ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

The mindset for finding highs and crits in bug bounty with JR0ch17

Автор: Bug Bounty Reports Explained

Загружено: 2025-05-14

Просмотров: 8552

Описание: 📣 Follow JR0ch17 on Twitter: https://x.com/jr0ch17
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw

Interview with Jasmin “JR0ch17” Landry, a former triager and security manager, now a full-time bug bounty hunter. We discuss bug bounty strategy, mindset, and finding high and critical vulnerabilities.

BBRD podcast is also available on most popular podcast platforms:
https://open.spotify.com/show/6tLoJ5f...
   • Bug Bounty Reports Discussed  
https://podcasts.apple.com/us/podcast...

Links mentioned in the video:
The web application hacker's handbook: https://amzn.to/3GS4t68
Xlif: https://docs.oracle.com/en/cloud/saas...
DTD finder: https://github.com/GoSecure/dtd-finder
Secondary path traversal blogpost: https://samcurry.net/hacking-starbucks
OAuth dirty dancing: https://labs.detectify.com/writeups/a...
Cognito doc-driver misconfiguration: https://docs.aws.amazon.com/elasticlo...

Timestamps:

00:00 Intro
00:37 The road to becoming the full-time bug bounty hunter
20:06 The change in the mindset that lands a lot of highs and crits recently
23:02 SSRFs
24:33 How to test for SSTI?
28:54 Does SQLi still exist in 2025?
35:09 Where to test for XXEs?
41:33 Secondary path traversals
47:40 GraphQL bugs
51:04 The Chromium bug that still allows to control the referrer policy despite using DOM Purify
53:58 OAuth testing
1:03:41 Automation for a manual hacker

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
The mindset for finding highs and crits in bug bounty with JR0ch17

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

Bomby, drony i 40 tysięcy dezerterów. Płk rez. Piotr Lewandowski: Front może pęknąć w każdej chwili

Bomby, drony i 40 tysięcy dezerterów. Płk rez. Piotr Lewandowski: Front może pęknąć w każdej chwili

Gemini 3 — ИМБА для SEO и маркетинга! Тест на реальных задачах

Gemini 3 — ИМБА для SEO и маркетинга! Тест на реальных задачах

Bug bounty tools that actually land bugs with Arthur Aires

Bug bounty tools that actually land bugs with Arthur Aires

Как стать экспертом по XSS с помощью renniepak

Как стать экспертом по XSS с помощью renniepak

Finding criticals on well-tested targets - Victor “doomerhunter” Poucheret

Finding criticals on well-tested targets - Victor “doomerhunter” Poucheret

Секрет Gr3pme: Методология ведения заметок о наградах за ошибки (Эпизод 145)

Секрет Gr3pme: Методология ведения заметок о наградах за ошибки (Эпизод 145)

How I Made $2,500 From a High Severity Vulnerability | Bug Bounty Hacktivity Explained

How I Made $2,500 From a High Severity Vulnerability | Bug Bounty Hacktivity Explained

Going full-time bug bounty, privilege escalation bugs and more with Douglas Day

Going full-time bug bounty, privilege escalation bugs and more with Douglas Day

How not to get stuck when learning web security? Louis Nyffenegger from PentesterLab

How not to get stuck when learning web security? Louis Nyffenegger from PentesterLab

James Kettle: Pwning in Prod & How to do Web Security Research (Ep. 139)

James Kettle: Pwning in Prod & How to do Web Security Research (Ep. 139)

The key to succeed in bug bounty - @NahamSec

The key to succeed in bug bounty - @NahamSec

DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix

DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix

My Full Bug Bounty Recon Methodology Using My Bug Bounty Hunting Framework | Beta Launch @ DEFCON 33

My Full Bug Bounty Recon Methodology Using My Bug Bounty Hunting Framework | Beta Launch @ DEFCON 33

From 0 to a top bug bounty hunter - Johan Carlsson's journey to GitLab TOP1 on Hackerone

From 0 to a top bug bounty hunter - Johan Carlsson's journey to GitLab TOP1 on Hackerone

Bug Bounty Q&A with Jhaddix & Blaklis

Bug Bounty Q&A with Jhaddix & Blaklis

XBOW - AI Hacking Agent and Human in the Loop with Diego Jurado (Ep. 134)

XBOW - AI Hacking Agent and Human in the Loop with Diego Jurado (Ep. 134)

Хакер демонстрирует самые безумные гаджеты в своем EDC

Хакер демонстрирует самые безумные гаджеты в своем EDC

Top-Tier Bug Bounty Hunter Mindset - Yassine Aboukir KEYNOTE at BSides Ahmedabad 2022

Top-Tier Bug Bounty Hunter Mindset - Yassine Aboukir KEYNOTE at BSides Ahmedabad 2022

Everything about full-time bug bounty - Justin “rhynorater” Gardner from @criticalthinkingpodcast

Everything about full-time bug bounty - Justin “rhynorater” Gardner from @criticalthinkingpodcast

СЫРЫЕ видео от НАСТОЯЩИХ хакеров

СЫРЫЕ видео от НАСТОЯЩИХ хакеров

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]