Discover
Bug Bounty Reports Discussed

Bug Bounty Reports Discussed
Author: Grzegorz Niedziela
Subscribed: 64Played: 573Subscribe
Share
© Copyright Grzegorz Niedziela
Description
From Bug Bounty Reports Discussed podcast you can learn from the best bug bounty hunters in the world. I ask them about their methodologies, tools they use, the advice they give to beginners and many more... Subscribe to never miss an episode!
22 Episodes
Reverse
In this podcast, my guest is Arthur Aires, part-time bug bounty hunter and cybersecurity pro from Brazil. He has an amazing approach that combines manual hacking with using a lot of tools for recon and fuzzing.Some links mentioned in the video: https://github.com/pwntester/SerialKillerBypassGadgetCollection https://book.hacktricks.wiki/en/index.html https://portswigger.net/bappstore/e4e0f6c4f0274754917dcb5f4937bb9e https://portswigger.net/bappstore/594a49bb233748f2bc80a9eb18a2e08f https://portswigger.net/bappstore/0e61c786db0c4ac787a08c4516d52ccf https://github.com/PortSwigger/403-bypasser https://github.com/projectdiscovery/nuclei https://github.com/SeifElsallamy/Blind-XSS-Manager/tree/main https://github.com/trufflesecurity/xsshunter https://infosecwriteups.com/easy-xsshunter-discord-alerts-33fcff24a8f7 https://github.com/elkokc/reflector https://portswigger.net/burp/documentation/desktop/tools/dom-invader https://urlscan.io/Timestamps:00:00 Intro01:30 Balancing part-time bug bounty with full-time job02:56 Mixing manual bug bounty hunting with automation22:04 The most useful Burp extensions33:25 Fuzzing in bug bounty46:34 Live Hacking Events
Interview with Jasmin “JR0ch17” Landry, a former triager and security manager, now a full-time bug bounty hunter. We discuss bug bounty strategy, mindset, and finding high and critical vulnerabilities.
This video is an interview with René de Sain, known as renniepak. We talk about XSS, CSP bypasses, privilege escalation, speeding up the workflow with tricks like JS bookmarks and we discuss if there's such thing as bug bounty methodology.
This episode is the interview with Johan Carlsson, a full-time bug bounty hunter who specialises in client-side bugs and is currently the TOP1 hunter on GitLab.
This video is my interview with a full-time bug bounty hunter that had a great success at recent Live Hacking Events - Victor “doomerhunter” Poucheret. We're talking about his bug bounty methodology, choosing a bug bounty program, tools and much more.
In this interview, I'm talking with Louis Nyffenegger who's been teaching people websecurity since 13 years by creating Pentesterlab - web security learning platform, as well as by giving multiple talks and guiding people through their careers.
📧 Subscribe to BBRE Premium: https://bbre.dev/premium✉️ Sign up for the mailing list: https://bbre.dev/nl📣 Follow me on Twitter: https://bbre.dev/tw📣 Follow Douglas on Twitter: https://twitter.com/ArchAngelDDayIn this interview, we're talking with Douglas Day about his bug hunting methodlogy, about quitting his job to become a full-time bug bounty hunter and many more.BBRD podcast is also available on most popular podcast platforms:https://open.spotify.com/show/6tLoJ5foOoZPPELwrHPBO4 https://podcasts.google.com/feed/aHR0cHM6Ly93d3cuc3ByZWFrZXIuY29tL3Nob3cvNTA3Mzc4MS9lcGlzb2Rlcy9mZWVk https://podcasts.apple.com/us/podcast/bug-bounty-reports-discussed/id1583400215?uo=4Timestamps:00:00 Intro0:29 Going full-time bug bounty9:12 Douglas' bug bounty methodology28:13 Bug Bounty tools you need43:04 The benefits of collaboration in bug bounty54:23 How to deal with having a similar bug on many endpoints?1:11:37 How to select a bug bounty program?
📧 Subscribe to BBRE Premium: https://bbre.dev/premium✉️ Sign up for the mailing list: https://bbre.dev/nl📣 Follow me on Twitter: https://bbre.dev/tw📣 Follow Joel on Twitter: https://x.com/0xteknogeekIn this interview, we're talking with Joel about bug bounty hunting on mobile apps, about being a program manager, about Live Hacking Events and more.BBRD podcast is also available on most popular podcast platforms:https://open.spotify.com/show/6tLoJ5foOoZPPELwrHPBO4 https://podcasts.google.com/feed/aHR0cHM6Ly93d3cuc3ByZWFrZXIuY29tL3Nob3cvNTA3Mzc4MS9lcGlzb2Rlcy9mZWVk https://podcasts.apple.com/us/podcast/bug-bounty-reports-discussed/id1583400215?uo=4Links mentioned during the interview:https://www.timeshifter.comhttps://codeshare.frida.re/@teknogeek/android-universal-ssl-unpin/https://gitlab.com/newbit/rootAVDhttps://github.com/Ch0pin/medusahttps://github.com/teknogeek/get_schemasTimestamps:00:00 Intro00:22 Getting into bug bounty11:04 Live Hacking Events24:58 Mobile bug bounty48:34 Lessons from being a bug bounty program manager1:03:54 The plans for the Critical Thinking Bug Bounty podcast
📧 Subscribe to BBRE Premium: https://bbre.dev/premium✉️ Sign up for the mailing list: https://bbre.dev/nl📣 Follow me on Twitter: https://bbre.dev/tw📣 Follow Alex on Twitter: https://x.com/ajxchapmanIn this episode I'm interviewing Alex Chapman - a full-time bug bounty hunter known for finding many high-impact bugs and very little medium and low-impact ones.BBRD podcast is also available on most popular podcast platforms:https://open.spotify.com/show/6tLoJ5foOoZPPELwrHPBO4 https://podcasts.google.com/feed/aHR0cHM6Ly93d3cuc3ByZWFrZXIuY29tL3Nob3cvNTA3Mzc4MS9lcGlzb2Rlcy9mZWVk https://podcasts.apple.com/us/podcast/bug-bounty-reports-discussed/id1583400215?uo=4Timestamps:00:00 Intro0:22 How did Alex start with cybersecurity and bug bounty?3:05 Alex' uique hacking style19:18 Source code review tips28:37 How to write a good bug bounty report?45:52 Finding bugs in desktop applications52:15 LHEs1:00:57 Live of a full-time bug bounty hunter
In this episode, I'm talking about my story of getting into cybersecurity - what got me interested, how I became a pentester, what motivated my to create my channel and finally, how I became a bug bounty hunter.
In this episode of the podcast, I'm interviewing Cristi Vlad about bug bounty and pentesting - the differences, ways to build your network of clients, continuous learning and more.
In this episode of the podcast, I interview Justin Gardner, the host of the Critical Thinking Bug Bounty Podcast who's been a full-time hunter for about 4 years. We talk about his methodology, tooling and many more!
📧 Subscribe to BBRE Premium: https://bbre.dev/premium📖 Check out AppSecEngineer, the sponsor of today's video: https://www.appsecengineer.com📣 Follow GUEST on Twitter: https://twitter.com/@rez0✉️ Sign up for the mailing list: https://bbre.dev/nl📣 Follow me on Twitter: https://bbre.dev/twIn this interview we are discussing with rez0 a range of topics around AI - the new vulnerability opportunities it created, how can I help us in hacking and if it will replace us in the future.Resources and people mentioned in the podcast:https://olickel.com/everything-i-know-about-prompting-llmshttps://www.anthropic.com/index/prompting-long-contexthttps://simonwillison.nethttps://llm-attacks.org/zou2023universal.pdfhttp://llm-attacks.orgBBRD podcast is also available on most popular podcast platforms:https://open.spotify.com/show/6tLoJ5foOoZPPELwrHPBO4 https://podcasts.google.com/feed/aHR0cHM6Ly93d3cuc3ByZWFrZXIuY29tL3Nob3cvNTA3Mzc4MS9lcGlzb2Rlcy9mZWVk https://podcasts.apple.com/us/podcast/bug-bounty-reports-discussed/id1583400215?uo=4Timestamps:00:00 Intro00:32 Check out AppSecEngineer, the sponsor of this podcast01:36 rez0's regular bug bounty hacking style22:39 AI and hacking
In this episode, I interview Michał Bentkowski who specializes in crazy XSS bugs and now works on improving security of the browsers at Google.
In this episode with @NahamSec we are talking about bug bounty. Ben has a unique insight into mistakes beginners make since he's the biggest content creator in the bug bounty space and gets asked a lot of questions. We are talking about his methodology, the role of recon and much more.
In this podcast, I interview Yassine Aboukir - the winner of Most Valuable Hacker award at H1-303 Live hacking event. We talk about his bug bounty methodology, bounty vs pentesting as well as travelling, digital nomad lifestyle and doing sports.
In this podcast episode, I interview Shubham Shah - one of my biggest authorities in bug bounty space and expert in source code review who regularly finds 0days.📧 Subscribe to BBRE Premium: https://bbre.dev/premium ✉️ Sign up for the mailing list: https://bbre.dev/nl📣Follow me on Twitter: https://bbre.dev/tw📣 Follow Shubs on Twitter: http://twitter.com/infosec_au/Timestamps:00:00 Intro00:18 Shubs' background13:04 Choosing good targets for finding 0days20:41 How to audit the source code?33:34 Who should consider a career as a full-time bug bounty hunter?38:04 Sharing knowledge and disclosing 0days45:54 What skills does Shubs pay attention to when recruiting security researchers?48:48 AI in security research
In this podcast, I interview Youssef Sammouda - top Facebook/Meta bug bounty hunter in 2020, 2021 and 2022. He has found numerous bugs on Facebook, including account takeovers. We talk about his methodology, tools he uses, productivity tips and many more!
In this podcast, I interview Michael Ness about bug bounty automation and scaling 0 days to get multiple payouts for a single bug. We also talk about how to make the automation better and about some tips to upcoming bug hunters.📧 Subscribe to BBRE Premium: https://bbre.dev/premium✉️ Sign up for the mailing list: https://bbre.dev/nl📣Follow me on Twitter: https://bbre.dev/tw📣 Follow Michael on Twitter: https://twitter.com/mikey96_bhCheck out Overcast Security: https://search.overcast-security.app
📧 Subscribe to BBRE Premium: https://bbre.dev/premium✉️ Sign up for the mailing list: https://bbre.dev/nl📣 Follow me on Twitter: https://bbre.dev/tw📣 Follow Johan on Twitter: https://twitter.com/joaxcarIn this podcast I interview one of bug bounty hunters who started very recently but already is having a lot of success - Johan Carlsson. We talk about his hacking methodology, his journey with GitLab and his tips for bug bounty hunters.🖥 Get $100 in credits for Digital Ocean: https://bbre.dev/do
Comments