Catch Me If You Can - Ephemeral Vulnerabilities in Bug Bounties
44CON Information Security Conference via YouTube
Overview
Syllabus
Intro
What Are Ephemeral Vulnerabilities?
Bug Bounties
Bounties Are Not Pen Tests
Getting Paid
Shifting To Continuous Security Assessment
Continuous Assessment
Root Causes of Ephemeral Vulnerabilities
Impact of Ephemeral Vulnerabilities
Evaluating AMPScript on Uber
Breaking Into "e-Commerce Company's" CI
Exposed Git Repository on Slack leading to Source Code and Secrets
Some More Examples
Avoiding Ephemeral Vulnerabilities
Taught by
44CON Information Security Conference