How I found the $1,500 SSRF in Stripe bug bounty program

Поделиться
HTML-код
  • Опубликовано: 2 янв 2025

Комментарии • 30

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  2 года назад +4

    Welcome to the comment section, I hope you enjoyed the video. Go here if you want to join BBRE Premium before the price goes up: bbre.dev/premium

    • @francisdonald4298
      @francisdonald4298 2 года назад

      Hey bro can learning webdevelopment assist with bugbounty???? Answer please

  • @sauer.voussoir
    @sauer.voussoir Год назад +5

    I disabled my adblock to support your channel, it really helps me a lot to get started on this bug bounty. Your videos are very informative.

  • @bertrandfossung1216
    @bertrandfossung1216 2 года назад +1

    Thanks for sharing this bro. I learnt a lot

  • @DavenSec
    @DavenSec 2 года назад +2

    Wow that was a so nice idea to use the dns dot, congratulations man !

  • @jpierce2l33t
    @jpierce2l33t 2 года назад +1

    Nice dude! I gotta learn Go sometime, some of its syntax is confusing because I've never studied it. A lot of it is similar to C-type languages, but a lot of it isn't 🤣

  • @shaarawyshaarawy8628
    @shaarawyshaarawy8628 2 года назад +1

    Good job bro ❤️❤️🙏

  • @0xgodson119
    @0xgodson119 2 года назад +1

    presentation link? 8:50

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  2 года назад +3

      Good point, the presentation is not yet available on RUclips, I'll link it as soon as it's published.

    • @0xgodson119
      @0xgodson119 2 года назад +1

      @@BugBountyReportsExplained ya, that's why I asked to make sure thats not public

    • @chaitubhojane6137
      @chaitubhojane6137 2 года назад

      @@BugBountyReportsExplained I learn from u. Great lessons. You are like my ta's in uni.

  • @kamilonurozkaleli
    @kamilonurozkaleli 2 года назад +1

    is there any other BB reports using this method or did you just invent it? Congarts btw really smart one!

  • @j4ck_d4niels
    @j4ck_d4niels 2 года назад

    Thnx for sharing awesome content

  • @aneeltripathy7420
    @aneeltripathy7420 2 года назад +1

    how can I open a web applications files in vsc ??

  • @0xgodson119
    @0xgodson119 2 года назад +1

    Super Cool!

  • @raff000
    @raff000 2 года назад +1

    Great video but I didn't understand how would you be able to extract any information from this. If you point your webhook request to the internal network how can you get any information to be redirected to you?

    • @marvelmaniac_
      @marvelmaniac_ 2 года назад +1

      Its basically a blind ssrf in that case where you are able to scan internal ports and ips . (Low impact bug)

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  2 года назад +1

      Stripe gives you webhook logs and you can see http responses there

    • @raff000
      @raff000 2 года назад

      @@BugBountyReportsExplained ah ok that makes sense. Thanks

  • @monKeman495
    @monKeman495 2 года назад +1

    big brain time: trailing dot in dns

  • @Lainad27
    @Lainad27 2 года назад +2

    why the reupload?

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  2 года назад

      It's not a reupload. If you are signed up to my newsletter, you get access to these videos before the release on RUclips

  • @crusader_
    @crusader_ 2 года назад

    Loved it

  • @saiya-jin
    @saiya-jin 2 года назад

    If I subscribe now with the monthly subscription and stay subscribed with recurring payments, would it stay on the old price? Or does the old price offer only work for annual subscription?

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  2 года назад

      Yes, with the monthly subscription you also stay at the current price forever.

    • @saiya-jin
      @saiya-jin 2 года назад

      @@BugBountyReportsExplained that's great! Thanks

  • @sim4n6
    @sim4n6 2 года назад

    Sweet