Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore the world of offensive security and ethical hacking in this 35-minute conference talk from GOTO Chicago 2024, where a professional hacker and content creator demonstrates how to leverage AI for more effective bug bounty hunting. Learn about critical vulnerabilities in modern web applications through real-world examples, including successful hacks of NASA systems and discoveries of insecure direct object references. Gain insights into using AI as a companion in the hacking process, from asset discovery to identifying security flaws that could compromise company infrastructure or customer PII. Follow along with practical demonstrations and collaborative case studies that showcase successful bug bounty hunting techniques, culminating in over $1M in bounties since 2022. Master essential concepts like IIS short name enumeration, API security, and the strategic application of AI tools to enhance your ethical hacking capabilities.
Syllabus
Intro
What's a bug bounty?
$1M since 2022
Easier with AI
Applied AI for bug bounties
Asset discovery
Hacking NASA
Insecure direct object reference
Unauthenticated access to the API leaks user PIl
IIS short name enumeration
In collaboration with Shubs & Rens
Demo
Final thoughts
Outro
Taught by
GOTO Conferences