views, 2.08K likes, dislikes audio only

channel thumbLiveOverflow

Authorization and Authentication can be confusing. In this video we look at their differences, and then focus on valid and invalid authorization bugs.

advertisement: this video was commissioned by the Google Vulnerablity Rewards Program for their site https://bughunters.google.com

watch all BHU videos here: https://www.youtube.com/playlist?list=PLY-vqlMAnJ9bGoI82H1BB8BE4A8H2OCA-

00:00 - Intro

00:33 - Authentication vs. Authentication

02:04 - Complex Systems with Permissions and Roles

02:42 - Example #1: Permission Complexity

04:16 - "Fixes" for Authorization Bugs

04:48 - Roles vs. Permissions

05:53 - What are Authorization Bugs?

06:52 - Example #2: Confusing Invalid Auth "Bugs"

08:22 - Summary

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Instagram: https://instagram.com/LiveOverflow/

→ Blog: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Intro
/youtube/video/hmJKUQlcGAc?t=0
Authentication vs. Authentication
/youtube/video/hmJKUQlcGAc?t=33
Complex Systems with Permissions and Roles
/youtube/video/hmJKUQlcGAc?t=124
Example #1: Permission Complexity
/youtube/video/hmJKUQlcGAc?t=162
"Fixes" for Authorization Bugs
/youtube/video/hmJKUQlcGAc?t=256
Roles vs. Permissions
/youtube/video/hmJKUQlcGAc?t=288
What are Authorization Bugs?
/youtube/video/hmJKUQlcGAc?t=353
Example #2: Confusing Invalid Auth "Bugs"
/youtube/video/hmJKUQlcGAc?t=412
Summary
/youtube/video/hmJKUQlcGAc?t=502
I’m moving, no videos sorry 17,541 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
Sudo Vulnerability Walkthrough by LiveOverflow
/youtube/video/TLa2VqcGGEQ