BePractical
Open in Telegram
If you have any doubts then email at faiyazahmad.online@gmail.com
Show more7 357
Subscribers
No data24 hours
-417 days
-4630 days
Posts Archive
7 357
It always makes me so happy to see comments like these. I am really honored that my videos are helping you all in your bug bounty journey! Thanks for all your support & love
7 357
Hi everyone! Check out my recent linkedin post where i was able to bypass cloudflare waf & got xss with a unique method on a real target
Link: https://www.linkedin.com/posts/faiyaz-ahmad-64457520b_ive-recently-bypassed-a-cloudflare-web-application-activity-7351124286058770433-dgvy?utm_source=share&utm_medium=member_desktop&rcm=ACoAADVMiFQBQBWOA7hoDcQSKy5oBb0cvy4PNXs
7 357
For example, Here's a little info on web development jobs. Many people were saying that these jobs will be replaced as AI is really good at doing it.However, just a Google search will show you that these jobs will get increased in the near future instead of decreasing.
Therefore, just chill, learn, treat ai as a tool and keep grinding!
7 357
My Take on AI in Cybersecurity
I believe that for a long time, AI will act more like a helpful assistant to cybersecurity professionals rather than replacing them completely. Hereās why:
1. AI Creates New Challenges Too
As the founder of Infosys once said, when machines start solving certain problems, humans begin working on more complex ones. A good example of this is how AI itself led to a new type of vulnerability known as *prompt injection*.
2. AI-Led Bug Hunting Isnāt Entirely New
Many people are talking about XBow AI, which recently ranked #1 on HackerOneās VDP leaderboard. While thatās impressive, itās important to remember that many top bug bounty hunters have been using their own powerful automation systems for years. These tools work at scale and follow unique methods, so this kind of automation isnāt new in the bug bounty world.
3. AI Struggles with Complex Vulnerabilities
While AI is good at finding common issues like simple XSS or IDOR, it still finds it hard to detect more advanced bugsālike business logic flaws, tricky XSS bypasses, or chaining multiple vulnerabilities together.
4. AI Can Make Mistakes (Hallucination)
Sometimes AI gives answers that sound correct but are completely wrong. This is called hallucination, and in cybersecurity, such mistakes can be risky and misleading.
Conclusion:
AI is definitely becoming a useful tool in cybersecurity, helping with automation, speed, and scale. But itās not perfect and still needs human oversight, creativity, and deep understanding. Instead of seeing AI as a replacement, we should treat it as a partner that boosts our capabilities while we focus on solving the bigger, more complex problems
7 357
The Risk of Hallucination
Another critical limitation of AI is the risk of hallucinationāwhere the model generates responses that appear accurate but are factually incorrect. This can be particularly dangerous in cybersecurity, where accuracy and precision are crucial.
In summary, while AI is making significant contributions to the field, it is best viewed as a tool to enhance human capabilitiesānot a replacement for human intuition, creativity, and contextual understanding.
Let me know if you'd like a version tailored for LinkedIn or a presentation slide.
You said:
Make it easy to understand and add a conclusion to it as well
ChatGPT said:
Sure! Hereās a simplified and easy-to-understand version of your take, with a clear conclusion:
My Take on AI in Cybersecurity
I believe that for a long time, AI will act more like a helpful assistant to cybersecurity professionals rather than replacing them completely. Hereās why:
AI Creates New Challenges Too
As the founder of Infosys once said, when machines start solving certain problems, humans begin working on more complex ones. A good example of this is how AI itself led to a new type of vulnerability known as prompt injection.
AI-Led Bug Hunting Isnāt Entirely New
Many people are talking about XBow AI, which recently ranked #1 on HackerOneās VDP leaderboard. While thatās impressive, itās important to remember that many top bug bounty hunters have been using their own powerful automation systems for years. These tools work at scale and follow unique methods, so this kind of automation isnāt new in the bug bounty world.
AI Struggles with Complex Vulnerabilities
While AI is good at finding common issues like simple XSS or IDOR, it still finds it hard to detect more advanced bugsālike business logic flaws, tricky XSS bypasses, or chaining multiple vulnerabilities together.
AI Can Make Mistakes (Hallucination)
Sometimes AI gives answers that sound correct but are completely wrong. This is called hallucination, and in cybersecurity, such mistakes can be risky and misleading.
Conclusion:
AI is definitely becoming a useful tool in cybersecurity, helping with automation, speed, and scale. But itās not perfect and still needs human oversight, creativity, and deep understanding. Instead of seeing AI as a replacement, we should treat it as a partner that boosts our capabilities while we focus on solving the bigger, more complex problems.
7 357
ChatGPT
Saved memory full
You said:
AI hallucination
ChatGPT said:
AI hallucination refers to a situation where an artificial intelligence modelālike ChatGPTāgenerates content that sounds plausible but is actually false, inaccurate, or fabricated.
š In Simple Terms:
Imagine asking an AI for a fact, and it confidently gives you an answerābut that answer is completely made up, even though it sounds right.
š§ Why It Happens:
Hallucination occurs because language models don't "know" factsāthey predict what words are likely to come next based on patterns in data they've seen during training. If the training data was incomplete, biased, or the AI tries to fill gaps creatively, it might invent information.
š Examples:
Fake citations: Citing articles or papers that donāt exist.
Wrong answers: Saying āParis is the capital of Italyā (plausible structure, wrong content).
Invented URLs, names, or commands: Especially in technical or niche topics.
š”ļø How to Reduce It:
Cross-check outputs from AI with trusted sources.
Ask for sources or explanations.
Use tools specifically fine-tuned for accuracy (like those integrated with live search or retrieval).
Let me know if you'd like real-life examples or want to learn how to detect hallucinations effectively.
You said:
Make it a bit formal and easy to understand
My take on AI in cyber security: I think for a long period of time, AI is going to act more like an assistant for cyber security people instead of completely replacing them and here's why:
1. As the founder of Infosys once said, when a machine solves a problem, we humans start looking for more complex problems and try to find solutions for it. A really great example is how AI has also given birth to a new class of vulnerability "prompt injection"
2. Many people are talking about xbow ai which is ranking #1 on h1 leaderboard(vdp). While this itself is a great news, but don't forget that many professional bug bounty hunters have their own complete automation system for bug bounty programs that hunt on a large scale with their unique methodology. Therefore it is not something very new in the industry
3. While AI can detect generic xss, idors etc..complex vulnerabilities are still a challenge for them specially business logic bugs, advanced xss bypass, chaining multiple attacks etc
4. AI can hallucinate
ChatGPT said:
Hereās a more formal yet easy-to-understand version of your take on AI in cybersecurity:
My Perspective on the Role of AI in Cybersecurity
In my view, AI will continue to serve as a powerful assistant to cybersecurity professionals for the foreseeable future, rather than replacing them entirelyāand hereās why:
Innovation Driven by Automation
As the founder of Infosys once pointed out, whenever machines begin to solve a particular class of problems, humans naturally shift their focus toward more complex challenges. A great example of this is the emergence of prompt injectionāa new category of vulnerability that arose specifically due to the advancement of AI.
AI-Led Bug Bounty Programs Are Not Entirely New
There's been a lot of attention around tools like XBow AI, which recently ranked #1 on the HackerOne leaderboard (VDP category). While this is certainly impressive, it's worth noting that many experienced bug bounty hunters have been running highly customized and fully automated systems for years. These systems often incorporate unique methodologies and scale efficientlyāso the concept of AI-driven automation in bug bounty is not entirely new to the industry.
Limitations in Handling Complex Vulnerabilities
Although AI can reliably detect common vulnerabilities such as reflected XSS or basic IDOR issues, it still struggles with more sophisticated attacks. Business logic vulnerabilities, advanced XSS bypass techniques, and chaining multiple vulnerabilities into a meaningful exploit remain areas where human expertise is essential.
7 357
Hi people, is it really true that nahamsec recently created a new video which is very similar to our recent jwt exploit vulnerability?
7 357
Hi everyone, Next video will be released tomorrow! This one's really interesting and will help you to discover vulnerabilities in modern applications.. I've recently used this method & found 5 critical vulnerabilities impacting their whole applications
Till then keep learning & keep hacking ā¤ļø
7 357
The webinar's recording is live on YouTube! Check it out here: https://www.youtube.com/watch?v=FwahyqRna5k
7 357
Really glad to have you all in the event! Hope you all liked it & got to learn something new
7 357
Hi everyone! For the next video, I am thinking of creating one on how to get your first job in cyber security as a fresher in 2025. What do you guys think?
7 357
Hi everyone! As promised, we will be conducting a free live webinar on server side request forgery on 29th June 2025 to celebrate 30k subscribers!!
This webinar will cover everything about ssrf from basics to advanced with practical demonstration & some PoCs as well
If you are interested then feel free to submit this form: https://forms.gle/2axTEKZpjTKcrVDa7
Once again, Thank you all for supporting the channel. Keep learning & Keep hacking!
- Faiyaz Ahmad
7 357
Bug Bounty Tip:
Found a subdomain of your target that looks like this api-prod.target.com?
Then try to use ffuf to discover additional subdomains with this same pattern using the command:
ffuf -u http://api-FUZZ.target.com/ -w wordlist.txt -mc all
This generally helps me to discover really interesting api apps that are usually hidden from the public
7 357
I have 3 published courses on Udemy focused on bug bounty and cybersecurity ā and Iāve never claimed that just buying one of these courses will make you thousands of dollars!!
In fact, Iāve always added a clear note in the course descriptions:
"These courses are designed to help you upskill and build a strong foundation ā not to make you rich overnight."
If any course is claiming to turn you into a professional bug bounty hunter instantly or promises quick money, it's most likely a scam.
My intention has always been to provide practical, beginner-friendly guidance based on real experience.
These courses are for those who are genuinely
curious and ready to learn through consistent effort, trial and error, and hands-on practice.
What makes me truly grateful is the response from the community ā all three courses have 4+ star ratings and many positive reviews from learners who found real value in them.
Feel free to check them out: https://www.udemy.com/user/faiyaz-ahmad-33/
7 357
Really happy to see that my videos are helping people in finding real vulnerabilities ā¤ļø
