CodeQL query to detect RCE via ZipSlip - $5,500 bounty from GitHub Security Lab

Поделиться
HTML-код
  • Опубликовано: 22 окт 2024

Комментарии • 16

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  Год назад +5

    Welcome to the comment section! I hope you've enjoyed the video. I'm closing in on 40,000 subscribers so if you haven't subscribed yet, do it and help me reach that number😉

    • @techsvictor
      @techsvictor Год назад

      are 2500 hours enough for learning bug hunting for person capable of finding best resources and IQ of 130.

    • @zivintoplomjer8889
      @zivintoplomjer8889 Год назад

      @@techsvictor lmao everything's possible with that confidence my guy 😂

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  Год назад +1

      @@techsvictor You have already found the best resource my friend ;)
      To calculate you bug bounty income, you take the square root of hours and multiply it by sin(IQ) and then you raise it to the power of two so I'm sorry but to learn bug bounty you need and IQ of at least 132.4 :/
      Seriously though, 2500 hours is enough

  • @cyber-man
    @cyber-man Год назад

    Great job on your finding! Maybe consider tutorial-like mini series on CodeQL? Teaching is the best way of learning they say 😊

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  Год назад +3

      Thank you!
      Regarding the mini series.
      The bullsh*t answer (courtesy of ChatGPT):
      I apologize for any inconvenience, but it appears that CodeQL may not be the best fit for a RUclips video topic due to its highly specialized nature and complexity, which could make producing videos on the subject quite time-consuming. To make the effort worthwhile, it would be necessary to either put the series behind a paywall or seek endorsement from GitHub.
      No bullsh*t answer (wrote by me):
      This is not happening here. CodeQL is not a good topic for RUclips because it's a super small niche while at the same time being very complex which means videos would be very time-consuming. While I will make a video once in a while, knowing it will perform worse, to justify spending time on the series, I would have to either paywall the series or get endorsed by GitHub to do it.

  • @utensilapparatus8692
    @utensilapparatus8692 Год назад

    Superb Greg. I'll learn codeql later. Hope u hit another jackpot.

  • @stanlyoncm
    @stanlyoncm Год назад

    Hi @gregxsunday,
    To participate in the CodeQL program, is it enough to just submit the query or do we need to implement all the files including documentation? The question arises because when looking at the pull request, I see many changes in various files within CodeQL, even added by you.
    Best regards,
    Stan.

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  Год назад

      Hi Stan,
      All the other files and structuring the files really are easy once you have the bug and the query and they significantly boost your payout. You probably could get a bounty without it but it would not be maximizing on your ROI.

    • @stanlyoncm
      @stanlyoncm Год назад

      @@BugBountyReportsExplained I appreciate your response, it's really valuable to me. Thank you Greg.👍

  • @utensilapparatus8692
    @utensilapparatus8692 6 месяцев назад

    now i really get into it. 😊

  • @neiltsakatsa
    @neiltsakatsa Год назад +1

    Congratulations! 🎉🥳

  • @alireza8923
    @alireza8923 Год назад

    tnx a lot

  • @zTech300
    @zTech300 Год назад

    👍

  • @damtap5319
    @damtap5319 Год назад

    Bro I started learning ethical hacking
    please answer the question
    Brother, if I do 5 hours hacking practice per day, then after 6 months, how much money I will earn per month? according to your opinion

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  Год назад

      I think if you learn well, it's enough to get a job as a junior pentester. You can find their salaries in your country online.