Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Hacking on Bug Bounties for Five Years

HackerOne via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This presentation explains how vulnerabilities were discovered and reported across five years of bug bounty participation. It walks through selected findings and lessons on reconnaissance, testing techniques, report quality, and getting started.

Syllabus

Intro
Working at Hungry Jacks
PayPal's Bug Bounty
The First Critical Bug (SSRF)
My Background
How I got started
My First Unrated bug
Before You Start Hunting
Writing High Quality Reports
Getting Into Bounties
Exposed HAProxy Statistics ($500)
Open Administration Interface owned by Scompany (Ansible Tower) ($500)
Trying To Be Cheeky
Low Risk Bugs
N/A Bugs
Full Time vs Part Time
Focus on Techniques
Multiple Steps To Victory
Second Order Takeovers
Expanding The Scope
Targeting Country Specific Assets
Dirty box...
Testing Scripts
Debug Endpoints
Transport.Co Dox'd
Third Party Platforms
Dangling IP Subdomain Takeover
Defining Recon
Performing Recon
IDORS: A Systemic Problem
Automation
Retrospective
Further Reading

Taught by

HackerOne

Reviews

Start your review of Hacking on Bug Bounties for Five Years

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.