Demystifying Bug Bounties: Insights from a Decade of Experience - Yassine Aboukir

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024
  • Bug bounties have gained popularity as a well-established process within organizations with a mature security posture. Throughout the last decade, I have been an active member of the bug bounty community and have had the privilege of managing such programs for several high-profile organizations, including Airbnb, the US military, Spotify, Sony, PayPal, and Slack.
    Additionally, I have also taken part in these programs as a hacker and have successfully identified over a thousand security vulnerabilities. This experience has proved invaluable in advancing my skills, mindset, and hacking methodology, allowing me to identify better and higher severity bugs over time, leading to increased payouts in return. During this presentation, we will deconstruct the concept of bug bounties and share insights and lessons learned from my experience as both a hacker and a bug bounty program manager. Furthermore, I will walk you through some of my favorite technical bugs that I have uncovered during my journey.

Комментарии • 19

  • @Mini-kyu
    @Mini-kyu Год назад +9

    That guy who fixed the microphone in the beginning is a star.

    • @Frawkesish
      @Frawkesish Год назад

      That was clutch. What a difference 😅

  • @davel525
    @davel525 2 месяца назад

    Very well done

  • @soufianeamt5745
    @soufianeamt5745 6 месяцев назад

    Wow Amazing how much information I got from this lecture , this is definitely one of the best talks that will change too much in my bug bounty journey , thank you Yassine for this amazing talk.

  • @doya8130
    @doya8130 6 месяцев назад

    great talk thank you

  • @FTH1723
    @FTH1723 Год назад

    this was a great talk. thank you!

  • @ritikkarayat4647
    @ritikkarayat4647 Год назад +1

    1:07:09
    I think the IMDSv2 has a ttl of 1 hop so only the ec2 instance can get the credentials and it can't send it to the client back even if there is valid SSRF?

  • @ko-Daegu
    @ko-Daegu Год назад

    Kosovo was really nice, loved the country and beside was dope

  • @shubham_srt
    @shubham_srt Год назад

    Thanks

  • @thomasr22272
    @thomasr22272 Год назад

    Great talk thank you!

  • @position876
    @position876 Год назад

    Great talk! Will you be making the slides available? Thank you!!!

  • @TheCyberWarriorGuy
    @TheCyberWarriorGuy Год назад +1

    :)

  • @Golden2Talon
    @Golden2Talon Год назад

    Will you get pay more if you sell a critical bug on a black market?

    • @FTH1723
      @FTH1723 Год назад +2

      if you sell it to enough people always lol

  • @futuremillionaire3206
    @futuremillionaire3206 Год назад +1

    🇲🇦🇲🇦🇲🇦🇲🇦