📣 Follow Arthur on Twitter: https://x.com/arthurair_es
📧 Check out Case Studies: https://bbre.dev/cs
✉️ Sign up for the newsletter: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw
In this podcast, my guest is Arthur Aires, part-time bug bounty hunter and cybersecurity pro from Brazil. He has an amazing approach that combines manual hacking with using a lot of tools for recon and fuzzing.
BBRD podcast is also available on most popular podcast platforms:
https://open.spotify.com/show/6tLoJ5f...
• Bug Bounty Reports Discussed
https://podcasts.apple.com/us/podcast...
Some links mentioned in the video:
https://github.com/pwntester/SerialKi...
https://book.hacktricks.wiki/en/index...
https://portswigger.net/bappstore/e4e...
https://portswigger.net/bappstore/594...
https://portswigger.net/bappstore/0e6...
https://github.com/bytebutcher/burp-s...
https://github.com/PortSwigger/403-by...
https://github.com/projectdiscovery/n...
https://github.com/SeifElsallamy/Blin...
https://github.com/trufflesecurity/xs...
https://infosecwriteups.com/easy-xssh...
https://oneprovider.com/en/dedicated-...
https://github.com/elkokc/reflector
https://portswigger.net/burp/document...
https://urlscan.io/
Timestamps:
00:00 Intro
01:30 Balancing part-time bug bounty with full-time job
02:56 Mixing manual bug bounty hunting with automation
22:04 The most useful Burp extensions
33:25 Fuzzing in bug bounty
46:34 Live Hacking Events