56 тысяч подписчиков
211 видео
How to create personal brand as a beginner? #bugbounty #bugbountytips #bugbountyhunter
You found 9 bugs while I was sleeping? feat. Douglas Day
The top full-time bug bounty hunter reports less than 2 bugs per week feat. Alex Chapman
Keeping a spreadsheet with interesting features of different websites feat. Alex Chapman
The attack scenario to find critical bugs in local software feat. Alex Chapman
Turning unexploitable XSS into an account takeover with Matan Berson
The secret to finding many Criticals - Alex Chapman
The importance of letting go and spending time with the family feat. Alex Chapman
How does a program manager spot a top bug bounty hunter? feat. Joel Margolis
Going full-time bug bounty, privilege escalation bugs and more with Douglas Day
XSS sanitizer bypass with namespaces
$29,000 GitLab - Arbitrary File Read using symlinks
CSRF protection bypass feat. Teddy Katz
These privilege escalation endpoints are overlooked feat. Douglas Day
A mistake pentesters make when writing bug bounty reports feat. Alex Chapman
$203,000 bounties for 4 bugs in Azure Health Bot - 2x RCE, path traversal, memory leak
$50,000 Shopify access to source code via leaking GitHub token - Hackerone bug bounty
$37,500 Shopify auth bypass - Hackerone
Amazingly simple $100k login bypass on Apple
Injecting code into any Homebrew Cask by attacking GitHub Actions script
Bug bounty: year 2 - 0days, a $20k bounty and… laziness - bounty vlog #5
Bug Bounty Q&A with Jhaddix & Blaklis
CodeQL query to detect RCE via ZipSlip - $5,500 bounty from GitHub Security Lab
Are UUID-based IDORs valid bugs? feat. Douglas Day
Bypassing authorization check with secondary path traversal
The checklist for beginner pentesters
Turning SQL injection in MySQL into file read
Talking about bugs with non-technical people feat. Douglas Day
$12,000 Grafana SSRF in Gitlab - Bug Bounty Reports Explained
Client-side desync vulnerabilities - a breakthrough in request smuggling techniques
$10k+5k Web cache poisoning - Github + Firefox - Bug Bounty Reports Explained
Adding infinite funds to your Steam wallet - $7,500 bug bounty report
MetaMask - stealing ETH by exploiting clickjacking - $120,000 bug bounty
A common password reset vulnerability
How to create personal brand as a beginner?
How to hack WordPress?
The biggest change I made in my bug bounty hunting in 2024
What’s the most profitable bug bounty Michael has reported?
The perfect SSRF exploitation - 10/10 Critical SSRF with JR0ch17
Zoom - turning on someone's camera using SQL injection vulnerability - Bug Bounty Reports Explained
What functionalities are vulnerable to SSRFs? Case study of 124 bug bounty reports
AI and hacking - opportunities and threats - Joseph “rez0” Thacker
How long does Facebook’s TOP1 hunter stay on one target?
Fake bug bounty writeup exposed
HTTP Multiline headers
Encryption does not automagically make your app secure
$25,000 GitHub pages RCE via YAML file - Bug Bounty Reports Explained
Request smuggling - do more than running tools! HTTP Request smuggling bug bounty case study
Bug bounty tools that actually land bugs with Arthur Aires
$6,5k + $5k HTTP Request Smuggling mass account takeover - Slack + Zomato
How to become an XSS expert with renniepak