This is my coolest bug bounty report (SSRF ➡ Phishing)

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024

Комментарии • 24

  • @BugBountyReportsExplained
    @BugBountyReportsExplained  2 года назад +4

    Hi!
    In a few days, the price of BBRE Premium goes up but if you subscribe, you will lock in the current price forever! Go to bbre.dev/premium

  • @J0R1AN
    @J0R1AN 2 года назад +5

    I think the reason cool and creative bugs often don't have a big impact, is that you found a way to do something weird on the site, but you're searching for a way to barely exploit it. That requires some really creative thinking to find a cool bug. When you just find a CVE with some big impact on a site, you're not thinking very creatively and just want to report it as soon as possible

  • @dhyeychoksi5178
    @dhyeychoksi5178 2 года назад +2

    Cool find!

  • @terabaap1719
    @terabaap1719 2 года назад +2

    love your content brother❤

  • @polonia66
    @polonia66 2 года назад

    Well done! Thanks for video

  • @sazukegu
    @sazukegu 2 года назад

    Cool find!
    You feel any difference in "difficulty" when comparing public an private programs?
    Also, im still waiting for the next 100 hour video!

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  2 года назад +1

      Well, counterintuitively, the bugs I am finding on this program are more complex and harder to exploit that bugs that I was finding on public ones.
      I am also waiting for the next 100 hour video from Elastic but I am starting to think that before I get the disclosure there, I will finish the 50 hours on this private program and since I won't have to wait for disclosures here, I may publish this bounty vlog earlier.

  • @aryzen2781
    @aryzen2781 Год назад

    how did you learn web app security.

  • @terabaap1719
    @terabaap1719 2 года назад

    ❤❤❤

  • @farah13384
    @farah13384 2 года назад

    Hello, I need you and your help with my revenge plan, and I can explain to you why I want revenge and with the right evidence, can you help me?

  • @raihanhossain3423
    @raihanhossain3423 2 года назад +1

    How can we bypass the BBRE PREMIUM ? he he he

  • @CristiVladZ
    @CristiVladZ 2 года назад +2

    I think you're wasting away your genius thinking with these bug bounties. You can probably score much more in traditional pentesting with your skills, and way less friction.

    • @BugBountyReportsExplained
      @BugBountyReportsExplained  2 года назад

      I will consider this option but after a few years.

    • @SUMMedia
      @SUMMedia 2 года назад

      @Cristi Vlad I'm just curious to know more about that. What does the traditional pentesting mean? Is it like freelance pentesting service more like bug bounty hunting? Or, Is it joining a company as a pentester?

  • @utensilapparatus8692
    @utensilapparatus8692 2 года назад

    3:30 : !
    7:47 : !*!