DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix

Поделиться
HTML-код
  • Опубликовано: 20 ноя 2024

Комментарии • 108

  • @bgorortayber
    @bgorortayber Месяц назад +99

    Some things that happened to me while doing Bug Bounty:
    1. Downgrading the score of a vulnerability that was previously reported twice and rated as "Medium".
    2. Reporting to a open source project, they see the bug, they remove all the files from their Github, bumped up the version, then, told me that I've found the vulnerability in an older version.
    3. The program imported all the existing bugs into the platform, afterwards, marked them as duplicate once they got reported.
    And the list goes on, the lesson is simple, never hack for free.
    All the best for you and your family, Jason.

    • @official.sirhaxalot
      @official.sirhaxalot Месяц назад

      I got repeatedly fisted doing bb. Wrote a blog about it if you're interested?

    • @incognitoworth1205
      @incognitoworth1205 Месяц назад +1

      This is f*cking true

    • @trevermcbride4041
      @trevermcbride4041 Месяц назад +17

      I reported a vulnerability once that was currently working on the platform that allowed you to bypass mfa, and was told its a duplicate vulnerability from a internal bulletin a year before I submitted it to them.

    • @bgorortayber
      @bgorortayber Месяц назад

      @@trevermcbride4041 Name and shame!

    • @Studio23Media
      @Studio23Media Месяц назад +9

      @@trevermcbride4041 YIKES!! That's embarrassing for them to admit. 😂

  • @asurhacks
    @asurhacks Месяц назад +45

    This kinda guy is worshipped by everyone in their respective field. Someone who speaks up against the odd. Mad respect to boss haddix the legend.

  • @detecht
    @detecht Месяц назад +17

    Seeing you speak on this, makes the rest of us feel like we can too. Thank you for having the courage to say what we've all been thinking. We love you, jHaddix ❤

  • @manufaleschini
    @manufaleschini Месяц назад +8

    I love this talk and have the highest respekt of Jason. He is one of the most brilliant minds in the Bug Bounty scene and such a wonderful human being. He doesn't have to fight for this community, he does it at will. I admire your support for the "nonames" and new hunters in the field.
    May god bless you and your wife. 🙏🏻

  • @effsixteenblock50
    @effsixteenblock50 Месяц назад +40

    Mad respect to Haddix for this truth telling. No doubt he's been conflicted about this stuff for a long time and is finally in a position where he feels like he can talk about it.
    Something else that needs to be addressed is that when researchers are continuously facing these BS practices, many of them might just opt to sell their P-1 / 0 days to a buyer that pays way more and with much less friction than the programs.

    • @huzaifamuhammad8044
      @huzaifamuhammad8044 Месяц назад +5

      I'm afraid some might even turn into the other side (black hat)

    • @Mikey-Plays-Bass
      @Mikey-Plays-Bass Месяц назад

      @@huzaifamuhammad8044 IMO, that would be the appropriate response to corporate consolidation and research theft.

    • @Internet_User_0x0000
      @Internet_User_0x0000 Месяц назад

      My sentiment exactly, "Oh you want to treat me like a fool?" *proceeds to sell 0day to Russia instead*...

    • @youreabigguy
      @youreabigguy 29 дней назад

      ​​@@huzaifamuhammad8044 This happens frequently, I know this for a fact

  • @WarmEmpanada
    @WarmEmpanada Месяц назад +12

    Wishing the best for you and your family Jason ❤

  • @youreabigguy
    @youreabigguy 29 дней назад +8

    It should be well known by now, never to short, be stingy with, get over on or underestimate your hackers... When very talented researchers get screwed over they begin to thinking and being a legitimate researcher isn't worth it, and go from reporting bugs to selling exploits on the black market.

    • @theodorekorehonen
      @theodorekorehonen 12 дней назад

      If the suits that run these ticketing systems think the people that generate the revenue used to pay their salaries should simp for them and on top of that, be thankful for the privilege to work for them, I think marketplaces for bugs on the non clearnet might just grow in popularity.
      Greedy people seem to manage to ruin everything

    • @devz9530
      @devz9530 9 дней назад

      yes I think this will be the next step for the bug bounty scene and corporates will be forced to react, either by bidding on the exploits themselves on the black market, or creating a better marketplace solution that favors us hackers

  • @zerocewl
    @zerocewl Месяц назад +3

    Awesome talk by jason haddix thanks, And Prayers to your family jason 🙏

  • @PixelPulse_Playbook
    @PixelPulse_Playbook Месяц назад +4

    Some hackers create informative content, and that's a good thing. However, I believe that sometimes you need to stand up for your community. It's great content, and I respect you, bro.

  • @almc8445
    @almc8445 Месяц назад +13

    Almost all of the issues here seem like they come from the same reason we have unions for regular employees… Hackers union anyone?

    • @TESTA-CC
      @TESTA-CC 6 дней назад

      We Have a Hackers Union....it's called Code!

    • @almc8445
      @almc8445 6 дней назад

      @ Code doesn’t stop a race to the bottom for wages. That’s exactly my point…

  • @tobias8933
    @tobias8933 25 дней назад +1

    Thanks for speaking up! I've discovered a high severity vulnerability in a well-known social media platform a couple months ago. The triaging process was an absolutely ridiculous shit show. It took 6 months, included two interventions from the platform's support team and right before the payout, they decreased the severity rating reducing the payout by 90%.
    0/5 Never again.

    • @theodorekorehonen
      @theodorekorehonen 12 дней назад

      I'm assuming there's some forced arbitration thing so they can tell you to GFY whenever they pull their scam?

  • @matt5721
    @matt5721 Месяц назад +38

    Wow that's nuts about the traffic being monitored for the top 250.
    It would be petty cash to them AND create competition by paying those 250, but they discourage them instead.

    • @AlexbongoKurban
      @AlexbongoKurban Месяц назад +1

      Why do you think in the programs they request or require you to put a custom header with your username of the bug bounty program?

    • @matt5721
      @matt5721 Месяц назад +4

      @@AlexbongoKurban so you just commented without watching?
      They're stealing from the top 250

    • @sithrebel1548
      @sithrebel1548 29 дней назад

      ​@@matt5721 cry harder

  • @TimHerbert509
    @TimHerbert509 29 дней назад +1

    Thanks for helping us up and comers! Prayers for your family.

  • @Thiccolo
    @Thiccolo Месяц назад +5

    This needs to be put out there even more

  • @TomPotato-f7v
    @TomPotato-f7v 29 дней назад +5

    I'd drop everything to be at my wife's side, instead of worrying about using mild swear words at a talk that certainly won't change the world. but that's just me. all the best to you and yours, mr haddix

  • @official.sirhaxalot
    @official.sirhaxalot Месяц назад +68

    Putting personal shit to one side to work is the epitome of a professional. Excellent talk. I hope your wife recovers.

    • @2rx_bni
      @2rx_bni Месяц назад +21

      No it's deranged they should have given him an out. Don't do this. It's unhinged.

    • @galloe
      @galloe Месяц назад

      ​@@2rx_bniYeah, fuck that. A talk over my wife, there's no way in hell I'd ever do that.

    • @trustedsecurity6039
      @trustedsecurity6039 Месяц назад +11

      ​@@2rx_bni totally!!! The worst is his "my kids are watching my others kids" WTF!!! Kids must be sas for their mom and this guy isnt even there for them... Bad Parents really!!!

    • @emarbeats6896
      @emarbeats6896 Месяц назад

      ​@@trustedsecurity6039seems like hes working pretty hard to provide for his family.

    • @johnandmegh
      @johnandmegh 25 дней назад +3

      Setting aside whatever their family dynamics might be, which might make it totally ok in his particular case…the caveat given at the beginning tacitly encourages the behavior of “I’d rather push myself past the normal point and do a worse job, than take time away for me and my family”, which I believe is negative for most people.

  • @jhaddixP
    @jhaddixP Месяц назад +28

    • @michaelr.3799
      @michaelr.3799 Месяц назад

      Thank you for doing this, wishing your wife a speedy recovery.

  • @brunoeligiopavesi6987
    @brunoeligiopavesi6987 Месяц назад +2

    As usual Jason's talks are always very interesting.

  • @trailer-g1118
    @trailer-g1118 3 дня назад +1

    I have learnt something but also discouraged, whether to start bug bounty or something else........please advice..

  • @mohamedmater1230
    @mohamedmater1230 Месяц назад +1

    wishing your wife a speedy recovery Thanks JHaddix

  • @evilcorp3037
    @evilcorp3037 Месяц назад +2

    Wow, really eye opening! Thank you very much

  • @comosaycomosah
    @comosaycomosah Месяц назад

    very hard to navigate appreciate you advocating for the little guy always

  • @tallst1
    @tallst1 Месяц назад +15

    Glorified ticketing system

    • @EarthWalkerOne
      @EarthWalkerOne Месяц назад

      Bug Bounty is the same as the BetterBusinessBurreau. Started by bad businesses to limit the number of lawsuits they receive...

  • @shmo9943
    @shmo9943 18 дней назад +1

    Pissing off hackers is a very bold move

  • @0xbeven462
    @0xbeven462 Месяц назад +2

    🎉 great talk , though it maybe underrvalued your illustrated valuable insights into shady platforms and shit loads that occur to bug hunters, misrepresentation etc, nice talk

  • @EarthWalkerOne
    @EarthWalkerOne Месяц назад +3

    Seems like all that really needs to happen is companies and especially Platforms being taught a lesson. Bounty platforms should also be anonymous, there should be no room for celebrity/favoritism or targeted monitoring. If we're in this to make things more secure and get paid, then bug bounty programs and platforms should really try to incentivize white hat behavior. If I'm not going to get paid either way, the world will become more secure by forcing companies to listen and practice security if their vulns given away in alternative markets. If they're going to make getting compensated fairly difficult, you can just name your price elsewhere...

    • @SimonCas
      @SimonCas 29 дней назад +2

      They want to play a game, we like playing games 😊

  • @24bkdoor
    @24bkdoor 26 дней назад

    There are also organizations that wait for you to publicly disclose vulnerabilities and intentionally ignore your reports so you do so, platforms that suggest bugs are not shared with customers but are. The struggle they are face with are the legal implications of not protecting their systems. Lately the pros of ethical reporting are outweighed by the cons. I hope your talk inspires change.

  • @danishbhat1536
    @danishbhat1536 Месяц назад +2

    A wise man says wise things

  • @robertbruce7686
    @robertbruce7686 16 дней назад

    Another excellent talk!!

  • @grakka72
    @grakka72 28 дней назад +2

    Welcome to the WESTERN WORLD of capatilisme. You deserve more credit for your work.

  • @ak1t4hax0r8
    @ak1t4hax0r8 Месяц назад

    Amazing talk! thanks for sharing Jason!

  • @nullvoid3545
    @nullvoid3545 Месяц назад +7

    Why not make A but bounty "union" that instead acts as an intermediary between hunters and the platforms taking the contracts for bug bounties.
    If the platforms wont take your bugs because you didn't sign A contract, then you now have A barrier for negotiating. The bugs can be sent to either regulators(Does threatening to report A crime count as extortion?) or the company themselves with the advantage that A group representative has A larger megaphone to(responsibly) disclose publicly that this company would not pay you under this more equitable arrangement.
    Best I got.
    But I think it's A better plan than hoping they simply choose to be less exploitative.(On the internet?)

  • @JoeRogansForehead
    @JoeRogansForehead 23 дня назад +3

    I thought bug crowd was when more than 4 gay people formed a line?

  • @TripleA679
    @TripleA679 Месяц назад +2

    This is why some would rather sell their discoveries on the dark web.

  • @cosmin91ro
    @cosmin91ro 29 дней назад +2

    you have my respects man, but I was expecting mentioning about wanna be hackers that throws shitty reports and spams both platform triagers and programs' security teams, hoping to full them to get a 100$ bounty

    • @pcguy619
      @pcguy619 29 дней назад +1

      For real… or CVEs rated at high 9s that claim “code execution is possible” but are at most only memory corruption. POC or GTFO!

  • @TheStarcalibur
    @TheStarcalibur 19 дней назад

    They most probalbly think "thats their passion. They do it anyway, why should we pay for this?!"
    That is on so many sides just wrong and abusive. But i think its also a hint about who these people are. And think about if the hacking comunity should not branch out and make their own Bug bounty site. They have all the expertise.
    Dear ....
    If you read this idea and start doing it. Reach out to me and take me on board for sparking that process :)
    In a few years i will do it, bringing the right people together :)

  • @shadowunifer
    @shadowunifer 23 дня назад

    This is why I’m extremely paranoid about how I submit bugs and tend to sell them instead. My time and skills are valuable.

  • @jmz8086
    @jmz8086 Месяц назад

    amazing presentation. thank you!

  • @alextravine9422
    @alextravine9422 Месяц назад +2

    It would appear to me that the bug bounty program is corrupted and should not be something to participate in.

  • @monh964
    @monh964 Месяц назад +3

    This is sad, i thnk the black market is better

  • @dosesandmimoses
    @dosesandmimoses Месяц назад

    I brought this topic up to Dr. Hinton respectfully..

  • @archkittens
    @archkittens 14 дней назад

    How can the contract bind you re: the submission if you received no money(consideration) for the submission? It is not illegal to sell unregulated information, and it’s definitely not illegal to share unregulated information for free, the platforms and ultimately the customers are buying your right to do those things, and if they choose not to buy it your rights should be unchanged.

  • @mohamednasseribrahem
    @mohamednasseribrahem Месяц назад

    I am starting hunting nowadays but I am a little afraid of this question
    Will bug hunt decline or end with the rise of the AI?

  • @eyezikandexploits
    @eyezikandexploits Месяц назад +4

    This is kinda messed up

  • @sysadmin1350
    @sysadmin1350 22 дня назад

    Great talk

  • @biz1M
    @biz1M 16 дней назад

    Have seen BC employees stealing research (0day) then claiming the bounty on other targets leveraging the same tech stack. Repulsive behavior and blacklisted. Also seen employed hackers within firms share a 0day within the firm with strict instructions do duh, DO NOT LEAK to then be abused/leaked by said "future" employee who even went as far as asking on twitter for some bypasses for this very specific vector. BB is a scam.

  • @regular3dguy830
    @regular3dguy830 Месяц назад

    Great talk!

  • @zak6820
    @zak6820 Месяц назад

    wow respect to jasson haddix

  • @itsmemyme
    @itsmemyme Месяц назад

    lets implment some decentralized id or attachment which can trace out for found instances and properly pay for percentage to hunter

  • @AlexFlores-o5b
    @AlexFlores-o5b Месяц назад

    Where can I sign up? Can’t be worst than AT&T

  • @LewisCowles
    @LewisCowles Месяц назад +1

    Very interesting, and definitely food for thought. Doesn't sound very realistic though. "Shitty customers" feels like "anyone who doesn't do what I'd advise".

    • @theodorekorehonen
      @theodorekorehonen 12 дней назад

      Do you work for one of these companies? Your comment really has this "I'm a middle manager whose only task is to throw a wrench in the works and feel self important" energy.
      Or perhaps you're just someone whose personally trends towards the bootlicking side?

  • @slussssy01
    @slussssy01 Месяц назад +1

    Love you haddix

  • @elite_fitness
    @elite_fitness 27 дней назад

    3 tines bugcrowd has said thst my report was a dupe and a year later the vuln is still there. I also think a triager took my vulns and brushed me off

  • @eshayz
    @eshayz Месяц назад

    Hackers being replaced by AI before GTA 6

  • @bughunter9766
    @bughunter9766 24 дня назад

    3rd party shit happened to me,, with full access to cloud read and write,, with all the employees data.

  • @jnyc
    @jnyc 25 дней назад

    STOP HELPING THEM!! LET THEM EAT THE BUGS!

  • @dosesandmimoses
    @dosesandmimoses Месяц назад

    Also- the court systems - online.

  • @myfaveyoutube
    @myfaveyoutube 27 дней назад

    my dude

  • @AndreeaCe
    @AndreeaCe 29 дней назад

    (Better now?) American Magnet ;))

  • @usamaarshad1766
    @usamaarshad1766 Месяц назад

    Rep++

  • @k0ns0l
    @k0ns0l Месяц назад

    YOLO
    :p

  • @netbin
    @netbin Месяц назад

    /notes

  • @0x5001
    @0x5001 День назад

    bug bounty is scam :)

  • @cyb0rgh4kr
    @cyb0rgh4kr Месяц назад +3

    Freakin Jason HaddiX! best wishes to your FAM bro @jasonhaddix

  • @safisec
    @safisec Месяц назад

    Thanks @jhaddixP 100% Truth.