Top 4 Web hacking demos for aspiring hackers (with labs and CTF)
Big thanks to @ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the fo...

David Bombal
539.5K views ⢠Mar 15, 2026

About this video
Big thanks to @ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
Are you looking to get into bug bounty hunting but feel overwhelmed or worried the field is oversaturated? In this video, full-time bug bounty hunter Justin Gardner shares a realistic, actionable guide to web hacking for beginners.
We dive straight into the practical side with five live demonstrations of common web vulnerabilitiesāall done using just your browser and DevTools. Justin explains how Insecure Direct Object Reference (IDOR), Broken Access Controls, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF) work in the real world, including stories of finding these exact bugs on major platforms like Google.
After the demos, we tackle the biggest questions new hackers have: Is there still money to be made in 2026? How has AI changed the landscape? And what is the exact roadmap to landing your first bounty? Justin breaks down his "200-hour rule" for learning, why you need to get comfortable with failing, and the best resources (like HackerOne and PortSwigger) to help you launch your cybersecurity career today.
// Labs and more here: //
Labs: https://ztw.ctbb.show/
More labs: https://labs.cai.do/
And more labs: https://portswigger.net/web-security
// Justin Gardnerās SOCIAL //
YouTube: https://www.youtube.com/@criticalthinkingpodcast
LinkedIn: https://www.linkedin.com/in/rhynorater/
X: https://x.com/Rhynorater
GitHub: https://rhynorater.github.io/aboutme/
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
X: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/@davidbombal
Spotify: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ
SoundCloud: https://soundcloud.com/davidbombal
Apple Podcast: https://podcasts.apple.com/us/podcast/david-bombal/id1466865532
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:40 - Introduction
01:50 - Getting Started in Bug Bounty
03:11 - Can I Make Money in Bug Bounty?
04:11 - Demo 1
06:55 - Demo 2
08:47 - Lessons for Upcoming Hackers
10:09 - Demo 3
13:49 - Are There Demos on Justinās Podcast?
14:20 - Demo 4
18:11 - Real-Life Date of Birth Vulnerability
19:13 - Advice on Becoming a Hacker Like Justin
20:20 - What & Where to Study to Become a Bug Bounty Hacker
21:49 - How Long Does It Take?
25:07 - Outro & Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#webhacking #bugbounty #hack
Are you looking to get into bug bounty hunting but feel overwhelmed or worried the field is oversaturated? In this video, full-time bug bounty hunter Justin Gardner shares a realistic, actionable guide to web hacking for beginners.
We dive straight into the practical side with five live demonstrations of common web vulnerabilitiesāall done using just your browser and DevTools. Justin explains how Insecure Direct Object Reference (IDOR), Broken Access Controls, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF) work in the real world, including stories of finding these exact bugs on major platforms like Google.
After the demos, we tackle the biggest questions new hackers have: Is there still money to be made in 2026? How has AI changed the landscape? And what is the exact roadmap to landing your first bounty? Justin breaks down his "200-hour rule" for learning, why you need to get comfortable with failing, and the best resources (like HackerOne and PortSwigger) to help you launch your cybersecurity career today.
// Labs and more here: //
Labs: https://ztw.ctbb.show/
More labs: https://labs.cai.do/
And more labs: https://portswigger.net/web-security
// Justin Gardnerās SOCIAL //
YouTube: https://www.youtube.com/@criticalthinkingpodcast
LinkedIn: https://www.linkedin.com/in/rhynorater/
X: https://x.com/Rhynorater
GitHub: https://rhynorater.github.io/aboutme/
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
X: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/@davidbombal
Spotify: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ
SoundCloud: https://soundcloud.com/davidbombal
Apple Podcast: https://podcasts.apple.com/us/podcast/david-bombal/id1466865532
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:40 - Introduction
01:50 - Getting Started in Bug Bounty
03:11 - Can I Make Money in Bug Bounty?
04:11 - Demo 1
06:55 - Demo 2
08:47 - Lessons for Upcoming Hackers
10:09 - Demo 3
13:49 - Are There Demos on Justinās Podcast?
14:20 - Demo 4
18:11 - Real-Life Date of Birth Vulnerability
19:13 - Advice on Becoming a Hacker Like Justin
20:20 - What & Where to Study to Become a Bug Bounty Hacker
21:49 - How Long Does It Take?
25:07 - Outro & Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#webhacking #bugbounty #hack
Tags and Topics
Browse our collection to discover more content in these categories.
Video Information
Views
539.5K
Likes
2.6K
Duration
25:13
Published
Mar 15, 2026
User Reviews
4.2
(107) Related Trending Topics
LIVE TRENDSRelated trending topics. Click any trend to explore more videos.
No specific trending topics match this video yet.
Explore All Trends