DEFCON Workshop | Forming a Bug Bounty Hunting Party (Digital Version)

Поделиться
HTML-код
  • Опубликовано: 16 ноя 2024

Комментарии • 23

  • @akatech-ls5dq
    @akatech-ls5dq 22 дня назад

    As always, a FANTASTIC video which took us for two hours straight without feeling it .. A deep thanks from the bottom of our heart for what you are doing . Truly, your teaching intention has reached us . THANKS

  • @hippolytnavrose5094
    @hippolytnavrose5094 Месяц назад +4

    What Mr. R-s0n has taught about bug bounty cannot be found in any medium. All those books and RUclips videos are teaching surfaces. They don't teach the detail side of it. We really appreciate Mr. R-s0n. Thank you.

  • @rHino122295
    @rHino122295 Месяц назад +1

    This was a FANTASTIC video. Thank you for this and your very detailed breakdown dude

  • @ezioauditore8744
    @ezioauditore8744 Месяц назад +1

    Your videos have taught me so much, sir.

  • @ImKidriani
    @ImKidriani 24 дня назад

    These is brilliant

  • @rupokhoque2979
    @rupokhoque2979 Месяц назад

    You change my life, Thank you so much bro

  • @CharanGowdak-sf5no
    @CharanGowdak-sf5no Месяц назад +5

    Client side injection part 2 plz

  • @jsmith85151
    @jsmith85151 Месяц назад

    Welcome back.

  • @youssefismail5754
    @youssefismail5754 Месяц назад

    Love this notifications

    • @rs0n_live
      @rs0n_live  Месяц назад

      I"m glad! I'll be in the chat to answer any questions that the group has :)

  • @jxkz7
    @jxkz7 Месяц назад

    What a nice personality ❤?

  • @RealWorldPortal464
    @RealWorldPortal464 Месяц назад

    Bro do a live bug hunting specialy focus on api

  • @awais0x1
    @awais0x1 Месяц назад

    need One More Video On Access Controls Please

  • @HackGuru.tech...
    @HackGuru.tech... Месяц назад

    How do you divide up the pay for the group?

    • @rs0n_live
      @rs0n_live  Месяц назад +2

      That's a great question! I typically see groups take one of two strategies:
      1. Everyone splits the bounty evenly, even if they did not participate in the hunting: This typically works for teams that know each other very well, have worked together before, and aren't highly motivated by money. This strategy can definitely breed resentment if you have someone "flaky" on the team. A way to mitigate that issue is that everyone agrees upfront that if someone doesn't participate in X way, they will be removed from the group. I've even seen groups create an SLA for async responses and number of synchronous meetups each month.
      2. Money is split per bounty, based on participation: This is the most common way I see teams split pay. Usually they come to some agreement for the scribes and automation engineers, for example if their notes/tools directly lead to finding a vuln they get 50%, etc. Mentors typically get a split of every vuln they advise on. Ultimately, the most important thing is to sit down as a team and formally set up/document these agreements. The simplest way to do that is just to say "Everyone who contributed to finding a bug splits the money evenly" but again, if you're primary motivation is earning money that may not work for you.

    • @HackGuru.tech...
      @HackGuru.tech... Месяц назад

      @@rs0n_live Thank you for the detailed response. Building a group is super stressful, as is talking in voice chat. However, I will continue to slog through discord . I will keep following your videos too. And again wow such a large reply.

  • @mdtonmoyhossainjifat9117
    @mdtonmoyhossainjifat9117 23 дня назад

    anybody want to create a team ?

  • @z.7856
    @z.7856 Месяц назад +1

    something i hate about watching live bounties n bug bounty tips in general is nobody talks about certain things, i've noticed a lot of people who do live bug bounties don't use vpns or proxies but don't say why, nobody talks about the program rules like how to change user agent for automated/manual recon, nobody explains anything like that

  • @huzaifamuhammad8044
    @huzaifamuhammad8044 Месяц назад

    Found that your discord server is gone. What is it only me or your took it down?

  • @APTsec
    @APTsec Месяц назад

    3 minutes to go